Services
One accountable expert, a written process, insurance behind the signature, and a public record behind the work.
Typical workflows
Generally, we have three choices – and they come down to who does the pulling.
Reactive support
A question about a vendor at 9 a.m., a strange feeling about an employee at 9 p.m. – you ask, I answer, all year. That's Advisory: one annual budget, paid monthly, covering everything a security person should cover. How the year works →
Proactive research
I test your named assets on my own initiative, whenever I have time, and bring findings whole – you decide about payment each time. That's the Private Bug Bounty. The model →
Standard process
A bounded project with a scope and a report, re-tests agreed separately: penetration testing first among them, and a whole shelf of others below. The pentest page →
Pick the shape, and the rest is details. Not sure which fits? That's a fine question to discuss.
A standard process that isn't a pentest?
Here's the shelf. The left column is what a client asks for; the right column is a real engagement already delivered in that area. The list keeps growing – and it can grow with the service you need.
| Ask for | Already delivered |
|---|---|
| Web application pentest | A decade of full-cycle testing, from scoping to exploitation and remediation validation; OSWE-backed white-box depth. |
| Mobile application pentest (iOS / Android) | App and binary testing including reverse engineering, mapped to OWASP MASTG / MASVS; GMOB. |
| API pentest | OWASP API Top 10, a standard part of full-cycle engagements. |
| Network, Active Directory & infrastructure | Large enterprise networks with BloodHound attack-path mapping and AV/IDS/IPS evasion; an engagement inside one of Europe's largest telecom providers. |
| Cloud pentest (AWS / Azure / GCP) | All three major platforms, in client engagements. |
| Secure source-code review | Java, Python, Go, Node.js, PHP, .NET, Erlang; two half-year review engagements on a national healthcare system, plus many smaller ones. |
| Enterprise PKI & cryptography assessment | A production post-quantum rollout delivered – ML-DSA (FIPS 204), design advisory plus post-implementation audit; two penetration-testing engagements for a central-bank-grade financial regulator; a B.S. in Applied Cryptology. |
| Red team / adversary emulation | Emulation mapped to MITRE ATT&CK; built and ran a Big-4 offensive security practice – 10+ testers, ~200 engagements a year. |
| AI / ML red teaming | Application-layer testing mapped to MITRE ATLAS – prompt injection, model evasion – on production ML-powered platforms. |
| Real-time communications (WebRTC / VoIP) | Original WebRTC Top-10 research, presented at OWASP Columbus – recorded. |
| IoT / hardware device testing | Hands-on device work; technical mentor at an IoT Village CTF. |
| Configuration review | CIS Benchmarks up to DoD STIG level, under NIST 800-37. |
| Phishing & social engineering | Campaigns designed and run inside long-term client engagements. |
| Incident response | End-to-end casework: DarkGate malware, business email compromise, a production platform incident. |
| Exploit & vulnerability research | 12+ CVEs, published 0-day write-ups, the "MakeSense" Hack The Box machine, OffSec lab content – the Responsible Disclosure Lab. |
Standing commitments
- One-business-day response to any project message, both directions – and strict scope discipline: out of scope means out of scope, reconfirmed before any disruptive step.
- An auditor-friendly paper trail, with General Liability and Professional Liability insurance in force and a sanitized sample report available on request.
- Reports in your working language. I work in three – English, Ukrainian, Russian – so the findings read the same in the boardroom and in the dev channel.
Pricing
An old joke first. A banker tells a hacker: "Break into my bank." Five minutes later the hacker says, "Done." "Well done," says the banker, "go to accounting and tell them: worked five minutes."
It's really hard to predict the hourly rate. The American Fund for Ukrainian Reconstruction receives my help for free. Another commercial business pays me $5,000.00 for the three hours of an urgent investigation when they need me most. Standard penetration testing engagements usually cost between $3,000.00 and $15,000.00 – about $1,000.00 for a well-structured, predictable day. The Private Bug Bounty brings issues in at $1,000.00 to $3,000.00 apiece.
The best price prediction works on the Advisory package, which is optimized for annual budgeting, usually between $36,000.00 and $96,000.00 a year. It creates a firm, reliable structure that stays intact no matter what kind of urgency comes up during the contract.
Book a consultation