GuaranteeFull refund if no validated High or Critical finding

Every system looks safe from the surface.

I test what is underneath. Penetration testing, red teaming and AI security for banks, ministries and digital platforms across Asia. One senior tester, from the first call to the closure letter.

DATAAPICLIENT123CUSTOMER RECORDS
Attack path · representative engagement
The problem

Most pentests look safe from the surface, too.

A scanner export, reformatted.

Four hundred informational items and a new cover page. The business-logic flaws that actually lose money never appear in it.

The tester you met is not the one testing.

Whoever is free that week, often a junior with senior “review”.

Criticals wait for the final report.

Found on day two, reported in week four. Your exposure lasts as long as their template does.

Do you really know what can be reached from the internet?

Portals, wallets, APIs, admin panels and the AI features added last quarter. I find the path to your customer records before someone else does.

9.8Highest severity found: full database access through SQL injection
6+Years testing banks, ministries, gaming and e-commerce
100%Of findings retested after the fix, free, with a closure letter
I scoped and sold agency pentests for years. I know exactly where they leak.
The approach

Four steps, from briefing to closure letter.

Testing runs on UAT or staging. A critical reaches you the day it is found, not at the end.

Brief
Day 1

Thirty minutes. What the system does, what would hurt most if it broke, and what must never be touched.

Permit
Days 3–5

NDA, authorisation and rules of engagement, already filled in. You sign, we fix the dates.

Test
Weeks 2–3

By hand, on UAT. A status note every day. A critical reaches you the same day, with a mitigation.

Close
Week 4

Report within three days, then a walkthrough. You fix, I retest free and sign the closure letter.

Pricing. Fixed per engagement, quoted in writing within two working days of the briefing. No hourly surprises. Retest and walkthrough included.

Book the briefing
Findings

Five findings from real engagements.

In the format you would receive them. Each one was reported, fixed by the client and retested by me. Names removed under NDA.

Critical

Full database access through SQL injection

Component
Search endpoint, customer-facing portal
Impact
Customer credentials, phone numbers and admin records extracted. Write access demonstrated on a single test record, to show how far it actually reached rather than report a “vulnerable parameter” and leave the client guessing what it meant.
Remediation
Parameterised queries throughout the endpoint, and a least-privilege database role that cannot write to privileged tables.
FoundReported same dayFixedRetestedClosure letter
What you receive

Three deliverables, all in the fixed price.

Findings, with proof

Manual testing of your logic, your roles and your workflows. Every finding comes with a working proof of concept, not a theory.

Not a scanner export with 400 informational items.

A report for two readers

Page one for the board. The rest for your engineers: CVSS, steps to reproduce, evidence and the fix.

Not a 90-page PDF nobody reads.

A closure letter for your auditor

You fix. I retest, free. Then I sign a closure letter you can file with NBC, ISO 27001 or PCI DSS.

Not “retest available at additional cost”.

Services

Twenty-five scopes, one accountable tester.

Each one written against a published standard: OWASP ASVS and MASVS, PTES, NIST SP 800-115, MITRE ATT&CK and ATLAS.

Applications

  • Web applicationPortal, admin panel, e-commerce
  • Mobile appiOS & Android
  • APIREST, GraphQL, partner integrations
  • AI / LLM featureChatbot, RAG search, agents
  • Smart contract auditSolidity, Move, Rust

Infrastructure

  • External networkEverything the internet can reach
  • Internal network & ADOffice network, Active Directory
  • CloudAWS / Azure / GCP
  • KubernetesCluster and workloads
  • Vulnerability assessmentWhole estate, triaged by hand
  • Attack-surface monitoringContinuous, alerts on change
  • Blockchain platformNodes, custody, exchange
  • IT infrastructure auditAgainst NBC, ISO 27001, CIS

Configuration & code

  • Source code reviewManual, with the developers
  • Host configurationServers against a CIS baseline
  • Firewall configurationRule base and segmentation
  • Cloud configurationAWS accounts against CIS Benchmarks
  • System hardeningPlan, apply, verify

People & programme

  • Phishing & awarenessCampaign plus the session after
  • Red teamWould you survive a real attack?
  • Compliance pentestNBC, ISO 27001, PCI DSS
  • Executive briefings & tabletopsDecisions rehearsed, not improvised
  • Purple teamDetections written in the room
  • Vulnerability managementFindings tracked to closure
  • Incident response retainerSigned before you need it
About

One tester. The name on the report is the person who did the work.

Chamroeun Chhor, principal penetration tester at Mehsao Security
Chamroeun ChhorPrincipal Penetration Tester · Lecturer, Institute of Technology of Cambodia

Six years attacking systems with permission. Core banking and mobile wallets at national-payment scale. Ministry platforms in live production. Gaming and e-commerce, where a logic flaw is a direct financial loss.

I led testers and priced engagements at a regional firm, so I know where agencies cut corners. I lecture at ITC, coached a national-CTF runner-up team, and have briefed close to a thousand officials. Phnom Penh based, working in Khmer and English. Mehsao (មេសោ) is Khmer for master key.

  • Since 2026Cybersecurity Lecturer · Institute of Technology of Cambodia
  • Since 2025Senior Penetration Tester · Loma
  • 2025–26Penetration Tester Lead · MISTI: public-service systems in production
  • 2022–25Security Engineer & PreSales Lead · Veilron: engagements across Asia
  • 2021–22Cyber Risk Advisory · Deloitte: Bakong wallet, core banking & paygate code review

Team certifications

eWPTeMAPTCRTPCOAECPSAOSCCCPTSCWEECWES
Start here

Tell me what worries you.

Test plan and fixed price in two working days. I reply within one working day, and the redacted sample report is yours either way.