Hazem Elbatawy
Discuss a Project

Full-Stack & Backend API Developer | Integration Developer | Founder, FolioVista Books
Security Researcher

I build and integrate secure, production-ready backend APIs and full-stack web systems.

I build full-stack web systems and backend APIs, with a focus on integration work that connects services into reliable, production-ready products. A security engineer's perspective is built into how I work, so what I ship holds up to real-world access-control and data-exposure risks.

Experience

Full-Stack, Backend API & Integration Developer

Freelance · Remote · International clients · 2023 - Present

  • Built and deployed production-ready web applications using React, TypeScript, FastAPI, Django, Laravel, PostgreSQL, MySQL, Docker, Nginx, and Linux servers.
  • Deployed Vox Estate Agent, a FastAPI + React application, on a Linux VPS with Nginx, systemd process management, HTTPS, and production server configuration.
  • Delivered AI Product Image Similarity Search for a German client through the AutoHubPlatform GitHub organization, using AI image embeddings and containerized deployment practices.
  • Built and deployed SECHIVE, a multi-page React/TypeScript website for a physical security firm, under the SECHIVEE GitHub organization on GitHub Pages.
  • Worked with OpenAI APIs, WebSockets, multi-tenant SaaS patterns, CI/CD through GitHub Actions, and Linux server administration.

Security Researcher

Independent · Web & API Security · 2024 - Present

  • Conduct scoped web and API bug bounty testing with a focus on recon, attack-surface mapping, controlled validation, and responsible disclosure.
  • Test for broken access control, authorization logic flaws, insecure object references, privilege boundary issues, and business logic weaknesses.
  • Produce clear, reproducible reports with evidence quality focused on triage and remediation.
  • Build practical automation to reduce false positives and improve testing efficiency.
  • Develop public proof through redacted case studies and open-source security tooling.

Services

Backend API and Service Integration

Build, extend, and integrate secure backend APIs that connect applications, third-party services, databases, and operational workflows into reliable production systems.

Secure MVP and Web System Builds

Build or refine web applications, admin systems, and product MVPs with practical full-stack delivery, clean structure, and production-minded implementation.

Internal Tools and Workflow Systems

Create operational tools, database-backed flows, automation helpers, and structured interfaces that reduce manual overhead and improve business workflows.

Technical Publishing and Content Platforms

Design and implement technical publishing assets such as digital book platforms, guide systems, structured documentation flows, and conversion-ready content pages.

Production Platform — FolioVista Books

I founded FolioVista Books as a digital publishing company for digital books, practical guides, manuals, and free sample chapters.

FolioVista Books

Founder · Digital Publishing · Live Production Platform

FolioVista Books demonstrates product ownership, technical publishing, public deployment, production operations, and direct customer communication.

Selected Work

Selected public projects demonstrating full-stack delivery, backend APIs, service integration, cloud deployment, security work, and frontend engineering.

Vox Estate Agent

Full-Stack / API

FastAPI, React, AI integration, chat, text-to-speech, and property management.

Miando — MT5 Forex Data Integration

Backend / Integration

Windows MT5/MQL5 integration with Dockerized Python and PostgreSQL on Linux.

Users & Vehicles Forms API

Backend / API

Django 5, Django REST Framework, token authentication, middleware, structured logging, and tests.

Django on AWS EC2

Backend / Cloud

Django data application and AWS EC2 deployment documentation.

Django Notifications

Backend / Events

REST APIs, WebSockets, Channels, Celery, Redis, email notifications, and tests.

Laravel E-commerce Admin

Backend / Admin

Laravel, Jetstream authentication, MySQL, Docker, Blade, and catalog administration.

Broken Access Control Case Study

API Security

Disclosure-safe IDOR/BOLA methodology, evidence handling, and remediation.

Linux VPS Security Cases

Security Operations

Hardening, incident response, network troubleshooting, and Bash automation.

SECHIVE

Frontend

React, TypeScript, Vite, and a multi-page physical-security website.

Reactify

Frontend

React component patterns, Context API, hooks, feature flags, toasts, and a portal modal.

Case Studies

Public-friendly summaries only. Keep sensitive details redacted and share only authorized evidence.

Case Study 1: Private Program Access-Control Finding

Authorized testing in a private bug bounty workflow with object-level authorization validation.

  • Focus: authorization boundary checks on account-owned objects.
  • Method: controlled account testing with reproducible evidence and strict redaction.
  • Outcome: report submitted with clear reproduction and remediation guidance; triage status duplicate.
  • Signal: demonstrates discipline in reporting and technical validation quality.

Case Study 2: Redacted Recon and Fuzz Pipeline

Recon plus fuzz automation flow for authorized target assessment and endpoint behavior analysis.

  • Focus: exposure mapping, endpoint probing, and fuzz-based edge case validation.
  • Authorization focus: object-level access checks and workflow state validation in controlled testing scenarios.
  • Method: DNS and CT recon, orchestrated fuzz runs, and result triage.
  • Tooling: recon.py, recon_fuzz_orchestrator.py, selenium_socks_simple_fuzz.py.
  • Outcome: prioritized findings and reusable evidence bundles for remediation.

Recon and Fuzz Workflow

A practical workflow used to move from discovery to reproducible findings.

Phase 1: Passive Recon DNS, CT logs, headers, and endpoint map
Phase 2: Guided Fuzz Parameter/path test cases and anomaly checks
Phase 3: Evidence Pack Repro steps, logs, and impact summary
Phase 4: Remediation Support Fix guidance and verification rerun

Security Assessment Process

  1. Scope call and risk focus alignment
  2. Recon and attack-surface mapping in approved scope
  3. Controlled vulnerability validation and evidence collection
  4. Remediation-first report for engineering teams
  5. Verification pass and handover summary

Disclosure Compliance

Public references are disclosure-safe summaries only and follow program policy boundaries.

Contact

Based in Cairo, Egypt. Open to technical partnerships, product collaborations, and selected consulting engagements.