services

Independent researcher — small, senior, evidence-driven engagements. Every deliverable below answers to the same rule as the rest of this site: claims carry evidence, or they don’t ship.

Web & app pentest

  • scoped web apps and APIs: authn/authz, business logic, injection, the OWASP web and API Top 10 as a floor, not a ceiling
  • every finding ships with a request/response pair or a reproducer
  • report you can hand to engineers without translation; retest after fix

Source-code audit

  • manual review plus variant analysis: find the bug class, then sweep the codebase for its siblings
  • web stacks and native code; sanitizer/fuzzing harnesses where they pay for themselves
  • deliverable: root cause per finding, minimal PoC, concrete fix guidance

Custom security tooling & automation

  • small, sharp tools: fuzz harnesses, scanner glue, CI security checks, PoC-to-regression tests
  • Go/Python, stdlib-first, single binaries where possible — the same standard as my public tools
  • delivered with tests and docs; you own the code

Technical writing

  • deep-dive research articles, disclosure-style writeups, documentation with runnable examples
  • terse, technical, evidence-first — the voice you are reading now

Start a conversation

Email chattr [at] linux [dot] com (or see contact) with the target, the timeline, and the constraints. You get a fast yes/no and a scoped quote — not a sales funnel.