
01Des Moines, Iowa
Targets that aren't a website
Connected farm machinery, in Des Moines. When the target has no browser, half of what you know about web work is useless and you pick up the protocol as you go.

Security researcher · Software engineer
I'm Javier Corral. I report vulnerabilities to bug bounty programs and build software for companies. I've been doing both at once for years.
OWASP WSTG · ASVS
Live hacking events
Edge-first engineering
Vulnerabilities reported and accepted at
And other Fortune 500 companies, through their bug bounty programs.
See the reports on HackerOneThey're two different jobs, but they feed each other. Once you've watched a system come apart from the inside, you design differently.

Live hacking event · Singapore
Bug bounty and manual pentesting. Scanners find what's already catalogued; the rest sits in business logic and in chaining flaws that are worth nothing on their own. Every finding comes with a proof of concept you can reproduce.
Multi-tenant SaaS, payment integrations and applications your team will have to maintain long after I'm gone. I write with that in mind, and with the security work done before the first release.
Performance, slow queries and cloud bills that grew while nobody was watching. I measure first and change things second; where it pays off, the deployment moves to the edge to sit closer to whoever is using it.
On the ground

01Des Moines, Iowa
Connected farm machinery, in Des Moines. When the target has no browser, half of what you know about web work is useless and you pick up the protocol as you go.

02Ambassador World Cup 2024
I finished first in the Championship Finals of HackerOne's Ambassador World Cup, with the Spanish team. You compete as a team: targets get split, everything that turns up gets shared, and the individual score comes out of that.
See the leaderboardLive hacking
H1-65: HackerOne put a room of researchers in Singapore for three days to hack OKX live. The video is from that event.
Work
No sales rep in front, no junior behind doing the work. You talk to the same person from start to finish.
Web and API pentesting, audits and recurring reviews. OWASP methodology, plus the things that work in bug bounty and aren't in the guide.
Web development, custom SaaS and integrations with the systems you already run. The security review is included in the price.
Performance, databases and the cloud bill. I start by measuring, and you get the before and after when it's done.
A pentest, an audit, a product you want to ship, or just a bug you've found and can't tell how bad it is. Write, and I'm the one who answers.
Response time
Under 24 business hours
Research
hackerone.com/corraldev ↗