Hi There!
I am Web Security Researcher
Building secure applications, researching web vulnerabilities and continuously learning through practice.

Who am i?
I'm Z3tra, a Web Security Researcher
I got into security about two years ago — not to become a hacker, but because I wanted to understand how applications actually work underneath. Over time I narrowed down to web application security, which is where the logic lives. I also build my own projects, so I see applications from the developer's side as well as the researcher's.
- Started in security:
- 2023
- Focus:
- Web application security
- Currently:
- Preparing the OSCP
- Looking for:
- An apprenticeship, Sept 2026
- From:
- France
- Email:
- contact@z3tra.com
What I do
My Services
Assessment tooling is used in labs, CTFs and authorised engagements. Nowhere else.
Web Application Security
Assessing web applications against the classes that actually show up — broken access control, injection, authentication flaws — starting from how the application works, not from a scanner.
Secure Development
Building with Next.js, TypeScript and PostgreSQL, with the security decisions made at design time: scoped queries, validated input, and secrets that never reach the client.
Vulnerability Research
Reading source with intent, reproducing findings from a clean state, and turning them into a minimal proof of concept a developer can act on.
Infrastructure & Isolation
Containerised environments that assume compromise: dropped capabilities, no outbound network, hard resource limits and a short life. Built for Hackuten, used in my lab.
Automation & Tooling
Python and shell tooling for the parts of enumeration and reporting I run every time — consistent output, reproducible results, less room to forget a step.
Technical Reporting
Findings written for the person who has to ship the fix: impact, reproduction, evidence and remediation, in the terms of their codebase.
Selected work
Three projects, three very different problems
A platform built to be attacked, a messenger built to distrust its own server, and a safety app where being offline is the failure I have to design for.
Hackuten
A CTF platform for learning cybersecurity
Hackuten is a capture-the-flag platform covering several areas of cybersecurity — web, reverse engineering, cryptography, forensics and more. It exists to make the first steps into the field less discouraging: challenges that teach something specific, in an order that makes sense, with infrastructure that does not get in the way.
- Next.js
- TypeScript
- TailwindCSS
- PostgreSQL
- Docker
Orbyte
An end-to-end encrypted messenger
Orbyte is an encrypted messaging application in the spirit of Session: private conversations that do not require a phone number to start, and a server that is designed to know as little as possible. It is in active development — the parts that are built are built carefully, and the parts that are not are honestly labelled as such.
- TypeScript
- React
- Next.js
- Node.js
- PostgreSQL
Batelys
Lone worker safety, one button at a time
Batelys protects people who work alone. You check in when you arrive, then press a button now and then to confirm you are fine. Miss a check-in — because you fell, collapsed, or simply cannot reach your phone — and an alert leaves on its own, with your position, escalating through your chain until someone responds.
- TypeScript
- Next.js
- React
- Node.js
- PostgreSQL
Writing
Notes, write-ups and research
What I learned, written while it was still fresh — including the paths that went nowhere, which is usually the useful part.
Encrypting content is easy. Hiding who talks to whom is not.
Notes from designing Orbyte: why metadata is often more sensitive than message content, and the spectrum of defences between 'we encrypt messages' and actual metadata resistance.
- Research
- Web Security
- Cryptography
Understand the application before you test it
Scanners find what they were told to look for. The bugs that matter live in the gap between what an application believes about itself and what it actually enforces.
- Web Security
- OWASP
- Methodology
When being offline is the emergency: designing a reliable dead man's switch
Notes from Batelys on building a lone-worker alert system, where availability is a safety property and a missed check-in has to be as loud as a pressed button.
- Research
- Linux
- Architecture
Right now
Where I am at
Kept current, because a portfolio that describes last year is worse than no portfolio.
Latest experience
Cybersecurity Intern
Oteria · 2025
Second placement, focused on web application security: reviewing applications, reproducing findings and turning them into reports someone could act on.
Stack
Languages
- TypeScript
- Python
- JavaScript
- SQL
- HTML
- CSS
Frameworks
- Next.js
- React
- TailwindCSS
Technologies
- Git
- GitHub
- Docker
- REST API
- Linux
- PostgreSQL
Security tooling
- Burp Suite
- Caido
- OWASP ZAP
- ffuf
- Gobuster
- Nmap
- SQLMap
- Hashcat
Systems
- CachyOS
- Windows
- macOS
Looking for an apprenticeship in application security, starting September 2026.
If you are hiring, or you just found something on this site worth arguing about, I would like to hear from you.

