I'm an independent security researcher hunting on HackerOne, focused on web application and API security. I look for real, exploitable vulnerabilities and report them responsibly — no noise, no guesswork, just verified findings.
Security research grounded in manual verification — not scanner output dressed up as a finding.
Hunting for vulnerabilities through HackerOne-hosted programs, within each program's defined scope and rules.
Authentication, session handling, access control, injection points, and business-logic edge cases.
Auth bypass, IDOR, schema abuse, and misconfiguration testing across REST and GraphQL APIs.
Clear, reproducible reports with verified impact — written to help teams fix issues fast, not to pad a count.
Every finding goes through the same discipline before it's ever written up.
Map the target and confirm what's in scope.
Manual + tool-assisted probing of attack surface.
Confirm real, reproducible impact — reject false positives.
Clear write-up with PoC, steps, and severity.
Support retesting once a fix ships.
I'm relatively new to bug bounty hunting and building my track record openly on HackerOne. My approach is deliberately unglamorous: understand the target, test carefully, verify impact before ever calling something a vulnerability, and write reports that are easy for a triager to act on.
I'd rather submit fewer, high-quality reports than chase volume with scanner output — that's the reputation I'm building.
For vulnerability disclosures or general inquiries, reach out below.