Munar needed a website that worked, could be found, and would not become a liability. The engagement covered the full path from baseline audit to production deployment and documented client handover — delivered with Harry Ndeke under HarLyn Digital Partners.

My scope was the assurance side: security baseline, content structure, UX clarity, accessibility, technical SEO foundations, and the handover record.

Engagement context

ClientMunar
My roleSecurity baseline, technical SEO, UX and accessibility audit, handover documentation
Delivery partnerHarry Ndeke — build and AI systems
DeploymentVercel production deployment

Phase 1 — Baseline audit

Before changing anything, the existing state was measured: performance under real network conditions, mobile responsiveness across viewport ranges, HTTP security headers, TLS configuration, and accessibility against WCAG criteria. A baseline matters because it is the only way to demonstrate afterwards that a change was an improvement rather than a preference.

Phase 2 — Security boundary

SCOPE DISCIPLINE
The review was conducted strictly within the authorized scope — configuration, headers, exposed surfaces, and client-side handling. No intrusive or unauthorized scanning was performed against infrastructure outside the agreed boundary, including third-party services the site depends on. Where a risk sat outside scope, it was documented and reported rather than tested.

Practical outcomes included security header configuration, removal of information disclosure in error responses, and verification that no credentials or API keys were reachable from the client bundle.

Phase 3 — Structure, clarity and findability

Phase 4 — Handover

A delivery is not finished when it ships; it is finished when the client can operate it without the people who built it. Handover included credential transfer under client ownership, deployment and rollback documentation, a maintenance record, and a walkthrough of what was changed and why.

What this demonstrates

This engagement is the commercial reference point for the Authorized Web & API Security Assessment service — specifically the discipline of working inside a defined boundary, producing evidence a client can verify, and leaving behind documentation rather than dependency.

START HERE

Engagements begin with a fixed-scope scoping call. Clear decisions before code, and no obligation to proceed to follow-on build work.

Request a Similar Engagement →

Related: AI Integrated Smart Packet Analyzer · All proof & deliveries