Tushar Daga
confievil · co-founder
Two people, testing by hand. Web, API, mobile, AI, cloud, network and red team engagements, run by hackers who find real bugs for a living. You get exploits your engineers can reproduce, not a scanner export with the severities turned up.
Vulnerabilities found and reported to
Services
Every engagement is manual and scoped to your system. You get a report your engineers can act on, and a retest once you have fixed things.
Multi-tenant platforms. Every role tested against every tenant.
BOLA, BFLA, mass assignment, and the endpoints your docs forgot.
The binary, and the backend it actually talks to.
Prompt injection, tool abuse, and the blast radius afterwards.
IAM paths to privilege, and what one leaked key really reaches.
Perimeter and internal segments. What is exposed, and what chains.
Goal-driven. Tests whether anyone notices, not just whether a bug exists.
White-box, alongside the test. The bug classes traffic never surfaces.
Retest after your fix is included in every engagement, not billed separately.
Who you work with
From scoping through retesting, experienced security practitioners stay directly involved. Every finding is manually validated, clearly documented, and discussed with your engineers—without layers of account management getting between your team and the people doing the work.
confievil · co-founder
kxddah · co-founder
Vulnerabilities found and reported to
Reported through bug bounty and coordinated disclosure programmes. The reports are not public; we can walk you through the details under NDA.
Writings
Dart ships its own TLS stack and its own trust store, so the system proxy and the usual hook scripts both miss it. Here is where the verify function actually lives, and how to find it by anchor instead of by a borrowed signature.
Contact
A rough scope is enough to start. We will come back with what we would test, how long it takes, and a price. If we are not the right people for it, we will say so.
PGP [KEY FINGERPRINT]
NDA before scope, always.
We reply within [N] business days.