Cybersecurity isn’t just an afterthought, it’s a mindset. I work on your applications, servers and infrastructure to identify vulnerabilities before they can be exploited.

Four years’ experience in penetration testing and vulnerability management. Dozens of audits carried out for SMEs, mid-market companies and large corporations.


My approach

I don’t produce a 100-pages report that ends up at the back of a drawer. I propose a pragmatic approach:

PrincipleIn practical terms
TransparencyYou receive evidence of operation, not just theoretical descriptions.
PriorisationNot all risks are equal. I rank vulnerabilities according to their actual impact.
EnforceabilitySpecific recommendations, including commands or code snippets to fix the issue.
Follow-upI’ll proofread your corrections free of charge.

My work in cybersecurity

Server security audit

Public: IT managers, CIOs, system administrators

Comprehensive analysis of your exposed servers. Open ports, versions, configurations SSH/PF, TLS certificates, backups.

Deadline: 1-2 days | Budget: from 800€ excl. tax

→ Offer details


Web penetration test

Public: Software publishers, e-commerce businesses, tech start-ups

Black-box or grey-box penetration testing on your Web applications. OWASP Top 10 vulnerabilities, business logic, authentication, access control.

Deadline: 3-10 days | Budget : from 2500€ excl. tax (package)

→ Offer details


Linux Hardening

Public: Companies with critical Linux servers

Hardening your existing systems. Firewalls, SSH, SELinux/AppArmor, monitoring, update policies.

Deadline: 1-3 days | Budget: from 1000€ excl. tax

→ Offer details


Vulnerability management

Public: IT teams tasked with sorting through the results of automated scans

Analysis, triage and prioritisation of scan results. You’ll know what to patch first without getting bogged down in false positives.

Terms and Conditions: Fixed-price package or monthly subscription. From 500€ excl. tax

→ Get in touch to discuss your case.


Secure code review

Public: Software publishers, tech start-ups

Source code analysis (Python, Rust, PHP) to detect vulnerabilities before deployment. SQLi, XSS, CSRF, command injections.

Deadline: 1-5 days depending on volume | Budget: From 800€ excl. tax

→ Get in touch to assess the scope.


Why work with me?

Dual technical expertise

I’m not just a listener: I’m a developer. I understand how vulnerabilities are introduced into the code and how they are exploited.

Stack mastered: Python, Rust, PHP, Bash. Linux, OpenBSD, pf, systemd, Docker.


Complete independence

I do not sell any SaaS products, antivirus software or proprietary solutions. My recommendations are impartial and can be put into practice straight away.

No conflict of interest. No commercial partnerships with security software publishers.


Discretion and confidentiality

Sensitive data never leaves your infrastructure during an audit. Reports are encrypted, signed and transmitted via a secure channel.

Signed NDA on demand. Traceability of access and deliverables.


Standard methodology

Phase 1 - Acknowledgement (1-2h) Entretien avec vos équipes techniques. Compréhension du périmètre, des contraintes, des objectifs.

Phase 2 - Penetration testing (depending on the scope) Manual and tool-based testing. Application mapping, exploitation of identified vulnerabilities, attempts at vertical and horizontal escalation.

Phase 3 - Detailed report (3-5 days) Description of vulnerabilities, proof-of-concept exploits, severity, and mitigation recommendations.

Phase 4 - Oral presentation (1h) Presentation to technical and decision-making teams. Q&A, action plan.

Phase 5 - Patch Summary (included) Proofreading of your finalised documents, approval, and adjustments where necessary.


Any questions?

Get in touch to discuss your requirements. We’ll get back to you within 24 hours.