services
Independent researcher — small, senior, evidence-driven engagements. Every deliverable below answers to the same rule as the rest of this site: claims carry evidence, or they don’t ship.
Web & app pentest
- scoped web apps and APIs: authn/authz, business logic, injection, the OWASP web and API Top 10 as a floor, not a ceiling
- every finding ships with a request/response pair or a reproducer
- report you can hand to engineers without translation; retest after fix
Source-code audit
- manual review plus variant analysis: find the bug class, then sweep the codebase for its siblings
- web stacks and native code; sanitizer/fuzzing harnesses where they pay for themselves
- deliverable: root cause per finding, minimal PoC, concrete fix guidance
Custom security tooling & automation
- small, sharp tools: fuzz harnesses, scanner glue, CI security checks, PoC-to-regression tests
- Go/Python, stdlib-first, single binaries where possible — the same standard as my public tools
- delivered with tests and docs; you own the code
Technical writing
- deep-dive research articles, disclosure-style writeups, documentation with runnable examples
- terse, technical, evidence-first — the voice you are reading now
Start a conversation
Email chattr [at] linux [dot] com (or see contact) with the target, the timeline, and the constraints. You get a fast yes/no and a scoped quote — not a sales funnel.