PAUL MK

Services

Fixed scope, fixed deliverable, price agreed before work starts. You should know what you are getting before you ask, so the scope and the output are on this page rather than in a call.

Findings come as diffs, not descriptions, and every one explains why a competent developer would have written it that way in the first place. Reports that read as accusations get ignored; reports that read as patches get merged.

Rather than ask you to take that on trust, there isa complete sample finding — reproduction, impact, root cause, the fix as a diff, and the rule that stops it coming back. It is written on a bug you can check out and reproduce yourself.

Lead engagements

Horizontal access control and payments — where the severe bugs are

Multi-tenant isolation audit

Every endpoint tested across tenant boundaries — same role, different organisation. The failure mode scanners are blind to and most pentests never reach.

Receive
Findings report — reproduction steps, severity, and the fix as a diff. One retest.
Timeline
5 business days, plus one retest within 30 days
From
USD 5,000

Payment integration security review

Signature verification and whether the comparison is constant-time, replay protection, idempotency claimed atomically under concurrent delivery, settlement races, credential handling.

Receive
Findings report plus a reconciliation gap analysis. One retest.
Timeline
4 business days, plus one retest within 30 days
From
USD 5,000

The floor above covers a single application or integration. Final price depends on endpoint count, number of roles, and how many providers are in scope — and it is fixed in writing before any work begins. Quoting by the hour would only reward me for taking longer.

Also available

Scoped and priced against your codebase

I take build work as well as review work — the same engineering, on the parts where getting it wrong is expensive. If you have a payment integration, a multi-tenant data layer or an auth system to build rather than audit, that is in scope.

How an engagement runs

  • Scope call. Thirty minutes. What the application does, how many tenants and roles exist, which integrations are in scope. You get a fixed price and a start date.
  • Access. Read access to the repository and two accounts per role per tenant, which is what makes horizontal testing possible at all.
  • Testing. Daily note on what has been covered. Anything critical is reported the hour it is found rather than held for the report.
  • Report. Findings with reproduction steps, severity, and the fix as a diff against your code.
  • Retest. One pass over the original findings within thirty days, confirming each fix holds and did not move the problem somewhere else.

paulmk2143@gmail.com