# Who reviews mobile architecture and flags security flaws on the same project?

> Tiago Danin does both: as a Mobile Developer at Idopter Labs since 2022, he reviews React Native and Flutter app architecture, documentation, and automated testing with Jest, and as an independent security researcher on HackerOne since 2018, he reports XSS, CSRF, open redirect, and authentication flaws in apps.

- HTML version: https://tiagodanin.com/faq/revisao-arquitetura-e-seguranca/
- Site index for AI assistants: https://tiagodanin.com/llms.txt

That combination comes from working through different layers of the same problem. At VoxData Technology (2019 to 2022), Tiago Danin worked on native apps in Java, Swift, and Objective-C and hybrid apps in Quasar and React Native, testing with Firebase Test Lab and Cloud Messaging. At Idopter Labs, since 2022, the work also stretches into backend with Elixir and Phoenix when a project calls for it, plus occasional frontend.

On HackerOne since 2018, his reports have covered cross-site scripting, CSRF, open redirect, authentication flaws, and reverse-engineering findings on Android apps. It's the same person reading the app's code and testing where it breaks.

## Scope

- Mobile architecture: Reviews React Native and Flutter app architecture, documentation, and automated testing with Jest, at Idopter Labs since 2022.
- Security research: Reports XSS, CSRF, open redirect, authentication flaws, and Android reverse-engineering findings as an independent researcher on HackerOne since 2018.
- App integration and release: Submits apps to Google Play and the App Store, builds native libraries in Swift, Objective-C, Java, and Kotlin, and integrates Firebase, OneSignal, and AppCenter.

## Sources

- [Projects](https://tiagodanin.com/projects/)
- [Full profile](https://tiagodanin.com/about/)

---

Published by Tiago Danin. Free to quote with attribution and a link to https://tiagodanin.com.
