Penetration testing for web applications and APIs
I assess web applications and APIs for realistic attack paths. You receive reproducible findings, clear risk priorities and specific remediation guidance.
View detailsOffensive security for business-critical applications
I assess web applications and APIs from an attacker’s perspective, support secure development processes and enable development teams—with reproducible findings, clear risk assessments and actionable recommendations.
For software companies and IT service providers with business-critical applications and APIs.
Available for new projects from October 2026 · early planning is already possible
Services
You receive a transparent assessment of realistic attack paths, prioritised findings and specific recommendations for development teams and management.
I assess web applications and APIs for realistic attack paths. You receive reproducible findings, clear risk priorities and specific remediation guidance.
View detailsI assess architecture, code and development decisions. You receive prioritised improvements for threat modelling, reviews, the SDLC and security gates.
View detailsI teach attack patterns, secure coding and decision criteria using real findings. Development teams identify risks earlier and address them more effectively.
View detailsSelected evidence of experience
Trust is built through demonstrable technical experience, responsible working practices and results that can be used internally—not through buzzwords.
Published vulnerabilities in enterprise software demonstrate hands-on experience in analysis, reproduction, impact assessment and responsible disclosure.
View TeamCity CVEsAn EC-Council Hall of Fame entry and publicly visible activity in the OTTO.de programme on YesWeHack demonstrate experience with real applications and responsible disclosure.
View bug bounty evidenceExtensive development experience helps me present findings so that architecture, development and management decisions can be derived from them.
Experience in security-critical environments supports projects where approvals, confidentiality, governance and clear communication are essential.
How I work
Three clear phases take us from defining objectives to reliable results and concrete next steps.
We clarify objectives, constraints and systems. Based on this, you receive a suitable proposal covering scope, schedule, roles and the required authorisations.
I work within the agreed scope, coordinate relevant interim results with you and report critical findings early through the agreed communication channel.
You receive transparent results, a clear risk assessment and specific recommendations. After the review, I can perform a focused retest of remediated findings.