
Over the past few months I’ve been asked things I won’t do. Nothing dramatic, no supervillain stuff, but enough to make me realize that something needs to be clarified explicitly, upfront, before anyone wastes each other’s time or takes wrong assumptions.
The requests ranged from mildly awkward to genuinely not happening: NDAs with penalty clauses that would make a lawyer blush, engagements where the “target” of a security assessment was clearly not something the client had any right to touch, a situation where the underlying ask was essentially “can you do this and pretend it was me”, the assumption that I could be some sort of despicable mercenary and the evergreen “can you do it fo less”. The answer to all of the above was no, but having to say it over and over gets annoying.
So I took a decision: I wrote it down, once and for all.
There’s now an Ethics section on the homepage. It’s not a corporate manifesto, it’s not a list of noble principles I stole from a fairy tale. It’s just how I actually work — including the parts that are slightly uncomfortable to say out loud, like the fact that reverse engineering engagements live in a legal grey area, or that I won’t sign contracts designed to make me liable for things outside my control; I’m not desperate enough to bend my rules for anyone who shows up with some money.
It’s also got the stuff I’m genuinely proud of: quality first, I document everything, I don’t build lock-ins, and I don’t disappear after the final invoice.
If you read it and think “this guy’s not for me” — good! That’s exactly the point.
If you read it and think “finally someone who says it straight”, let’s talk.