Services
What I take on.
Security work where the answer depends on understanding both the cryptography and the
platform it has to survive on, plus the web practice that surrounds it. If your problem
is somewhere else entirely, I will say so.
Age assurance and child safety systems
Design and review of age verification, minor-safety controls, and platform integrity,
built for real regulatory pressure rather than a policy page. I have implemented this,
not only advised on it.
5 days design review · longer if building
Mobile application security review
iOS and React Native. Key storage and keychain use, certificate handling, deep link
and IPC surface, what the binary leaks, and what the app actually sends when you
watch the traffic rather than read the docs.
4 to 8 days · written report and a working session
Cryptography implementation and review
End-to-end encrypted messaging, key exchange and rotation, encryption at rest, media
and voice handling. Most failures I find are not broken primitives. They are correct
primitives wired up wrongly, or a library that behaves differently on device than it
does in your test suite.
5 to 10 days · or ongoing retainer
Fractional CTO and security leadership
The technology function without a full-time hire. Architecture and threat modelling,
build versus buy calls, vendor selection, hiring and technical interviewing, security
questionnaires answered properly, and translating all of it for a board that does not
speak engineering. Eleven years doing the job, not advising on it from outside.
Two to six days a month · ongoing
Supabase and backend security review
Row Level Security that does not do what the team believes it does. Service role keys
reachable from the client. Edge functions trusting input they should not. Storage
buckets open to anyone holding a URL. These are the failures I find most often in
startups built on Supabase or Firebase, and they are usually invisible until someone
looks specifically.
3 to 6 days · policy-by-policy review
AI feature security review
You shipped a model into your product. Now: what can a user make it say, what tools
can they reach through it, what leaks into the context window, and what happens when
it answers confidently and wrongly. Prompt injection, tool-use boundaries, data
exposure, and the verification layer that should sit between the model and the user.
4 to 8 days · adversarial testing and written findings
Website security audit
Headers, transport, authentication, exposed endpoints, dependency and supply chain
risk, form and upload handling, and what your third-party scripts are quietly doing.
You get a prioritised list you can hand straight to a developer, not a scanner dump.
Fixed price · report within five working days
Websites built and maintained
Fast, accessible, secure by construction. No page builder bloat, no third-party
scripts you did not ask for. Then a care plan afterwards: patching, dependency
updates, uptime, backups, and someone who answers when something breaks at
an inconvenient hour.
Project fee · then monthly care plan