A precise glass network examined through a magnifying lens

Independent security

Find what others
look past.

Bypass Security investigates the seams between code, products, and people—then turns hard-to-find weaknesses into clear, actionable security work.

Research identityXSS Doctor
FocusApplication · AI · Product
ApproachEvidence over assumptions

Bypass Security works where modern products are most exposed:

Web applications·Desktop software·AI systems
What we do

Security work for the parts that don’t fit a checklist.

Focused assessment and research for teams building ambitious software. Every engagement is built around the product’s real trust boundaries, not a generic scan template.

01

Product security assessment

Targeted review of web, desktop, and AI-enabled products using source analysis, runtime testing, and attack-path validation.

  • Architecture and trust-boundary review
  • Manual vulnerability research
  • Exploitability and impact validation
02

Adversarial research

Deep, hypothesis-driven work on the edge cases where browsers, native bridges, identity, and application logic meet.

  • Attack-surface mapping
  • Exploit-chain development
  • Variant and root-cause analysis
03

AI & agent security

Review of agentic applications, model-facing data flows, tool orchestration, and the authorization boundaries around them.

  • Agent and tool-boundary assessment
  • Prompt and data-flow review
  • Local, cloud, and hybrid attack paths
How we work

A finding isn’t useful until it is understood.

The goal is not to make a scanner beep. It is to show exactly what breaks, why it matters, and what a durable fix looks like.

  1. 01

    Observe the real system

    Map behavior, data flow, and trust before making assumptions.

  2. 02

    Prove the attack path

    Validate exploitability with bounded, reproducible evidence.

  3. 03

    Translate it clearly

    Connect technical root cause to business impact and remediation.

Bypass Security LLCIndependent · United States

XSS Doctor is the research identity of Jonathan Dunn—and the public face of Bypass Security.

We bring a researcher’s curiosity and an engineer’s standard of evidence to complex application security. The work is independent, precise, and designed to help product teams make better decisions.

Web application securityBrowser & desktop securityAI & agent systemsAuthorization & identityExploit-chain validationVendor-ready reporting

Have something difficult?

Let’s take a closer look.

hello@xssdoctor.com