Web applications
Authentication, authorisation, data exposure and the chaining of sensitive features.
Application pentesting · Offensive security
I assess web applications and APIs within explicitly authorised scopes. Every confirmed vulnerability is documented with its impact and practical remediation guidance.
Practice based in France, working remotely
Public evidence
Public data verified on 25 July 2026.
What I assess
Find plausible bypasses, confirm their impact and leave engineering teams with evidence they can act on.
Authentication, authorisation, data exposure and the chaining of sensitive features.
Contracts, access controls, input validation and unexpected behaviour across services.
Business rules, role separation, critical workflows and bypasses that technical controls alone may miss.
My approach
A written scope, clear rules of engagement and shared stop conditions.
I form and test attack hypotheses until an impact is confirmed or ruled out.
Every finding connects evidence, impact and remediation so product and engineering teams can use it.

Research & internal tooling
I am developing an internal framework to orchestrate the collection, analysis and validation of leads within an authorised scope. Sensitive decisions, exploitation actions and final validation remain under human supervision.
It replaces neither authorisation, analysis nor accountability.
About
It builds on my backend engineering experience: understanding architecture, code and operational constraints before judging impact.
Explore my engineering backgroundDirect contact
Questions, technical discussions and enquiries about authorised pentesting can be sent by email.
contact@cybervanguard.eu