Offensive testing
Black- and gray-box penetration tests against staging or production with written authorization. Goal: the flaw an attacker chains, not the 400 informational rows a scanner prints.
Details on the services page →independent offensive security
Dgxcode is an independent security researcher and bug bounty hunter. Manual testing for web, API, mobile, and LLM-powered products — authorization flaws, business-logic abuse, injection, and agent tool-calling misuse, written up so your team can actually fix them.
Black- and gray-box penetration tests against staging or production with written authorization. Goal: the flaw an attacker chains, not the 400 informational rows a scanner prints.
Details on the services page →Targeted review of authentication, authorization, crypto, secret handling, injection sinks, and dependency risk — reported per file and line with a suggested patch.
Details on the services page →Adversarial review of LLM features: direct and indirect prompt injection, tool-calling abuse, SSRF through agents, training-data leakage, and guardrail bypass. Mapped to the OWASP LLM Top 10.
Details on the services page →Vulnerabilities are handled as coordinated disclosure. Targets are named only after a fix ships or the vendor publishes an advisory, and published write-ups never include a working exploit or customer data. Found something in a Dgxcode property? Send it to security@dgxcode.com — the policy is on the contact page.