Skip to content
View kai63001's full-sized avatar
🟦
𝐰𝐚𝐭𝐜𝐡𝐢𝐧𝐠 𝐭𝐡𝐞 𝐰𝐨𝐫𝐥𝐝 𝐠𝐨 𝐪𝐮𝐢𝐞𝐭.
🟦
𝐰𝐚𝐭𝐜𝐡𝐢𝐧𝐠 𝐭𝐡𝐞 𝐰𝐨𝐫𝐥𝐝 𝐠𝐨 𝐪𝐮𝐢𝐞𝐭.
  • Thailand
  • 23:13 (UTC +07:00)

Highlights

  • Pro

Block or report kai63001

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kai63001/README.md

Header

Hi there, I'm Supanat Konprom 👋

Full-Stack Engineer · Mobile App Developer · Security Researcher

I build production-ready mobile and web applications with a security-first engineering mindset.
My work combines product development, secure architecture, cloud deployment, and responsible vulnerability research.

GitHub Stars HackerOne HackenProof App Store Google Play


🚀 Recruiter Snapshot

💻 Product Engineering

Full-stack development across mobile, frontend, backend, APIs, databases, and infrastructure.

📱 Mobile Delivery

Flutter and iOS development focused on clean architecture, performance, and smooth user experience.

🛡️ Security Research

CVE-recognized vulnerability research, responsible disclosure, bug bounty participation, and secure coding.

Best-fit roles: Full-Stack Engineer · Mobile Engineer · Backend Engineer · Application Security Engineer · Product Security Engineer · Security Researcher

Working style: Practical, detail-oriented, security-aware, and focused on building useful, maintainable, and resilient software.


🧠 What I Bring to a Team

  • Builder mindset: I can take a product from idea, architecture, and implementation through deployment and iteration.
  • Security-first thinking: I look for weak assumptions in authentication, authorization, API design, business logic, data access, and deployment workflows.
  • Clear communication: I document issues with reproducible steps, real impact, affected scope, and remediation guidance.
  • Full lifecycle ownership: I care about reliability, performance, maintainability, developer experience, and long-term product quality.

🧰 Tech Stack

Mobile

Flutter Swift iOS Android

Frontend

Next.js Nuxt Svelte TypeScript JavaScript

Backend & Systems

Node.js NestJS Express.js Rust Go C%23 PHP Solidity

Database, Cloud & DevOps

PostgreSQL MongoDB RabbitMQ Google Pub/Sub Google Cloud Docker Nginx Linux


🛡️ Security Research & CVE Portfolio

I contribute to the cybersecurity community through vulnerability research and responsible disclosure. My research focuses on practical application security weaknesses that can affect authentication, authorization, data exposure, business logic, and secure software design.

Some CVE records may be reserved or pending public details until the assigning CNA publishes the full record.

CVE-2026-7465 CVE-2026-7458 CVE-2026-4664 CVE-2026-3722 CVE-2026-3629 CVE-2026-3454 CVE-2026-3453 CVE-2026-3369 CVE-2026-3365 CVE-2026-3361

Research Approach

Discovery  →  Validation  →  Documentation  →  Responsible Disclosure  →  Follow-through

I aim to help teams understand risk clearly, reproduce issues safely, prioritize fixes, and improve security posture.


📱 Published Apps

🍎 App Store

Supanat Konprom — Developer Profile
View on App Store

▶️ Google Play

Laybiks — Developer Profile
View on Google Play


🎯 Bug Bounty & Security Platforms


Let’s build secure, reliable, and useful software 🚀

Footer

Pinned Loading

  1. wildcard-game wildcard-game Public

    Wild game is NFT Card Game online make with godot or unity, dapp web3 (react,next js) marketplace (sell and buy NFT) and mint (create) NFT upload to IPFS

    C# 112 52

  2. focusify focusify Public

    Focusify.io is a productivity application designed to help you streamline your tasks, organize your notes, master the Pomodoro technique, and create a work environment that resonates with your pers…

    TypeScript 3

  3. peakpicks peakpicks Public

    AI-generated content engine with affiliate monetisation Rust (Actix + SurrealDB) · Next.js frontend

    TypeScript

  4. unclelife unclelife Public

    Building UncleLife.co: A Deep Dive into Next.js, Supabase, and the Power of Notion Integration

    TypeScript

  5. SummarizeIt SummarizeIt Public

    Instant text, video & audio summaries on iOS Flutter client · Python (llmlingua) & Node.js (Whisper) services · MongoDB · RevenueCat IAP

    Dart 2

  6. focusify-chrome-extension focusify-chrome-extension Public

    Your customizable new-tab dashboard for laser-focus and productivity Chrome Extension · React 18 + Vite · Manifest v3

    JavaScript