Independent research recordUnited States

Independent security researcher

Gevork Sarkisyan

Authorized vulnerability research built on controlled testing, reproducible evidence, and responsible disclosure.

Public verification

Independent / Sole Proprietor United States

Selected research

Evidence before adjectives.

Anonymized records are intentionally bounded to proven behavior, controlled identities, and the status of each disclosure.

AI-content platform

Object-level authorization

Submitted

Account and authorization boundaries

Identified cross-account authorization failures affecting private and collaborative resources, then reported the proven impact through the platform’s security channel.

Method
Two controlled identities, synthetic records, owner-versus-non-owner comparisons, and exact negative controls.
Boundary
Testing stopped after the minimum cross-account impact was reproduced. No external accounts or third-party records were used.

Education technology platform

Identity and trust boundaries

Submitted

OAuth and identity-linking security

Demonstrated weaknesses in an account-linking trust boundary with separate controlled identities and documented the resulting identity mismatch.

Method
Isolated browser contexts, fresh identity baselines, session separation, and end-to-end verification against controlled accounts.
Boundary
No private content was opened, changed, or retained. Active controlled sessions were discarded after validation.

Collaborative web application

Stored-content security

Researcher validated

Stored content and organization integrity

Validated how attacker-controlled stored content could cross a role boundary and affect organization-level integrity after a controlled user interaction.

Method
Role-separated test accounts, an inert controlled fixture, before-and-after ownership checks, and independent state confirmation.
Boundary
The controlled fixture was removed and original roles were restored. No unrelated users, teams, or content were accessed.

Target names and operational details remain private until written disclosure permission is received.

Research method

A controlled path from scope to report.

Every engagement begins with authorization and ends with cleanup, evidence review, and a reproducible disclosure.

  1. 01

    Confirm authorization

    Review the program policy, permitted assets, exclusions, and stop conditions before interacting with a target.

  2. 02

    Establish controls

    Create distinct controlled identities and synthetic fixtures that make expected ownership boundaries observable.

  3. 03

    Record the baseline

    Capture the permitted path and meaningful negative controls before testing the suspected failure case.

  4. 04

    Prove the minimum

    Reproduce only the smallest safe result needed to demonstrate tangible security impact.

  5. 05

    Restore state

    Remove controlled fixtures, restore roles, close sessions, and confirm that temporary state no longer remains.

  6. 06

    Report reproducibly

    Submit sanitized evidence, precise controls, bounded impact, and a remediation path through the authorized channel.

Operating principles

Boundaries are part of the evidence.

The quality of a finding depends on how safely it was obtained, how honestly it is framed, and how completely temporary state is removed.

Explicit authorization only

Research is limited to assets and actions covered by a clear policy or written permission.

Controlled identities

Cross-account behavior is tested only with accounts and fixtures under researcher control.

Minimum necessary proof

Testing stops when the smallest reproducible security impact has been established.

No destructive testing

Availability, persistence, credential attacks, and destructive actions remain outside the workflow.

No third-party data

Synthetic content replaces real-user information, and unrelated records are never inspected.

Evidence hygiene

Credentials, secrets, personal identifiers, and unnecessary content are removed from reports.

Documented cleanup

Controlled state is restored or removed, and cleanup results are recorded alongside the proof.

Honest severity

Claims remain limited to demonstrated impact, including negative controls and known caveats.

Authorized work only

Let's examine the boundary.

Available for scoped vulnerability research, private programs, and responsible disclosure opportunities.

gevork@thesarkisyan.com