// PRINCIPAL ARCHITECT · CAPE TOWN, ZA

Jarrit
Hosking_

Solo founder. I build infrastructure that scales, research the security of systems that shouldn't fail, and treat AI as a full co-worker — not a shortcut.

By day I architect client products through Forge Vertical and build out TripSpace Global, a commission-free hospitality marketplace. When the terminal calls, I'm hunting logic flaws in enterprise SaaS infrastructure for bug bounty programmes on HackerOne and YesWeHack.

FORGE VERTICAL
Digital agency &
AI consultancy

High-performance web architecture, GEO/SEO strategy, and AI workflow integration for startups and SMBs worldwide.

View deployments →
36
Reports · 60-day sprint
04
Private programme invites
TRIPSPACE GLOBAL
Commission-free
hospitality marketplace

React + Firebase · PWA + TWA · Payments · Real-time messaging

Visit →
CI/CD Pipeline Audits
React + Firebase Architecture
IDOR · Auth Bypass
PWA + TWA Deployment
GEO · llms.txt · AI Indexing
WAF Evasion Research
Cloudflare + cPanel Infrastructure
CVSS Severity Scoring
Business Logic Flaws
Vite Bundle Optimisation
HackerOne · YesWeHack
Firestore Security Rules
CI/CD Pipeline Audits
React + Firebase Architecture
IDOR · Auth Bypass
PWA + TWA Deployment
GEO · llms.txt · AI Indexing
WAF Evasion Research
Cloudflare + cPanel Infrastructure
CVSS Severity Scoring
Business Logic Flaws
Vite Bundle Optimisation
HackerOne · YesWeHack
Firestore Security Rules
// HOW I WORK
01

AI as a co-worker

I don't use AI as a prompt machine. It's a pair programmer, a research assistant, a sounding board. The architecture decisions stay with me — AI handles the throughput.

02

Build for scale from day one

Every system I architect assumes it will grow. Firestore rules that hold at 10k users. Vite bundles that don't bloat. Infrastructure that doesn't need a rewrite at growth.

03

Security is context, not a checkbox

Bug bounty research feeds directly back into how I build. If I've found a cross-tenant API bypass in production SaaS, I know exactly how to prevent one in yours.

// SECURITY RESEARCH · THREAT VECTOR FOCUS
CI/CD PPE RCE ATO IDOR WAF Bypass Business Logic SDLC Bleed Auth State Abuse Cross-Tenant Isolation
// PRIMARY STACK
FRONTEND
React · TypeScript · Vite · Tailwind
BACKEND
Firebase · Cloud Functions · Firestore
INFRA
Cloudflare · GitHub Pages · cPanel
SECURITY
Kali Linux · Docker · curl-impersonate
// LET'S BUILD

Have a problem worth solving?

Whether it's a product that needs architecture, infrastructure that needs a security audit, or a marketplace idea — I'm interested in problems with real stakes.