Independent security assessment

Web & API Security Assessment

Find vulnerabilities in your application before they become incidents. Hands-on, manual testing by a security researcher, with a clear report your team can act on.

What is covered

A full assessment, not a scanner run

Every engagement combines automated tooling with deep manual testing, the part that actually finds the vulnerabilities that matter.

Published security research

Real vulnerabilities, responsibly disclosed

High-severity issues I found and reported in widely-used open-source software, publicly credited to SYR-ROOT.

For a security buyer, this is the proof that counts. Finding real, high-severity vulnerabilities in software that thousands of people depend on says more than a shelf of certificates. The same rigor goes into your application.

Engagements

Simple, scope-based pricing

Starting points below. You get a fixed-scope quote after a short scoping call, so there are no surprises.

Every engagement includes a prioritized technical report and one free retest after fixes.

Get started

Request an assessment

Tell me about your application and what you would like assessed. I reply within one business day.