Security hardening & review

Find the exploit before an attacker does.

A security review built for teams shipping AI features and web apps fast: a real threat model, dependency and secret audits, OWASP Web + LLM Top 10 red-teaming, and a security gate wired into your CI so the holes you close stay closed — all in your repo, your stack, your conventions.

Book an intro call → Read the security posture Read the engineering briefs
sound familiar?
what you get

Threat model

Your system mapped by trust boundary and data flow — the exploitable paths ranked by blast radius, not a generic checklist. A document your team keeps.

Dependency & supply-chain audit

Known-vulnerable packages, risky transitive deps, and unpinned versions surfaced and patched — with scanning wired into CI so new ones get caught on the PR.

Secrets & config review

Secrets found in history, env, and logs — rotated, moved to a manager, and kept out with a pre-commit + CI scan. Headers, CSP, and auth config checked against the baseline.

AI red-team battery

Adversarial probes against your LLM feature — prompt injection, jailbreaks, PII leakage, insecure output handling, excessive agency — with verbatim transcripts of every failure.

CI security gate

Dependency, secret, and AI-safety checks that run on every push — a regression below the baseline fails the build instead of shipping to production.

fixed scope · quoted after a week-1 threat model · your repo, your CI · no secrets leave your environment

how we work together
Security Audit
~1 week · scoped & quoted

A threat model and a prioritized findings list — the exploitable paths ranked by blast radius, with a concrete remediation plan you own. The fastest way to a real quote.

Start here — get a quote →
Hardening Sprint
~2 weeks · scoped & quoted

The highest-severity findings fixed and verified: injection and auth gaps closed, secrets rotated and moved, dependencies patched — with the checks wired in so they stay closed.

Get a quote →
Secure-by-default Build
~4–8 weeks · scoped & quoted

A security gate built into your pipeline — dependency and secret scanning, an AI red-team battery, a CI check that blocks a regression — plus a runbook your team maintains after I leave.

Get a quote →

fixed-price starting points from $497, plus a custom quote for larger or unusual builds — scoped in writing before we start, so you pay for your problem, not a package · every engagement ends with evidence you keep — and if the scoping shows I can’t help, I’ll say so and it costs nothing

proof, not promises
Security posture Where your data lives, what I will and won't do with it, the honest SOC 2 answer, incident response, retention and deletion — the full posture in plain English → llm-eval-gate Public, keyless eval gate with a safety runner battery — injection, jailbreak, PII, toxicity — the same probes I run against a client's AI feature → This site A production CSP, security headers, and no third-party script sprawl — the hardening baseline applied to the page you're reading →
worked example

15 exploitable issues, caught before ship.

On a build review, a combined pass — static analysis, a dependency and secret audit, and an AI red-team battery against the LLM surface — surfaced 15 exploitable issues: prompt-injection paths, an exposed credential, missing authorization checks, and vulnerable transitive dependencies. Every one was triaged by blast radius and closed before it reached production.

without the review

15 live paths an attacker could have walked — shipped silently, found in an incident.

with it

0 shipped — each closed, verified, and a CI check added so it can't come back.

Findings count self-reported from the engagement; remediation verified in CI. Method is the same on every review.

questions
Are you a licensed penetration tester?

No — I'm a senior engineer who builds security into the pipeline: threat modeling, OWASP Web + LLM Top 10 review, dependency/secret/CI hardening, and an AI red-team battery. For a formal third-party pentest or a signed compliance attestation you need a licensed firm, and I'll tell you plainly when that's the case and hand off a clean scope. Most teams need the engineering hardening first.

What AI-specific risks do you cover?

The OWASP LLM Top 10: prompt injection, insecure output handling, training-data and prompt leakage, PII exposure, over-reliance, and excessive agency. The red-team battery runs these as adversarial probes with verbatim transcripts of every failure, so you see the exploit before a user finds it.

Can you do SOC 2 for us?

SOC 2 is an audit performed by a licensed CPA firm — I can't issue that, and anyone claiming to "do your SOC 2" as a solo engineer is wrong. What I do is get your controls, logging, secret handling, and data flows into the shape an auditor wants to see. The honest, full answer is on the security page.

Where does the work run, and what do we own?

In your repo and your CI. The threat model, the findings, the fixes, and the security gate are all yours, documented, with nothing retained on my side after handoff. No secrets ever leave your environment.

How do you price this?

Scoped and quoted in writing after a short call — fixed scope, not open-ended hours. Most engagements start with a one-week security audit, and that fee credits into the hardening work if you continue.

How fast can you find the serious problems?

The week-one audit surfaces the exploitable paths ranked by blast radius. On a recent build, a combined static, dependency, and AI-probe review surfaced 15 exploitable issues before ship; the highest-severity ones are typically closed inside the following sprint.

15 minutes. Bring the feature that scares you.

You leave with a concrete plan either way — the call is free and the plan is yours.

Book the call → see the engagement paths ↑
Related services & guides
AI agent testing →LLM evaluation & QA →