dgxcode

independent offensive security

I find the bugs scanners miss.

Dgxcode is an independent security researcher and bug bounty hunter. Manual testing for web, API, mobile, and LLM-powered products — authorization flaws, business-logic abuse, injection, and agent tool-calling misuse, written up so your team can actually fix them.

Focus
Web apps, REST & GraphQL APIs, Android/iOS clients, LLM agents
Method
Manual, scope-fixed testing. No scan-only reports.
Output
CVSS-ranked findings, redacted proof of concept, remediation notes, retest of fixes.

What I do

Offensive testing

Black- and gray-box penetration tests against staging or production with written authorization. Goal: the flaw an attacker chains, not the 400 informational rows a scanner prints.

Details on the services page →

Secure code review

Targeted review of authentication, authorization, crypto, secret handling, injection sinks, and dependency risk — reported per file and line with a suggested patch.

Details on the services page →

AI & agent security

Adversarial review of LLM features: direct and indirect prompt injection, tool-calling abuse, SSRF through agents, training-data leakage, and guardrail bypass. Mapped to the OWASP LLM Top 10.

Details on the services page →

How I work

  1. Scoping — assets, roles, endpoints, environment, timeline.
  2. Written authorization — rules of engagement, test accounts, maintenance window.
  3. Manual testing — hypothesis-driven, business logic first.
  4. Report — findings, CVSS, redacted PoC, remediation.
  5. Retest — fixes re-verified within 30 days of the report, no extra fee.

Disclosure

Vulnerabilities are handled as coordinated disclosure. Targets are named only after a fix ships or the vendor publishes an advisory, and published write-ups never include a working exploit or customer data. Found something in a Dgxcode property? Send it to security@dgxcode.com — the policy is on the contact page.