Manual, not automated
I don't run a scanner and call it a pentest. Every engagement involves human analysis. Scanners miss business logic. I don't.
Reports built for developers
Every vulnerability comes with a reproduction path, a code snippet, root cause, and a fix. Your developers can act immediately.
Direct contact, no middleman
You talk to the person doing the audit, from scoping to retest. No project manager, no outsourced junior, no surprises.
NDA first, always
I sign the NDA before any exchange. Your code, your data, your results — strictly confidential. No exceptions.
Backed by certified, independent research
What the work actually looks like
No client testimonials yet — Uplentic is a new practice. Here's what's verifiable today.
OSCP certified
Offensive Security Certified Professional — hands-on exam, no multiple choice.
Active bug bounty hunter
Independent researcher on HackerOne and YesWeHack, with reports across multiple live programs.
Conference speaker
Spoke on the CXO track at Nullcon Goa 2026.
Top-3 detection engineering
Ranked top three on the detections.ai CQL leaderboard.
Published training content
Authored three OffSec Proving Grounds practice labs used by other pentesters preparing for OSCP.
Real disclosure history
Confirmed findings across bug bounty and VDP programs, from CORS misconfigurations to exposed internal tokens.
Frequently asked
How long does a typical engagement take?
Most single-application engagements run 1–3 weeks depending on scope. Larger or multi-target engagements are scheduled after a scoping call confirms the full surface.
What do I receive at the end?
A written report with every finding scored by severity, clear reproduction steps, and remediation guidance — walked through live with your team on a debrief call.
Is retesting included?
Yes. Once your team ships fixes, I retest every finding at no additional cost within the agreed remediation window.
How is my data protected during testing?
I sign an NDA before any scoping details are exchanged, and testing is confined strictly to the agreed rules of engagement.
Do you test production environments?
I can, with clearly agreed rules of engagement and safeguards. Many clients prefer a staging environment that mirrors production instead.
Ready to start?
Tell me what you want tested, or call me directly. I reply within a few hours.