
I will run a focused security review of your web app or API
Service overview
Scope: external review of one web app or API (authentication, session handling, input validation, OWASP-Top-10 classes, secrets management, audit logging), light threat modeling, and a prioritized remediation list. For regulated contexts (banking, fintech), I tag findings against BAIT/MaRisk-adjacent concerns.
Deliverable: a written report with risk-rated findings, reproducible repro steps for criticals, and a 60-minute remediation walkthrough with your dev team.
Best fit: pre-launch SaaS, post-launch fintech, or any team where "have we missed something obvious?" is keeping someone awake.
Background: three years as Team Lead Threat Intelligence at a security boutique, including pentest mandates for banking clients in the DACH region (anonymized).
