SELECTED WORK

Things I have actually shipped and defended.

WEB SYSTEMS • 2025

Secure Client Portal for Legal Firm

Laravel • PostgreSQL • Strict RBAC

Full-stack hardened platform with granular access controls, comprehensive audit logging, and zero-trust architecture. Designed specifically for law firms handling sensitive client data.

HOSTING & INFRA • 2024

FASTPANEL Hardened Multi-Tenant Platform

FastPanel • Ansible • Immutable Backups

Production-grade multi-tenant hosting environment with tenant isolation, automated hardening, and immutable backup strategy. Currently serving 20+ production clients.

RESEARCH • 2024

Bug Bounty: Multi-Step Account Takeover Chain

Responsible Disclosure

Discovered and responsibly disclosed a critical multi-step authentication bypass affecting a production SaaS platform with over 40,000 users.

DEFENSIVE • 2025

Zero-Trust Starter Kit for Modern PHP

Open Source

Open-source toolkit implementing cryptography, strict Content Security Policy, rate limiting, and audit trails from day one. Used by 300+ developers.