WEB3 · AI · SECURITY AUDITING

I build support agents, on-chain alerts and reporting for crypto teams. I audit the security of AI-built apps and websites with the OWASP methodology. And I build and audit smart contracts.

Audits from €600. You get me directly, in English or Spanish.

Portrait of Daniel Brosed

Daniel Brosed · Founder of VaultBit

TRUSTED BY

Hours lost to repetitive work. Apps shipped to production with security holes. 

The tasks that repeat every week eat your time, and a lot of apps, especially the ones shipped fast with AI, go to production with exposed keys or broken permissions that nobody on the team knows about. I handle both: I automate the repetitive work, and I audit what is about to break.

Authentication flaws

Broken JWT and session handling, exposed keys and secrets

Exposed data

Missing RLS policies, unprotected API routes, injection

Insecure configuration

Environment variables, CORS and default headers

Did you ask the AI to review its own code? 

Asking the AI to check itself

Coverage
Repeats the same blind spots it created
Outcome
"Looks fine to me"
Fixes
Scattered patches, no judgment
Accountability
Nobody owns the outcome

Professional audit

Coverage
Full OWASP checklist, layer by layer
Outcome
A written report with prioritized findings
Fixes
The concrete fix for every finding
Accountability
A name and a reputation behind it

automate your processes and audit your security. 

AI AUTOMATION

Agents, alerts and reporting that work while you sleep

In plain words: programs that answer your customers and watch your systems on their own, 24/7.

  • Support agents for Discord and Telegram
  • Wallet monitoring with alerts
  • Automated reporting for community and investors
  • API integrations and back-office flows

SECURITY AUDIT

Security audits for AI-built apps and websites

In plain words: I find the security holes in your website or app and tell you how to close them.

  • Secrets, access control and authentication
  • Supabase RLS, input validation and headers
  • Full OWASP checklist
  • Actionable report, explained in plain language

Fixed prices, scope in writing. 

Express

from €600

1-2 business days

For MVPs and AI-built apps not yet making money

  • Full app-level OWASP checklist
  • Report with findings ranked by severity
  • The concrete fix for every finding

Out of scope

  • Not a penetration test
  • Does not include implementing the fixes
  • No compliance certification (SOC 2, GDPR)

Full

from €1,500

4-5 business days

For production apps with users or payments

  • Everything in Express
  • Deep review of RLS/Supabase, secrets, auth and headers
  • A 30-min call to walk you through it all

Out of scope

  • Not a penetration test
  • Does not include implementing the fixes

Hardening

from €2,500

8-10 business days

For teams that want the problem solved, not just diagnosed

  • Everything in Full
  • I implement the fixes as Pull Requests
  • Verification re-test + 30 days of support

Out of scope

  • Not a penetration test
  • No compliance certification (SOC 2, GDPR)

Prices exclude VAT: Spain +21%; EU businesses with a VAT number, reverse charge; outside the EU, no VAT applies.

EVERYTHING CONNECTED

Every piece ends in the same place: your project. 

AI automation
Security review
On-chain alerts and reporting
Smart contract auditing
Your project

Hire one piece or the whole system. Everything ships working, documented and explained.

From the first call to delivery. 

01

30-min call

You tell me what you need. I tell you how I can help and where we start.

02

Fixed-price proposal

You know what you get, when, and what it costs before we start.

03

Delivery and walkthrough

I hand over the working system or the report, and I explain it so you actually understand it.

Concrete results, explained clearly. 

01.A clear, actionable report.Every finding with its severity, its impact and the concrete fix. No generic PDF you cannot act on.
02.I build with AI every day.I use the same tools I review. I know where AI-built apps break because I build them too.
03.Apps and smart contracts.I audit the security of your website or app and your smart contracts, and I build them for you if you need them. All with the OWASP methodology.
04.Fixed, public pricing.You see it on the site and the proposal comes with a fixed price. No surprises, no "contact us for a quote".
Working session with the Balority team.

A REAL CASE

I reviewed the security ofBalority.

Balority is a startup-ecosystem social network connecting founders, investors, mentors and talent. I reviewed its app-level security using the OWASP methodology, builder to builder.

Visit BalorityWorking session with the Balority team.

Real credentials, verifiable. 

Every Cyfrin Updraft security track completed. Each badge is real: tap one to see what it covers.

Cyfrin: Blockchain Basics
Blockchain Basics
Cyfrin: Wallet Basics
Wallet Basics
Cyfrin: Advanced Wallets
Advanced Wallets
Cyfrin: Solidity 101
Solidity 101
Cyfrin: Foundry Fundamentals
Foundry Fundamentals
Cyfrin: Advanced Foundry
Advanced Foundry
Cyfrin: Chainlink Fundamentals
Chainlink Fundamentals
Cyfrin: Smart Contract Security
Smart Contract Security
Cyfrin: Assembly & Formal Verification
Assembly & Formal Verification
Anthropic

ANTHROPIC ACADEMY · 10 CERTIFICATIONS

Building software since was 14. 

Websites, apps and automations for businesses. Since 2022 I have been deep in crypto, where I founded VaultBit. I have built real things: investment solutions for businesses and automations for companies.

No university degree, no big logo behind me. I come from building things and breaking them to understand how they break. That is why I now do two things that go together: automate what steals your time, and review the security of what could hurt you.

Freelance, project-based. Open to remote Web3/AI roles and long-term collaborations.

Daniel Brosed

Should we automate something 
or review your app? 

No pitch, no pressure. Just a conversation about your app.

Prefer to talk?Book 30 min on Cal.comTelegramLinkedIn

Frequently asked questions. 

It is a technical review of the application layer of your web or app: the code, authentication and access control, keys and secrets, the database (for example Supabase RLS policies), input validation and security headers. I follow the OWASP checklist, the industry reference, and you get a report with every finding ranked by severity plus the concrete fix for each one. It is not a penetration test and not a compliance certification: it is the review an AI-built app needs before facing real users. The Express starts at €600 and takes 1-2 business days; the Full, from €1,500 in 4-5 days; Hardening, from €2,500 with the fixes implemented as Pull Requests.

One process of your business automated end to end, working and documented. We pick the process together (Discord or Telegram support, wallet monitoring with alerts, reporting for your community and investors, or an integration with your APIs), I build it with n8n and Claude on top of your tools, and I hand it over with training for your team. A sprint takes 3-4 weeks and starts at €1,500. If you need several connected flows, Multi-flow starts at €3,000 in 6-8 weeks. And if you want what I delivered to keep growing month by month, there is a retainer from €400/month with no lock-in.

Read access to the repository (or a ZIP of the code) and the app URL. If there is a database, the schema and its policies. That is enough for the Express.

Mostly what AI tools produce: Next.js and React, Supabase, Node, REST APIs, deployments on Vercel and similar. If your stack is different, ask me and I will tell you honestly whether I am a fit.

Your code never leaves my machine, I do not share it, and I delete it when the project closes. If you want an NDA, we sign it before you show me anything.

In Express and Full you get the report with the concrete fix for every finding. In Hardening I implement them myself as Pull Requests.

Before it goes to production with real users, and always when it touches payments or personal data. If it is already live and nobody has ever reviewed it, as soon as possible.

Express in 1-2 business days, Full in 4-5, Hardening in 8-10. Automation runs in 3-4 week sprints.

Prices exclude VAT. Spain +21%. EU businesses with a VAT number: no VAT (reverse charge). Outside the EU: no VAT applies.

Book a 30-minute call or write to me. It leads to a proposal with a fixed price.