Researcher who breaks payment rails
I test payment rails, authorization models, multi-tenant systems and AI agent surfaces for the logic flaws that scanners never reach. Ranked 33rd all-time on Bugcrowd, first in Egypt.
Scoped engagements, program design, or someone who stays close to your system.
Scoped web and API engagements, usually three to five testing days. A findings report with severity, reproduction steps and remediation guidance, plus a retest once fixes land. Critical findings reach you the day I find them.
Standing up a program that produces signal instead of noise: scope matched to your real risk, reward tiers that attract researchers who can find the hard things, and triage your team can act on.
An annual pass plus scoped reviews whenever you ship something touching money movement, authentication or payouts. Faster every time, because I already know how your system works.
Most of what I find comes down to a control that exists on one path and not another. A selection from managed programs, with clients and identifying detail removed.
Also: server-side request forgery across webhook and integration surfaces, stored cross-site scripting chained to credentialed cross-origin reads, unrestricted API keys billed per use, and unauthenticated access to internal document stores.
Five testing days, as an example. Shorter engagements compress the middle, never the ends.
A written scope naming the systems, the test window and an escalation contact, signed by whoever owns the assets. Nothing is touched until that is on file. Half the fee is invoiced at signing.
Walkthrough with your engineer, the API specification, and every role provisioned. I spend the first day understanding how money and permissions are meant to move, because that is what tells me where they might not.
Authorization boundaries between roles and tenants, whatever the server takes on trust from the client, concurrency on anything that counts or spends, and the routes that were replaced but never removed. Anything critical reaches you the same day.
Individually minor findings are worth more together. The last day is spent building the realistic attack path and confirming each issue reproduces cleanly, so your team is not chasing something that only worked once.
A written report within three working days: severity, reproduction steps, and remediation your engineers can act on without a follow-up call. One retest is included once fixes land, because a patch that reverts is a finding I have reported before.
Fixed price per scope, not a day rate to negotiate down. Half at signing, half on delivery of the report.
Scope drives the number, not the calendar. If the budget is fixed, I would rather narrow what gets tested and do it properly than stretch the same days across more surface.
No. A staging environment with seeded data and provisioned roles is better for both of us. If only production exists, we agree in writing what is off limits and I work read-mostly.
Yes, and I expect to. I will also want written authorization to test, which an NDA does not provide on its own. Client names never appear in my public work.
A scanner finds what it has a signature for. Nothing in the list above would appear in one, because every item is a system behaving exactly as written and wrongly as designed.
You get the report anyway, documenting what was tested and how. That is a defensible artifact for a customer or an auditor. In practice it has not happened yet.
Usually two to four weeks out. Scoping takes one email exchange; the wait is the calendar, not the paperwork.
Half at signing, half on delivery. Bank transfer or Wise, in US dollars. I am an individual contractor, so a W-8BEN is available if your finance team needs one.
Describe the system and what worries you about it. I will come back with a scope, a timeline and a price.