$ whoami
Sang Tran
Application Security Engineer
I find the bugs before attackers do, and build the guardrails so they stay fixed.
Press ` to open the terminal.
this site, by the numbers
- 0third-party scripts
- 0cookies
- strictCSP, no inline JS
- RFC 9116security.txt
selected work
Placeholder: CI security gate
Semgrep, secret scanning and dependency checks wired into every pull request.
SemgrepGitHub ActionsPython
Placeholder: SBOM and provenance pipeline
Generate, sign and publish SBOMs for every release artifact.
CycloneDXSigstoreGo
Placeholder: Vulnerable-by-design lab
A small intentionally vulnerable API used for training and demos.
TypeScriptDockerOWASP API Top 10
latest write-ups
No write-ups published yet.