zenbyte.sh
# hidden != forbidden != enforced

Independent security researcher focused on access control and API authorization. I hunt the flaws that persist when an endpoint is hidden but never actually enforced.

The bugs I care about usually aren't buried in clever code; they sit where authorization was assumed instead of enforced — and they survive review after review because everything around them looks locked down.

Lately I've been leaning on AI to find them faster, and turning the same lens on the AI attack surface itself.

Focus
Writing
Approach

I operate strictly within authorized scope — bug-bounty program rules, safe-harbor policies, and only assets I own or have explicit permission to assess. Every finding is verified through a reproducible proof of concept before submission; I don't report scanner- or AI-generated results without manual validation. My testing is non-destructive, minimizes impact to production systems, and relies only on self-owned test accounts and identities.