Offensive security for business-critical applications

Identify vulnerabilities before they put applications, data or releases at risk

I assess web applications and APIs from an attacker’s perspective, support secure development processes and enable development teams—with reproducible findings, clear risk assessments and actionable recommendations.

For software companies and IT service providers with business-critical applications and APIs.

Available for new projects from October 2026 · early planning is already possible

Offensive security that delivers actionable results

You receive a transparent assessment of realistic attack paths, prioritised findings and specific recommendations for development teams and management.

Evidence without sensitive project details

Trust is built through demonstrable technical experience, responsible working practices and results that can be used internally—not through buzzwords.

Published CVEs

Published vulnerabilities in enterprise software demonstrate hands-on experience in analysis, reproduction, impact assessment and responsible disclosure.

View TeamCity CVEs

Public bug bounty track record

An EC-Council Hall of Fame entry and publicly visible activity in the OTTO.de programme on YesWeHack demonstrate experience with real applications and responsible disclosure.

View bug bounty evidence

Software development and security

Extensive development experience helps me present findings so that architecture, development and management decisions can be derived from them.

Sensitive environments

Experience in security-critical environments supports projects where approvals, confidentiality, governance and clear communication are essential.

From clear objectives to actionable results

Three clear phases take us from defining objectives to reliable results and concrete next steps.

  1. Plan and authorise

    We clarify objectives, constraints and systems. Based on this, you receive a suitable proposal covering scope, schedule, roles and the required authorisations.

  2. Assess and coordinate

    I work within the agreed scope, coordinate relevant interim results with you and report critical findings early through the agreed communication channel.

  3. Report and retest

    You receive transparent results, a clear risk assessment and specific recommendations. After the review, I can perform a focused retest of remediated findings.

Do you need a reliable security assessment?

Whether you are preparing a new application, an API launch, a customer requirement or an audit—or dealing with recurring findings—I support you with technical analysis and clear recommendations for your next decisions.

Discuss your project