Web applications
Identity, access control, business logic, session state, file handling, and privileged workflows.
01 Offensive security consultancy
Find the exploit path, prove the impact, and leave engineering with a fix they can ship.
02 The work
1H Security tests the assumptions between users, applications, APIs, and infrastructure. The goal is not a longer finding list. It is a sharper view of what is reachable, what matters, and what to fix first.
Human-led / exploit-driven / fix-focused
03 Testing scope
Identity, access control, business logic, session state, file handling, and privileged workflows.
Object-level authorisation, token handling, state manipulation, webhooks, schemas, and trust boundaries.
Internet-facing services, identity assumptions, storage exposure, deployment defaults, and management reachability.
Asset discovery, exposed services, forgotten hosts, weak entry points, and evidence-backed prioritisation.
Hands-on review shaped by data flows, system roles, sensitive operations, and the controls between them.
04 On trust
The report excerpt below is illustrative, not a claimed client result. It shows the standard: reproducible evidence, a defensible impact, and a fix an engineer can validate.
05 Sample finding
Clear preconditions. A short attack path. Enough evidence to reproduce the issue without reverse-engineering the report.
Broken object-level authorisation
A low-privileged user can retrieve an export created by another tenant because the download endpoint does not re-evaluate tenant ownership.
GET /v1/exports/{job_id}Attack path
Bind export lookup to the caller's tenant, re-check access at download time, and add a cross-tenant regression test.
06 Engagement shape
Set targets, roles, test access, priorities, dates, and production constraints.
Map the system, probe the controls, and chain weaknesses where the impact changes.
Raise serious findings early, confirm context, and keep engineers close to the evidence.
Deliver the report, walk through priorities, and validate the critical repairs.
07 What lands
Reproduction steps, preconditions, affected components, evidence, impact, and specific repair guidance.
A concise view of exposure, important attack paths, immediate actions, and systemic themes.
A clear status for repaired findings, with any remaining conditions or follow-up work called out.
The useful unit is not a vulnerability count.
It is a decision: fix now, fix next, or accept the risk with eyes open.
08 Start here
Send the systems in scope, preferred dates, production constraints, and the decision the test needs to support.
[email protected]