Most security reports fail at the last step. The testing is fine, the findings are real, and then the remediation section says "implement proper input validation" — and a developer with four other tickets has no idea what to change.
My background is the reason my reports do not read that way. Before security, I shipped mobile and web applications: 50+ apps to the Play Store and App Store, five years of production code, release cycles, hotfixes and the specific feeling of finding out that a thing you built handles money badly. That experience is what lets a finding land as a diff instead of a lecture.
How I work
- One named consultant does the testing, writes the report and runs the remediation call.
- Findings are shared as they are confirmed — critical issues the same day, never held for the report.
- Every engagement is fixed-scope and fixed-price, with the number of testing days stated in the proposal.
- Every fixed finding is retested free within 30 days, and the report is reissued with closure status.
- Evidence is minimised, stored encrypted and destroyed 90 days after closure unless you ask otherwise.
What I do not claim
Plenty of security marketing is unfalsifiable. Here is the opposite: I am one person, not a team. I do not run a 24/7 SOC, I do not sell managed detection, and I do not issue compliance certifications — that requires an accredited auditor, and anyone telling you otherwise is selling you a PDF. For red teaming at national-infrastructure scale, or physical and social engineering programmes, you want a larger firm and I will say so.
Areas of focus
- Penetration testing
- Mobile application security
- Android security
- iOS security
- OWASP MASVS
- OWASP ASVS
- OWASP API Security Top 10
- Secure code review
- Threat modelling
- Cloud security
- DevSecOps
- Reverse engineering
- Vulnerability assessment
- Application security
Background & credentials
50+ apps shipped to the Play Store & App Store
abinantony.io · 2019–present
VerifiedFormal certifications in progress are not listed here until they are awarded and verifiable. Ask directly and you will get a straight answer about what is held and what is not.