I build production mobile and web applications end to end: data model, backend, the apps themselves and the App Store and Google Play release. I also test web applications, APIs, smart contracts, blockchain infrastructure and AI/LLM features the way a real adversary would: manual, hypothesis-driven, and proven with a working proof-of-concept. Every security engagement ends in a report you can hand to engineers and auditors, so you can hire me to ship the product as well as to break it.
Two practices, one person. Hire me to test what you have built, to build something new, or both, since the cheapest security fix is the one designed in from the start.
iOS and Android from one React Native / Expo codebase, through App Store and Google Play review.
Customer-facing web apps, admin consoles and marketing sites in Next.js / React and TypeScript.
Serverless backends on Firebase / Google Cloud with least-privilege rules and secrets handled properly.
Black-box or grey-box testing of production or staging systems against OWASP Top 10 and beyond.
Manual review with invariant-first analysis and fork-tested proofs-of-concept.
The layer most audits skip: nodes, RPC namespaces, bridges, relayers and consensus code.
Assessment of assistants, agents and RAG pipelines that touch private data or take actions.
Security-minded full-stack development. I design the data model, write the backend rules and functions, build the apps, get them through App Store and Play review, and keep them running.
Customers book identity-verified repairmen, technicians and service professionals at a fixed, published price, then follow the job live on a map from accepted to paid. Partners apply in-app, pass ID-card and background checks, and manage jobs, earnings and warranty from their own side of the same app. Built solo, from first commit to store submission, in about ten weeks.
Next.js 16 · React 19 · Tailwind v4 · static export · Firebase Hosting
Bilingual TH/EN venture-studio website with route-based localisation, typed copy dictionaries and a static build that survives without JavaScript. phenovative-web.web.app
Hand-written HTML/CSS/JS · Firebase Hosting · in-page PDF viewer
Zero-framework, theme-aware, filterable portfolio with deep-linkable report viewer and strict response headers. Loads in one request.
Python · Node · Playwright · Foundry · Anchor
Custom recon and API-surface mappers, JS-bundle miners, fork-based exploit harnesses and PDF report generators used across the 96 engagements above.
Every engagement below ran under an authorized bug-bounty or audit-competition program. Click a card to read the research summary. Reports were issued under my research label, Phoenix5981 Security. Engagements still under vendor review are listed without identifying detail.
Outcome labels are the platform's verdict, not mine. "Duplicate" means the vendor confirmed the issue but another researcher reported it first; "Known issue" means the vendor already tracked it internally. Both are listed because the finding was real and demonstrated. Zero-finding engagements are published too: knowing what was tested and cleared is a deliverable.
A short call, then a written scope: users, screens, data, integrations and what is out. You get a fixed price per milestone before any code is written.
Screens as a clickable prototype, with the database structure and security rules designed together, so permissions are built in rather than patched later.
Working software at every milestone, deployed to a test link you can open on your phone. Code lives in your repository from day one.
Automated checks, real-device testing and a pentest of the finished product by the person who built it, before real users arrive.
Production deploy, App Store and Google Play submission, admin access, documentation and a handover session. A maintenance retainer is optional.
Map every entry point, trust boundary and privileged role before touching a payload. Read prior audits and known issues first so effort goes to the un-audited delta.
Subdomain and host enumeration, JavaScript bundle mining, API surface extraction (typically 150 to 300 endpoints per target), commit-history analysis for code targets.
Hypothesis-driven, checklist-backed testing: auth and session, authorization boundaries with two independent tenants, business logic, economic invariants, signature schemes, boundary arithmetic.
Every reported issue ships with a minimal proof-of-concept run from the attacker's position, on a fork or an isolated test tenant, that demonstrates the impact rather than the defect.
Severity with dollar or data impact, reproduction steps, root cause, specific remediation. One free retest round once fixes land.
Fixed price per job, agreed after a 30-minute scoping call. Prices are in USD; invoices can be issued in USD or THB.
1–2 weeks
Data model, the key screens as a clickable prototype, a backend plan and a fixed estimate for the build.
4–6 weeks
One platform (mobile or web) with its backend and admin basics, ready for real users.
8–12 weeks
iOS + Android + web + backend + admin console, including store submission and a security review of the result.
up to 4 days per month
Releases, monitoring, bug fixes and small features for an app you already run.
| Development rate card | |
|---|---|
| Hourly | $45 / hour, 10-hour minimum block |
| Day rate | $350 / day |
| Payment terms | Milestone-based: 30% on kickoff, then per milestone. Bank transfer, Wise, or USDC. Code delivered in your repository from day one. |
Every build ships with the security basics done properly: least-privilege database rules, server-side validation, secrets kept out of the client, and a pentest of the finished product at no extra charge.
5–10 days · typical $2,500–5,000
One application or API surface, grey-box with test accounts. Best for SaaS, fintech dashboards, exchanges and marketplaces before a launch or compliance audit.
1–3 weeks · scoped by lines of code
Manual review with invariant definition, fork-tested PoCs and a fix-review round. Suitable as a second opinion after a primary audit. Indicative: $4k for up to ~1,000 lines, $8–15k for a full protocol.
2–4 weeks
Contracts + backend + frontend + AI features together, since real attacks chain across them. Includes bug-bounty scope and policy drafting.
up to 5 days per month
Continuous review of releases, PR-level security review, incident triage and on-call reproduction of externally reported bugs.
| Security rate card | |
|---|---|
| Day rate (time & materials) | $450 / day |
| Hourly (advisory, code review, triage) | $60 / hour, 4-hour minimum |
| Retest of fixed findings | Included, one round within 60 days |
| Rush (start within 48 hours) | +25% |
| Pay-per-finding option | Bug-bounty style: no upfront fee, paid per validated finding by severity. Ask for the schedule. |
| Payment terms | 50% on kickoff, 50% on report delivery. Bank transfer, Wise, or USDC. |
All testing happens only against systems you own or are authorized to have tested, under a signed statement of work and NDA. Prices exclude VAT where applicable.
I spent eighteen years in industries where mistakes are expensive before I wrote software for a living. From 2004 to 2011 I was an engineer in precision electronics manufacturing: R&D engineer at Fujitsu (hard-disk drives, 2004–2005), process engineer at Delta Electronics (PCB assembly, 2005–2006) and Nidec (electric motors, 2006–2007), maintenance engineer at Rohm Integrated (semiconductors, 2007–2009), quality engineer at Sony (DSLR cameras, 2009–2011). From 2011 to October 2022 I was a flight dispatcher at Thai Airways International — planning and releasing commercial flights, and making time-critical calls inside a safety-critical regulatory framework. Both are worlds where a silent failure is the expensive kind and nothing counts until it is verified against the real article.
In 2022 I started teaching myself software, beginning with Java through Coursera, freeCodeCamp and open courseware, then JavaScript and TypeScript, React and React Native, Node.js, data structures and cloud architecture. By 2026 that had turned into shipped work: FixIt, a two-sided home-services marketplace I designed and built alone and released on iOS, Android and the web, and, since May 2025, a security practice running authorised engagements on 18 bug-bounty and audit platforms. The two feed each other — testing other people's systems changed how I build my own, and building production systems is why my reports come with remediation an engineering team can actually apply.
Timeline: BEng Electrical Engineering, KMUTNB (1999–2003) · electronics manufacturing engineering (2004–2011) · flight dispatch, Thai Airways International (2011–2022) · self-directed software study from 2022 · independent software and security practice since May 2025.

Send a short description of the system, the tech stack and your deadline. I reply within one business day (UTC+7).