Contest submissions
Audit-contest findings, validated and submitted. Supporting repositories stay private, so the record is summarized here without platform or date details.
Research & findings
Contest records, responsible disclosures, and the report format behind the work. Private findings stay private — publishing is gated by disclosure terms.
On record
Contest record
Audit-contest findings, validated and submitted. Supporting repositories stay private, so the record is summarized here without platform or date details.
Responsible disclosures
Findings from a protocol configuration review, shared privately with the team. Details are withheld until disclosure terms permit.
Four private disclosures are recorded without publishing exploit details. Evidence is shared only when disclosure terms permit it.
Authorized testing only. I do not publish active exploit paths, private reports, or sensitive protocol details before a responsible-disclosure process is complete. Where a severity is shown, it reflects what was validated — not the worst case that can be imagined — and nothing goes public until disclosure terms permit it.
Sample finding
Interactive sample — pick a severity and copy the report. This is the ErrorLens output format.
This is a reporting-format sample, not a published client finding. Protocol details and exploit paths remain private until disclosure terms permit publication.
Have a finding to verify?
Share the repository, program list, and the exact systems or flows under review.
Point to trusted roles, asset movement, integrations, and assumptions that cannot fail.
Get severity, impact, reproduction, remediation, and verification in one usable format.