Available for Q4 2026 engagements

Offensive security
for teams that ship fast.

Independent web & API penetration testing, delivered as a continuous partnership, not a once-a-year fire drill.

CVE-2025-69245
Published research
10-15h
Monthly retainer
ISO 27001
Auditor background
WSTG · PTES
Methodology
CVE RESEARCH BOLA / IDOR OWASP WSTG AUTH BYPASS PTES BUSINESS LOGIC API SECURITY ISO 27001 RETAINER MODEL GRAPHQL CVE RESEARCH BOLA / IDOR OWASP WSTG AUTH BYPASS PTES BUSINESS LOGIC API SECURITY ISO 27001 RETAINER MODEL GRAPHQL
What I do

Two ways to work together

Most teams default to one large audit a year. There's a better model for teams that ship continuously.

02 // AUDIT

Web, API & Thick-Client Testing

Full-scope black-box / grey-box assessment: authentication flaws, authorization bypasses (BOLA/IDOR), session handling, business-logic abuse, and REST/GraphQL-specific attack surface. Also covers thick-client applications and manual source code review (Java).

OWASP Top 10 · API Top 10 · SAST
03 // COMPLIANCE

Audit-Ready Reporting

Independent penetration test reports structured to satisfy SOC 2, ISO 27001, HIPAA, and GDPR requirements for enterprise deals. Executive summary plus a developer-ready remediation guide.

Deal-closing deliverables
Vulnerability Research
Reflected XSS, via CERT Polska
Governance
ISO 27001:2023
TÜV NORD auditor training
Methodology
OWASP WSTG & PTES
Standard-compliant reporting
Proof, not promises

What you actually get in the report

  • Risk-ranked vulnerability breakdown, CVSS v3.1 scored
  • Verified, step-by-step proof-of-concepts, not theoretical findings
  • Direct engineering remediation snippets, not generic advice
  • Complimentary re-test after patch deployment
  • Executive summary written for leadership, not just engineers

"Patryk performed external penetration tests and delivered a detailed, well-structured report with clear explanations and actionable recommendations as part of our SOC 2 / ISO 27001 compliance preparation. Thanks to his input, we significantly strengthened our security posture."

Karol Obrębski
Owner, myFlipIt · CargoAssistant
✓ Verified client
Open source & research

Tools and write-ups, in the open

A working library of offensive-security tooling, maintained publicly and used in real engagements.

Kali-Linux-2025-UTM★ 44

Preconfigured Kali Linux template for UTM on Apple Silicon, up to date keys and sources, widely used by other testers on M-series Macs.

New CVE Research Logsoon

Fresh vulnerability write-ups and case studies from current engagements, replacing the older learning-phase material.

Let's talk

Ready for a security partner who ships with you?

Tell me about your stack and release cadence. I'll tell you honestly whether a retainer or a one-off audit fits better.