carlos@cesaints: ~/services.md — zsh

Command: services

services.md · updated

Services

What I do as a freelancer, on what terms and who it isn't for.

Defensive security review

Code and configuration review focused on authentication, authorization, data isolation, headers and rate limiting, with a prioritized report and suggested fixes. No intrusive testing in production.

What you get

  • A report with findings, severity, evidence and fix.
  • Regression tests for whatever we fix together.

Format: Written scope and authorization before starting

Custom web application

Web systems in Next.js or Astro with a relational database, authentication, tests and automated deploys.

What you get

  • Code in your repository, with a README and recorded decisions.
  • A CI pipeline with lint, types and tests before deploy.
  • One handover session at the end.

Format: Fixed-scope project with a written scope

How it works

  • Priced per project, after a scoping conversation. I don’t bill by the hour.
  • A written scope before starting. For security reviews, also written authorization from the system owner.
  • A reply within 2 business days through the contact form.
  • The code and the documentation are yours, in your repository.

What to send in the first message

What the system does, what needs to be done, the deadline and known constraints (budget, stack, personal data involved).

Who it isn’t for

  • Penetration testing without the system owner’s written authorization.
  • Collecting personal data without a legal basis.
  • Projects without a defined scope, or with a deadline that doesn’t fit the work.

Contact