Manual testing across applications, infrastructure and AI
I test the systems in scope, follow attack paths across their boundaries and stay through the engineering walkthrough and retest. Audit evidence, white-label delivery and training are available when the engagement needs them.
Frequently asked
Do you sign NDAs?
Always, before any scoping call that touches sensitive info. I have a standard mutual NDA I can send, or I sign yours.
Do you work directly with clients or through security companies?
Both. Most engagements are direct, but I also collaborate with security consultancies that outsource specific pentests when they need extra hands or a specialist profile. Either way you get the same person doing the work.
How much does a pentest cost?
A focused web or API engagement usually takes one to two testing weeks; multiple applications, roles or environments take longer. I send a fixed quote after reviewing the endpoint count, roles, integrations and test environment. The quote includes reporting, the engineering walkthrough and one retest.
Do you work with small companies or only enterprises?
Both. A smaller SaaS usually starts with one application or API; a larger organization may split the work by product, environment or business unit.
When are you available?
I take a limited number of engagements a year, which is why the lead time is 4 to 8 weeks and why the person who scopes the work is the person who does it. For urgent engagements, ask: slots open up.
Do you carry professional indemnity insurance?
Yes, professional indemnity cover specific to penetration testing work. I can send the certificate before we sign anything. Procurement asks for it more often than not, so it is easier to have it on the table early.
Conference talks & speaking
Available for talks at conferences, universities and meetups. Topics: offensive security, bug bounty methodology, CVE research, LLM red teaming, careers in security. Bilingual (English / Spanish). In-person in Spain, remote everywhere else.
Tell me what needs testing
Send the application, roles, target date and reason for the test. I will confirm whether I can cover it and what I need to quote it.