Architecte du Réel

What I've found in the field

No theory. Facts. Evidence. Scores. Real, anonymized and reproducible audits. OWASP, CVSS 3.1 methodologies. PDF reports 40+ pages with archived material evidence. Scoring out of 100, risk matrix, prioritized remediation plan.

Why cybersecurity can't wait any longer

€200M

France cybersecurity budget 2026
≈ 0.07% of national budget

$25B

US cybersecurity budget
125× more per capita

43M

France Travail profiles leaked
2024–2026

These figures don't come out of nowhere. They come from institutional reports, specialized press, and continuous technical monitoring. I've cross-checked them with what I see in the field: WordPress sites abandoned since 2023, publicly exposed backups, domains expiring in 10 days, API keys buried in frontend code. France is at the back of the pack. And the worst part? Most decision-makers don't know it.

What I can audit

Each domain corresponds to real missions, with concrete deliverables and internationally recognized methodologies.

Web Security & Pentest

OWASP WSTG v4.2, OWASP Top 10 2021, CVSS 3.1. Black-box and grey-box testing, CVE identification, risk scoring, realistic attack scenarios. From reconnaissance to controlled exploitation.

GDPR & Legal Compliance

Privacy policies, cookie and consent management, legal notices, right to be forgotten, data traceability, processing registers. Business-specific analysis (notaries, e-commerce, local authorities).

Architecture & Infrastructure

Secure HTTP headers, SSL/TLS, HSTS, server configuration, WAF, rate-limiting, DNS and certificate analysis. Audit of interconnections and attack surfaces exposed to the Internet.

Factual Territorial Audit

Cross-referencing public data (INSEE, Météo-France, institutions), quantitative projections, quantified scenarios, interdependency matrices. Rigorous method: ~39 archived evidence files per study.

Cyber Investigation

Malware analysis (wipers like AcidRain), cyberwarfare, attack attribution, network forensics. Study of real incidents: Viasat KA-SAT, structured phishing campaigns.

Comparative Strategic Analysis

International benchmarks (France, US, UK, Germany, Japan), cyber budget studies, roadmaps for public decision-makers and businesses. Translating complex data into actionable decisions.

Audit Examples — Anonymized

No client names, no URLs. Only site typologies, measured scores, and findings that could apply to yours.

Institutional Site — Outdated CMS

9/100
Duration
~4h
CVEs
16 confirmed
Vulnerabilities
5 critical

WordPress abandoned since 2023. 11 critical plugins with known RCE and XSS flaws. Domain name expiring in 10 days. GDPR compliance at 0%. Finding: this site is an open door.

B2B/B2C E-commerce — Technical Debt

24.5/100
Duration
~14h
Artifacts
36 files
Vulnerabilities
22+ identified

Database backups exposed since 2010 (2.1 MB + 62.4 MB compressed). Historical CMS Joomla! 1.5 still accessible. Current PrestaShop with vulnerable theme. Finding: 15 years of security technical debt.

SaaS Platform — API & Extranet

56/100
Duration
~5h30
Data exposed
998 products
Vulnerabilities
17 identified

Mass scraping of 998 products in 11 minutes (237.77 MB). Ably API key exposed in frontend. Critical CORS flaws enabling cross-origin access. Finding: the API is an open tap.

Notary Office — Enhanced Compliance

32.5/100
Duration
~5h
Artifacts
20+ files
Vulnerabilities
13 identified

Notary business analysis: professional secrecy protection, deed traceability. Rudimentary rate-limiting triggering IP block on auditor. No intelligent WAF. Finding: the profession is exposed, not just the website.

Rental App — Mobile + Web Stack

65/100
Duration
~8h
Artifacts
25 files
Vulnerabilities
17 identified

Modern architecture but 5 high-severity flaws in authentication and session management. Missing security headers on API. Sensitive forms without anti-CSRF protection. Finding: well-built, poorly secured.

Local Authority

71.4/100
Duration
~3h
Artifacts
30+ files
Vulnerabilities
11 identified

Overall posture average but 2 critical vulnerabilities in administrative authentication. User data and administrative documents exposed. No robust password policy. Finding: the average hides serious flaws.

« People think I'm a fabulist »

When I say a site can be compromised in 20 minutes, that a database of 43 million profiles has leaked, or that France spends 0.07% of its budget on cybersecurity... people look at me wide-eyed. Sometimes they call me a fabulist.

Yet, every finding I present is sourced, timestamped, and reproducible. Here's how I work:

Recognized Methodologies

OWASP, CVSS 3.1, GDPR, ISO 19011. No opaque home-grown methods.

Material Evidence

20 to 36 timestamped artifacts per audit: screenshots, logs, HTTP responses, SHA-256 hashes.

Reproducibility

You can redo the test yourself with the same open-source tools. No black magic.

I don't predict the future. I measure the present.

Artificial Intelligence: a tool, not a monster

People are afraid of AI. That's normal — we fear what we don't know.

How I use AI

I use it like I use an oscilloscope or a NMEA protocol analyzer: it's a tool that lets me go faster and further. It doesn't replace my judgment. It amplifies it.

  • Analyze 10,000 lines of logs in seconds
  • Cross-reference data from multiple and contradictory sources
  • Generate realistic, documented attack scenarios
  • Produce structured reports without losing rigor

What it cannot do

The real threat isn't AI. It's ignorance of what it can do — and what it cannot do.

  • It doesn't replace business expertise (notary, marine, healthcare)
  • It doesn't validate material evidence by itself
  • It doesn't make ethical decisions for you
  • It doesn't protect your site if you don't fix the flaws

The audit makes visible what was hidden. AI is the flashlight. You're the one looking.

Discover my AI supervision mission

Want to know where you stand?

An audit doesn't judge. It measures. And measurement is the first step toward mastery.

Request an audit

First exchange without commitment. Response within 24h.