Kod × Tasarım × Güvenlik · Code × Design × Security
Application-security-focused full-stack developer.
I write software, then try to break it — and disclose what I find (two turned into CVEs).
The rest of the time I design brands and the interfaces that sit on top of them.
📍 Bursa, Türkiye · hybrid / remote-friendly
I can take a product end to end — from the database schema to the logo, from a penetration test to the ad creative.
Six years building corporate systems with PHP & Laravel: e-commerce, CRM, payment integrations, IoT dashboards.
PHPLaravelGoTypeScriptMySQL
I test what I build with an attacker's mindset and responsibly disclose the bugs I find. Two became CVEs.
OWASP Top 10SANS 25PentestThreat Modeling
The full visual identity for a new business — logo, corporate identity, social templates — and the product UI from the same hand.
LogoBrand IdentityUI/UX
Most of my client & enterprise work is under NDA — happy to walk you through it. These are the ones I can share openly.
- DoctorDock — a doctor for your Docker: local-first, AI-free Docker security & cleanup diagnostics, CLI + macOS app.
doctordock.iamcanturk.devGo·Security·CLI - MergenFlow — a "freelancer operating system."
TypeScript·SaaS - Erklig — a backdoor analysis engine.
Go·Security
| CVE | Vulnerability | Severity | Target | References |
|---|---|---|---|---|
| CVE-2026-28403 | Cross-Site WebSocket Hijacking | Textream | NVD · GHSA | |
| CVE-2026-28412 | Uncontrolled Resource Consumption | Textream | NVD · GHSA |
Started as a factory IT intern in 2015 · I also chase good light with a camera 📷
iamcanturk.dev — projects, writing, and how to reach me.


