DEVAesia

Application security, software development, and automation

I review web applications and APIs, build internal tools, and add focused checks to CI/CD. Findings are validated, remediation is clear, and the work fits the release process already in place.

See selected work Discuss the work

  • Web applications
  • APIs
  • Architecture
  • CI/CD

01 / Work

Selected work

Current tools and publishing projects, with concise notes on what each one does.

webscan.dev homepage with a website scan field and public, passive scanning status.

tool

webscan.dev

A non-intrusive scanner that turns public posture signals such as TLS, headers, and exposed files into readable next steps.

  • Web security
  • Assessment
  • Developer tooling
safebin.dev access screen with public and owner paths for creating an encrypted paste.

tool

safebin.dev

End-to-end encrypted text sharing where the browser holds the key and the server only ever stores a ciphertext envelope.

  • Encryption
  • Privacy
  • Developer tooling
alexmacra.com homepage with a grid of recent cybersecurity investigations and analysis.

writing

Techsplicer

Developer-focused cybersecurity analysis and practical guidance.

  • Writing
  • Cybersecurity
  • Research

View every project

02 / Engagements

Build, assess, automate.

Start with a clear scope and leave with a usable handoff.

  • Development

    Web software and internal tools with readable code, safe defaults, and maintainable security controls.

  • Assessment

    Targeted penetration tests and reviews for web applications, APIs, architecture, and delivery pipelines. Findings include validated issues and clear remediation.

  • Automation

    Focused CI/CD checks for dependencies, configuration, baseline scanning, and regressions. Each failure should make the next action clear.

03 / Method

Scope. Work. Verify. Handoff.

The work stays bounded, testable, and ready for the next person.

  1. Scope

    Name the system, the allowed boundaries, the risks, and the result this work needs to produce.

  2. Work

    Build the software or test the exposed paths. Stay inside the agreed scope.

  3. Verify

    Reproduce each finding. Test each change. Check the released artifact when deployment is in scope.

  4. Handoff

    Leave the code, findings, and next actions in a form the team can keep using.

04 / Writing

Field notes and articles

Build-time snapshots from the cybersecurity archive at alexmacra.com.

From alexmacra.com

View all writing

05 / FAQ

Frequently asked questions

The short version of how assessments, automation, and development work.

What security assessment services do you offer?

Vulnerability assessments, targeted penetration tests, secure architecture reviews, API testing, and pragmatic hardening guidance. The focus is on validated issues with clear remediation.

How does your security automation work?

I integrate focused checks into CI/CD and developer workflows, including dependency signals, configuration checks, baseline scanning, and guardrails that reduce regressions.

How does webscan.dev help?

webscan.dev provides quick, non-intrusive posture signals around areas such as TLS, headers, and public files. Deeper testing pairs those signals with a scoped manual assessment.

Do you offer custom security solutions?

Yes. I can build custom checks, internal tools, and automation around a specific stack, particularly when an off-the-shelf product does not fit the delivery workflow.

Can you work with an existing development workflow?

Yes. The aim is to work with the tools and release process already in place so that security findings remain understandable, actionable, and maintainable.

06 / Get in touch

Bring the difficult part.

Tell me what you are building, what is uncertain, and what a useful outcome would look like.

Good starting points

  • Targeted penetration test or AppSec review
  • Secure headers and TLS hardening
  • CI/CD security automation
Email mail@devaesia.com