Finding what others miss — real attacker mindset, real-world impact.
Critical vulnerability chain on an undisclosed programme — the largest single payout to date.
Accepted researcher on the Google Vulnerability Reward Programme.
Specialist in chaining low-severity issues into critical-impact exploits — finding what automated tools miss.
Active across HackerOne, Bugcrowd, Intigriti, YesWeHack, Synack, and private programmes.
The same attacker mindset behind six-figure bounties, available as a contracted assessment. Two areas of focus.
Manual, attacker-driven assessment — not an automated scan report. Full coverage of authentication, APIs, session management, and business logic.
Security assessment for AI-powered applications, LLM integrations, and agentic systems. A rapidly evolving attack surface that demands specialist expertise.
All engagements are scoped individually. Get in touch to discuss requirements, timeline, and pricing.
Open Web Application Security Project — leading application security standards and resources
Visit OWASPBurp Suite creators and web security research leaders
Visit PortSwiggerCybersecurity training and certification authority
Visit SANSCouncil of Registered Ethical Security Testers — UK certification body
Visit CRESTUK National Cyber Security Centre — government cybersecurity guidance
Visit NCSCPayment Card Industry Data Security Standard compliance
Visit PCI DSSWhether you need a security assessment or want to discuss a potential engagement — reach out.