Application pentesting · Offensive security

Test what must hold.

I assess web applications and APIs within explicitly authorised scopes. Every confirmed vulnerability is documented with its impact and practical remediation guidance.

Practice based in France, working remotely

Public evidence

Zephos on YesWeHack

Identity
KYC verified
Reports
23
Active
Since 2022
View the profile and activity

Public data verified on 25 July 2026.

What I assess

Three surfaces, one method.

Find plausible bypasses, confirm their impact and leave engineering teams with evidence they can act on.

01

Web applications

Authentication, authorisation, data exposure and the chaining of sensitive features.

02

APIs & backend

Contracts, access controls, input validation and unexpected behaviour across services.

03

Business logic

Business rules, role separation, critical workflows and bypasses that technical controls alone may miss.

My approach

An engagement must remain clear.

  1. Define

    A written scope, clear rules of engagement and shared stop conditions.

  2. Assess

    I form and test attack hypotheses until an impact is confirmed or ruled out.

  3. Make it actionable

    Every finding connects evidence, impact and remediation so product and engineering teams can use it.

Abstract diagram of several leads converging towards a supervised central validation.

Research & internal tooling

An agent-assisted pentest framework, under control.

I am developing an internal framework to orchestrate the collection, analysis and validation of leads within an authorised scope. Sensitive decisions, exploitation actions and final validation remain under human supervision.

It replaces neither authorisation, analysis nor accountability.

About

CyberVanguard is my offensive security practice.

It builds on my backend engineering experience: understanding architecture, code and operational constraints before judging impact.

Explore my engineering background

A question about CyberVanguard?

Direct contact

Questions, technical discussions and enquiries about authorised pentesting can be sent by email.

contact@cybervanguard.eu