Independent security researcher focused on access control and API authorization. I hunt the flaws that persist when an endpoint is hidden but never actually enforced.
The bugs I care about usually aren't buried in clever code; they sit where authorization was assumed instead of enforced, and they survive review after review because everything around them looks locked down.
I lean on AI to cast a wider net, but every lead gets validated by hand before I trust it. And I point the same authorization lens at AI systems themselves.
I operate strictly within authorized scope — bug-bounty program rules, safe-harbor policies, and only assets I own or have explicit permission to assess. Every finding is verified through a reproducible proof of concept before submission; I don't report scanner- or AI-generated results without manual validation. My testing is non-destructive, minimizes impact to production systems, and relies only on self-owned test accounts and identities.