Independent bug bounty researcher. I find the bugs others assume don't exist — then I hand them back politely. Currently hunting in API layer, auth flows and everything between the browser and the database.
- Fintech / payments — API security, access control, IDOR in transaction flows
- E-commerce marketplace — horizontal privilege escalation, checkout logic
- SaaS platform — auth bypass, session handling, GraphQL attack surface
- Healthcare portal — PII exposure, broken object-level authorization
Scope and program names stay private until disclosure is complete.
- Praket AI — multi-provider LLM chatbot with unified routing across models and APIs
- Dhristi AI — satellite image change detection for earth observation analysis
Notable findings — redacted until disclosure completes
- IDOR in account recovery flow — HackerOne · triaged · fixed
- JWT algorithm confusion leading to auth bypass — Bugcrowd · accepted
- GraphQL introspection + field-level access control gap — YesWeHack · confirmed
- Mass assignment on user profile endpoint — private program · fixed
Scope, responsible disclosure, and patience — in that order.