Offensive Security Expert | Penetration Testing, VAPT & Bug Bounty | CEH & ISO 27001 Certified | Founder @ Codethus
I'm Sheraz Kazmi, founder of Codethus, a cybersecurity and web development agency based in Lahore, Pakistan. I specialize in offensive security — penetration testing, VAPT, and red team exercises — for clients across Pakistan, UAE, Australia, and the US, including government bodies and enterprises.
I hold CEH (Certified Ethical Hacker) and ISO/IEC 27001 certifications, along with a BS in Computer Science. I've also worked as a cybersecurity instructor at a private institute, so I'm comfortable breaking down technical findings for both engineering teams and non-technical stakeholders.
What I offer:
Web application penetration testing (black-box and grey-box)
Full-scope VAPT for websites, networks, and infrastructure
Bug bounty / private program vulnerability hunting
Security consulting for ISO 27001 and compliance-driven pentests (PCI-DSS, HIPAA-adjacent)
How I work:
Every engagement follows a structured methodology — reconnaissance, vulnerability identification, exploitation validation, and remediation guidance — with a report that's actually useful to your team: CVSS-scored findings, clear reproduction steps, and proof-of-concept evidence, not just a scanner dump. I also use AI-assisted tooling (including Claude) to speed up recon and reporting, while keeping manual validation at the core so findings are accurate and exploitable, not false positives.
Whether you need a one-time website security audit or an ongoing security partner alongside your dev team, I'd be glad to help secure what you've built.
Work Terms
Communication: I respond to messages within 24 hours (usually much faster). Available for calls to scope engagements before we begin.
Engagement process: For penetration testing and VAPT work, I start with a scoping conversation to confirm targets, rules of engagement, and timeline. Fixed-price work is quoted after scope is confirmed; hourly work is tracked transparently with regular updates.
Rules of engagement: I only test systems I'm explicitly authorized to test, and I follow whatever boundaries the client sets (no destructive actions, no data exfiltration, no DoS unless specifically scoped). Critical findings (RCE, auth bypass, mass data exposure) are reported immediately, not held for the final report.
Deliverables: All engagements include a written report — executive summary plus technical findings with CVSS scoring, reproduction steps, and remediation guidance. A retest to confirm fixes is available on request.
Payments: I work through Guru's SafePay for milestone-based or hourly billing. Milestones are agreed upfront before work begins.
Confidentiality: Happy to sign an NDA before any testing begins. Client data and findings are handled confidentially and are not shared or referenced without permission.