Technical lead
Tural leads the research.
He owns technical investigation, careful validation, finding quality, and remediation guidance.
Head of Security Research
Manual-first security research for applications, APIs, and the systems people depend on.
Tural leads WisePal's technical security research: finding the real failure path, validating it carefully, and giving product teams a practical route to remediation.

The mandate
Offensive security is most useful when it produces a finding the team can understand, reproduce safely, and fix with confidence.
Tural's work spans vulnerability research, application and API testing, source review, exploit validation, and coordinated disclosure. The goal is not noise or a volume of scanner output. It is a clear account of the root cause, the credible impact, and the remediation path.
How he works
Tools help cover ground. Human judgment decides what matters, what is safe to validate, and how the result should reach the people responsible for the system.
Map the application, API, trust boundaries, and business logic before choosing where deeper manual review belongs.
Investigate behavior, source, and attack paths with human judgment leading the work and tools supporting it.
Confirm exploitability with the minimum impact necessary, inside the agreed authorization and stop conditions.
Explain root cause, practical impact, remediation options, and what should be retested after the change.
Focused expertise
Research follows the way a real user, role, or service moves through the system—not only the endpoints a tool can enumerate.
Engagement boundary
Testing begins only after WisePal and the client agree in writing on the systems, dates, methods, exclusions, stop conditions, and communication path. The engagement is defined by the work and deliverables—not by the number of vulnerabilities found.
Technical lead
He owns technical investigation, careful validation, finding quality, and remediation guidance.
Client lead
Hamid Elsevar leads product context, engagement design, and client communication so the technical work stays connected to the business decision.
Coordinated disclosure
Research stays within a published disclosure program, safe harbor, or other written authorization. Testing stops when scope, sensitive data, or destructive impact is in question.
Confirmed findings go through the organization's authorized channel. Publication waits for remediation coordination and permission; essential remediation detail is never conditional on payment.
Start with scope
Tell WisePal what you need protected, what access is available, and what decision the assessment must support.
Request a scoped security conversationProfessional contact: tural@wisepal.ai. Do not send credentials, exploit code, or sensitive vulnerability details through ordinary email.