Currently accepting new security engagementsRequest a scope
Case studies

What the work looks like, with the client removed

Security findings from real testing, with identity, product names, endpoints and payloads stripped out and the reasoning left in. Alongside them, honest walkthroughs of how DevOps, web and SEO engagements run, so you can judge the method before you commit to it.

Nothing published under embargo·No invented metrics·No client named without written permission
How to read these. Findings marked as a redacted engagement come from work that was carried out. The client, the product, the affected endpoints and the exact payloads are removed, because publishing those would put a real system at risk and would breach the confidentiality every client is owed. What is left is the vulnerability class, why it mattered and how it was fixed, which is the part that transfers to your system. Pieces marked as a walkthrough describe how a type of work runs. They carry no client and no result, and they are labelled that way so nothing here reads as an outcome that has not happened. Bug bounty research is discussed only where the program has authorised disclosure, so some findings are described by class alone.
Penetration testing

Findings from testing, redacted

Redacted findings from real testing. Client identity, product names and payloads are removed. The vulnerability class and the reasoning stay, because that is the part that transfers.

TRUST BOUNDARYBrowseruser controlledAuthenticationwho is callingAuthorizationis this record theirsDatascoped by tenantMOST OFTENTHE MISSINGCHECK
Redacted engagementCritical

OAuth misconfiguration that allowed one account to be linked to another

A SaaS platform offering social sign-in alongside email and password login

Single sign-on was configured so that the identity returned by the provider was trusted more than the account it was being attached to. The result was an account linking path that let one identity end up in control of a different user's account. This is the class of issue that reads as a configuration detail and behaves as a full account takeover.

  • OAuth
  • Single sign-on
  • Account takeover
Penetration testingRead it
Redacted engagementHigh

Password reset and session handling gaps found by testing the whole account lifecycle

A multi-tenant business application with invitations, role changes and self-service password reset

Reviewing authentication as a lifecycle rather than a login page surfaced several issues that individually looked minor and together produced a reliable way to hold access to an account after the owner had tried to lock it down. Most of these do not appear in scanner output at all, because every response involved is a legitimate one.

  • Authentication
  • Session management
  • Password reset
Penetration testingRead it
Redacted engagementCritical

SQL injection and stored cross-site scripting behind an authenticated interface

A web application with a reporting interface and user generated content, tested with valid low-privilege credentials

Two classic injection classes, both reachable only after login, which is why neither had ever been reported by an unauthenticated scan. The database defect exposed data across the whole application. The scripting defect ran in the browser of whoever reviewed the affected record, which in this product was always an administrator.

  • SQL injection
  • Cross-site scripting
  • Multi-tenancy
Penetration testingRead it
Redacted engagementHigh

Object references that were checked in the interface but not on the server

A multi-tenant platform where each customer's data is meant to be invisible to every other customer

The application hid what a user should not see and enforced very little of it server side. Interface level restriction is a usability feature. It becomes a security control only when the server independently reaches the same conclusion, and here it did not.

  • Access control
  • Multi-tenancy
  • API security
Penetration testingRead it
Cloud and DevOps

How cloud and devops work runs

How infrastructure, deployment and reliability work runs at Nextralix, from the first audit through to the change being deployed and verified.

CommitBuildTestScandeps + secretsDeployMonitoringROLLBACK, REHEARSED
How this work runs

Taking over a server that was set up quickly and never reviewed

The common starting point: one VPS, configured under launch pressure, running in production ever since

A walkthrough of a Linux and VPS hardening engagement, from the first audit to the point where the server is documented, monitored and provably recoverable. This describes the method rather than a specific client, and no result is claimed for it.

  • Linux
  • VPS
  • Hardening
Cloud and DevOpsRead it
Web development

How web development work runs

How a website or store is built and handed over, including the security configuration that a normal web build usually leaves out.

How this work runs

Building a website that is still correctly configured six months after launch

A business site or store where the build is the easy part and the configuration is what gets skipped

A walkthrough of how a WordPress or Shopify project is delivered, including the security and performance configuration that a normal web build usually treats as optional. Method only, with no client result attached.

  • WordPress
  • Shopify
  • Security headers
Web developmentRead it
SEO and growth

How seo and growth work runs

How technical SEO work is scoped, executed and reported, and what is deliberately excluded from it.

PublishedCrawledIndexedthis gap is the workPublishing more does not close it. Fixing what blocks indexation does.
How this work runs

A technical SEO audit that starts with whether your pages can be crawled at all

A site that publishes consistently and does not rank, where the content is not the problem

A walkthrough of a technical SEO engagement: crawlability and indexation first, then architecture, then performance and structured data, with reporting that separates what changed from what merely moved. Method only, with no client result attached.

  • Technical SEO
  • Indexation
  • Core Web Vitals
SEO and growthRead it
How this work runs

Product and collection structure for stores that are invisible below the brand name

An online store that ranks for its own name and for very little else

A walkthrough of e-commerce SEO work: faceted navigation, duplicate product content, collection architecture and the reporting that ties changes to revenue rather than to rankings alone. Method only, with no client result attached.

  • E-commerce SEO
  • Faceted navigation
  • Structured data
SEO and growthRead it

Recognise any of these on your own system?

Most of them are checkable in an afternoon. Describe what you are running and we will tell you which of these applies to you, including when the honest answer is that you do not need us yet.