Web & API Security Assessment
Find vulnerabilities in your application before they become incidents. Hands-on, manual testing by a security researcher, with a clear report your team can act on.
A full assessment, not a scanner run
Every engagement combines automated tooling with deep manual testing, the part that actually finds the vulnerabilities that matter.
Real vulnerabilities, responsibly disclosed
High-severity issues I found and reported in widely-used open-source software, publicly credited to SYR-ROOT.
For a security buyer, this is the proof that counts. Finding real, high-severity vulnerabilities in software that thousands of people depend on says more than a shelf of certificates. The same rigor goes into your application.
Simple, scope-based pricing
Starting points below. You get a fixed-scope quote after a short scoping call, so there are no surprises.
Every engagement includes a prioritized technical report and one free retest after fixes.
Request an assessment
Tell me about your application and what you would like assessed. I reply within one business day.