Skip to content
Andrew Van DykeAndrew Van Dyke

Full-stack products

Web development.

From interactive data tools to paid SaaS, I build full-stack web applications that bring a useful idea all the way through the product loop.

Relevant work

Case studies with links to the running applications.

All work
A deliberately vulnerable Practice Portal SaaS with a red 'intentionally vulnerable demo' banner, alongside a terminal running eight exploits.

2026 · Security audit, exploit development & remediation

The Vibe-Coded SaaS Teardown

A realistic AI-built B2B SaaS with eight planted-but-real vulnerabilities, a reproducible exploit for each (anon key reads every tenant; a member escalates to admin; patient PHI downloads with no auth), and a fixed branch whose 8/8 regression tests prove tenant isolation holds. The diff is the audit.

Explore another focus

Have a related project?

Email me