services
I provide expert human security review of AI-generated code and apps, focused on the subtle flaw an automated tester misses.
What I check: unsafe/FFI boundaries and memory-safety in Rust; nonce and key handling; constant-time operations; AES-GCM / ChaCha20-Poly1305 and post-quantum signature use; access control and signed-grant logic. You get a written report of vulnerabilities with reproduction steps and concrete fixes — I prove findings with measurements, not claims.
I am a lawyer as well as a cryptography engineer, and I VERIFY AUTHORIZATION before any work: I only audit systems you own or are explicitly authorized to test. No unauthorized reconnaissance.
This fixed price covers a focused audit of one app, service or module. Larger scopes are quoted by message.
Tech1h 30m
Bridging the gap between strict legal frameworks and artificial intelligence. As a legal professional with advanced software engineering capabilities, I specialize in evaluating AI models for legal accuracy, regulatory compliance, and logical soundness. I audit AI outputs to prevent "legal hallucinations" and ensure that the advice or documentation generated aligns with real-world jurisprudence and compliance protocols. If you are training a model for the legal tech sector, I provide the domain expertise required to make it reliable and safe.
Tech1h
about
I'm Juan Carlos Isaza, a software developer and security auditor (and lawyer) based in Medellín, Colombia. I both build and audit.
Development: web apps, APIs and backends in Python, PHP (Laravel), Node.js and Rust, with MySQL / PostgreSQL / SQLite. I'm fluent at building with AI/Claude, so I move fast and finish projects other people leave half-done — new builds, fixes, integrations, and automation.
Security: I review code and AI-generated code / agent integrations for the subtle bugs an automated tester misses — broken access control (IDOR/BAC), injection (SQLi/XSS/SSRF), authentication and session flaws, cryptographic misuse, and business-logic bugs. Deliverable: a clear report with vulnerabilities, real-world impact, and step-by-step reproduction.
Two commitments, because I'm also a lawyer: (1) I only test what you own or are authorized to test — I confirm authorization first; (2) I flag data-protection and compliance risks (Ley 1581 / GDPR-style), not just technical bugs. Coordinated, responsible disclosure; minimal proof-of-concept, no data exfiltration, no service disruption.