Founder Involvement
Scope, testing decisions, validation, and reporting remain connected to senior review.

Application Security Consultant
Founder, The Hidden Finds
The Hidden Finds was created after seeing a recurring problem across modern SaaS platforms and APIs:
Organizations often receive security reports filled with scanner output, while the vulnerabilities that actually matter remain undiscovered.
The focus became simple: identify real attack paths, validate exploitability, and provide findings that engineers can act on.
Direct senior involvement and practical product understanding without layers of generic delivery.
Scope, testing decisions, validation, and reporting remain connected to senior review.
Automation supports coverage, while important behavior and exploitability are validated manually.
Findings are interpreted through roles, tenant models, sensitive data, and business workflows.
Reports prioritize reproduction, impact, remediation clarity, and efficient retesting.
Good security work should make product risk clearer, not bury teams beneath more output.
Findings should represent realistic attack paths rather than theoretical weaknesses.
Security testing must understand how systems behave in practice.
Reports should help engineering teams make decisions, not create confusion.
Every finding should include actionable guidance and retesting support.
A steady focus on practical application security, direct delivery, and findings that improve real products.
Founded with a focus on practical application security testing.
Expanded across SaaS applications, APIs, authentication, and access control reviews.
Strengthened focus on IDOR, broken access control, business logic abuse, and API security.
Built deeper review workflows for SaaS and product teams.
Expanded structured services, positioning, and security consulting delivery.
Founder-led reviews focused on exploitability, product risk, and engineering-ready remediation.
Focused expertise for security-sensitive product behavior across modern SaaS and API systems.
REST and GraphQL authorization, object access, token scope, and data exposure.
Role boundaries, ownership checks, tenant isolation, and privilege escalation.
Login flows, sessions, recovery, token handling, and account takeover paths.
Valid product actions that can be chained or manipulated into unintended outcomes.
Manual testing across critical features, sensitive data paths, and user flows.
Validated weaknesses, exposed assets, prioritization, and remediation direction.
Get practical security guidance grounded in real attack paths, business impact, engineering communication, and remediation support.