$ whoamitanmay · founder, ElCampeon Systems$ cat focus.txtweb apps · APIs · Android · AI security$ ls certs/CEH-Practical CPENT-AI$ cat training.txtHTB AI Red Teamer path → COAE$ echo $RULEwritten authorization, every time
Background
Breaker first. Builder too.
Engineering and business training, three years of hands-on security work, and apps in production.
Security work
Three years of web application and API security
Reports vulnerabilities through bug bounty programs on HackerOne and Bugcrowd, and through companies' own disclosure programs. Focus on access control, authentication and API authorization flaws.
Details of past findings are shared on request, within each program's disclosure rules.
Certifications
EC-Council
CEH (Practical) Certified Ethical HackerCPENT AI Certified Penetration Testing Professional
Training now
HTB Academy AI Red Teamer path
Working toward Hack The Box's COAE certification.
In progressEducation
BTech, Computer Engineering
Plus an MBA in Marketing, so findings get explained in terms the business cares about.
Building
Three apps on Google Play
Android learning apps, free to download and written with Claude Code. See the apps.
Testing other people's apps shows how often the same flaws reach production. Building our own keeps us honest about how hard they are to avoid. ElCampeon does both on purpose, and each side makes the other better.