Uplentic
HomeServicesMethodologyAboutContact
Why me

Reports people read. Bugs that get fixed.

No scanner dumps, no jargon-heavy PDFs — just one researcher finding what matters and helping you close it.

  • Manual, not automated

    I don't run a scanner and call it a pentest. Every engagement involves human analysis. Scanners miss business logic. I don't.

  • Reports built for developers

    Every vulnerability comes with a reproduction path, a code snippet, root cause, and a fix. Your developers can act immediately.

  • Direct contact, no middleman

    You talk to the person doing the audit, from scoping to retest. No project manager, no outsourced junior, no surprises.

  • NDA first, always

    I sign the NDA before any exchange. Your code, your data, your results — strictly confidential. No exceptions.

Credentials

Backed by certified, independent research

Lead certificationOSCP
Independent researchActive on HackerOne & YesWeHack
Reporting standardIndustry severity scoring
ConfidentialityNDA before scoping
Track record

What the work actually looks like

No client testimonials yet — Uplentic is a new practice. Here's what's verifiable today.

OSCP certified

Offensive Security Certified Professional — hands-on exam, no multiple choice.

Active bug bounty hunter

Independent researcher on HackerOne and YesWeHack, with reports across multiple live programs.

Conference speaker

Spoke on the CXO track at Nullcon Goa 2026.

Top-3 detection engineering

Ranked top three on the detections.ai CQL leaderboard.

Published training content

Authored three OffSec Proving Grounds practice labs used by other pentesters preparing for OSCP.

Real disclosure history

Confirmed findings across bug bounty and VDP programs, from CORS misconfigurations to exposed internal tokens.

Common questions

Frequently asked

How long does a typical engagement take?

Most single-application engagements run 1–3 weeks depending on scope. Larger or multi-target engagements are scheduled after a scoping call confirms the full surface.

What do I receive at the end?

A written report with every finding scored by severity, clear reproduction steps, and remediation guidance — walked through live with your team on a debrief call.

Is retesting included?

Yes. Once your team ships fixes, I retest every finding at no additional cost within the agreed remediation window.

How is my data protected during testing?

I sign an NDA before any scoping details are exchanged, and testing is confined strictly to the agreed rules of engagement.

Do you test production environments?

I can, with clearly agreed rules of engagement and safeguards. Many clients prefer a staging environment that mirrors production instead.

Ready to start?

Tell me what you want tested, or call me directly. I reply within a few hours.

Book a call