~/appsecaudit/work.txt

Work

The company is new. The work is not.

20+
years hands-on
4-5
assessments / year
15+
public talks

0x01 / PRIVATE ASSESSMENTS

Client work stays with the client.

Recent work includes manual web application penetration testing and secure code review. Client names, scopes, and reports remain private unless publication is agreed.

focus:
web applications / APIs / code
delivery:
pentesting / code review
disclosure:
private / NDA

0x02 / ONGOING RESEARCH

Curiosity continues.

Offensive security research runs alongside client work. It favors meaningful findings and responsible disclosure over volume or platform rankings. Some work becomes public; much of it stays private until sharing is useful and safe.

blog:
vavkamil.cz
CVEs:
2+ assigned
articles:
13+ published
talks:
15+ across 13+ years
findings:
hundreds responsibly reported
channels:
direct disclosure / bug bounty