Hi, I’m Karan Mungara(verified)
Information security · Staffbase · Chemnitz
I own vulnerability management at Staffbase, a $1B+ employee communications company reaching about 16 million employees at roughly 2,000 organisations — Adidas, DHL and Alaska Airlines among them — and I automate the parts that repeat: vendor reviews, security questionnaires, the same scanner finding read four times over. The automation has to show its work: an answer a security team cannot trace back is worth less to them than no answer at all.
One of those assistants took a four-hour vendor security review down to about twenty minutes, at roughly $1.67 a run. It was accurate enough that we cancelled the tool we had been evaluating, and it won the company’s CFO Innovation Award. I also run AI-augmented pentests by wiring Burp Suite Pro to Claude over MCP.
The thread through all of it: get real return out of the AI a company already pays for, instead of buying the next tool. In practice that is agentic engineering with Claude Code, subagents and skills, shipping with React, TypeScript and GSAP.
Elsewhere
Vulnerability mgmt
230+ issues owned
140+ pentest findings retested · 46 bounty reports triaged
AI vendor reviews
4 hours → 20 minutes
At roughly $1.67 a run
GRC automation
10+ questionnaires in 3–4 days
Biggest was 900+ true/false — one wrong answer
ROI, not procurement
Cancelled a tool purchase
The assistant was accurate enough that we did not need it
Recognition
CFO Innovation Award
At Staffbase, a $1B+ company reaching ~16M employees
Journey
I build great software and solve hard, manual problems. Always learning, and teaching as much as I can along the way.
2018
Shipped my first production system
I started in C and PHP and shipped a library management system at NCrypted Technologies — the first code I wrote that real people depended on. That was the hook.
2019
Errsol Technologies LLP
A DPIIT-recognised software agency startup I started in 2019, at 21, in my third year of university. I delivered $50–100k+ in client web projects, created a few jobs along the way, and learned to ship for real.
2021
Moved to Germany
Relocated to Germany to gain deeper experience and explore: a new environment, harder problems, and the start of my path into security and AI.
2023
Into security at Staffbase
Joined the Information Security team as a working student — the door into security I had been working toward since I landed in Germany.
Now
Still at Staffbase, and building alongside it
I own vulnerability management at Staffbase, a $1B+ employee communications company reaching about 16 million employees at roughly 2,000 organisations — Adidas, DHL and Alaska Airlines among them. My AI assistant for vendor security reviews took them from about four hours to about twenty minutes, replaced a tool we were about to buy, and won the CFO Innovation Award. Alongside it I build Answerdeck, VODP and ClaudeSec — all the same idea, that AI should absorb the security busywork and leave the judgement to people.
Experience
Sep 2023 – Present
- Own vulnerability management end to end: 230+ security issues across verification, retesting, bug-bounty triage, and automation.
- Verified and retested 140+ pentest findings (26 High/Critical) across web, mobile, and infrastructure end-to-end, partnering with engineering teams to drive remediation; triaged 46 external bug-bounty reports.
- Built an AI vendor-review assistant: assessments dropped from ~4 hours to ~20 minutes (~12× faster) at ~$1.67 a run. It is accurate enough that we skipped buying an external tool.
- Run AI-augmented penetration testing by wiring Burp Suite Pro to Claude via MCP connectors; built reusable security-questionnaire-completion skills the team uses in real work.
- Shipped a training-compliance bot that automates InfoSec onboarding checks end-to-end, reclaiming hours of manual follow-up each week.
- Authored the security team's central AI-enablement hub and reusable prompt tooling, scaling AI adoption across the team.
Education
- Oct 2021 – Jul 2026
Master's, Web Engineering
Technische Universität Chemnitz · Grade 1.9 · thesis 1.5
- Apr 2021 – Sep 2021
Master's, Automotive Software Engineering
Technische Universität Chemnitz
- 2016 – 2020
B.Tech, Computer Engineering with a specialisation in Cloud Technology & Information Security
Poornima University · CGPA 8.32
- Claude Code in Action(verified credential, opens in a new tab)
- Claude Code 101(verified credential, opens in a new tab)
- Claude 101(verified credential, opens in a new tab)
- Vibe Coding L4: Platinum
- AWS Certified Cloud Practitioner
- Information Security IV
- Machine Learning for Remote Sensing Data Classification
- Photography, Gestion (The Management Colosseum)
Skills
Security & GRC
- Burp Suite Pro
- OWASP ZAP
- Nuclei
- Semgrep
- CodeQL
- SonarCloud
- Socket.dev
- Gitleaks
- TruffleHog
- OSV-Scanner
- Darktrace
- Drata
- Vulnerability mgmt
- Bug bounty triage
- 1Password
AI & agents
- Agentic engineering
- Claude
- Claude Code
- MCP
- Codex
- Cursor
- GitHub Copilot
- Antigravity
- Gemini
- NotebookLM
- Deep research
- LM Studio
- Hugging Face
- ElevenLabs
- Seedance
- Lovable
- Replit
- v0
- n8n
Build
- TypeScript
- React
- Next.js
- Node.js
- Deno
- Express.js
- Vite
- Tailwind
- GSAP
- Python
- C
- PHP · MySQL
- VS Code
Data & platform
- PostgreSQL
- Supabase
- SQLite
- Redis
- Docker
- Vercel
- Cloudflare
- nginx
- AWS
- Azure
Quality & observability
- Playwright
- Postman
- Vitest
- pgTAP
- Sentry
- PostHog
- OpenTelemetry
- GitHub Actions
- Git CI/CD
Design & workplace
- UI/UX design
- Figma
- Canva
- Screen Studio
- Jira
- Confluence
- Slack
- Notion
- Wispr Flow
Projects

Answerdeck
Building
In active development
Security questionnaires gate enterprise deals, and answering them by hand eats a week. Answerdeck draws answers from a team's own evidence and cites the document behind each one. Below a confidence floor it refuses and escalates to a person rather than writing something plausible — and every generation leaves a ten-field decision record, so an auditor can ask why any answer was given. The audit trail is append-only, enforced by database trigger rather than convention. 83 pgTAP tests across row-level security and roles, blocking in CI. EU by design.
- answerdeck.app

Briksync PropOS
Side project
Built with Claude automation agents
A live multi-tenant SaaS where the permission model is the product. Landlord, property manager, broker and tenant each sign in and see only their own part, enforced in the database rather than hidden in the screen — six roles across four kinds of user. I designed that model, then found a cross-tenant leak in it and measured the fix with real tokens: 137 foreign rows visible, driven to 0, with an RLS matrix suite to keep it there. ~4,400 executed test cases across 219 files, 105 migrations, and custom checks for search-path hardening, plan-limit drift and identity leaks.
- briksync.com

aifoxx
Active
Is this tool SOC 2? Do they train on our data? Where does it live? Those three questions kill every AI shortlist. aifoxx records them once, comparably, with a link to the vendor page that proves each one: 992 AI tools, 1,979 MCP servers, 1,638 Claude Code skills and 980 vendor trust reports. Every true flag carries a source URL on the vendor's own domain, and null means unverified — never false, enforced in the schema. Our own products appear with the same fields and no ranking advantage. Open source, MIT.
- aifoxx.com

Co-Founder OS
Experiment
An autonomous OS run by AI personas with memory. It drafts, plans, researches, and queues actions for your approval. Currently used by me; collaboration welcome.
- cofounder-ai-os.lovable.app
Open source
How this gets built
I don’t write code by hand. I dispatch agents — and I can tell you exactly how much, because I built the tool that measures it. ClaudeSec instruments every tool call my agents make. Across my own projects it has logged 385,647 spans over 146 repositories and three agent harnesses, and raised 4,843 alerts on my own agents — 22 of them critical. My session transcripts add the other half: 836 subagents dispatched across 1,358 sessions, at roughly seven agent or CLI actions for every hand edit.
The agents that write my code are watched by the tool I built to watch agents.
Writing
- We Built an AI Teammate That Takes the Grind Out of Security QuestionnairesJune 2026
- Today I Learned: Genuinely Capable AI Now Runs on My LaptopJune 2026
- I Spent $8 to Mass-Pentest My SaaS. A Human Would Have Cost $15,000.April 2026
- Everyone Vibe-Codes. Nobody Vibe-Engineers.April 2026
- Why I Wired Observability Before Writing a Single FeatureApril 2026
Learning
AI-augmented pentesting
Burp Suite Pro driven from Claude over MCP; turning findings into reusable skills.
Local models for security work
Gemma 4 QAT on a MacBook Pro: what runs on-device and what it doesn't solve.
Multi-agent orchestration
Persona subagents, orchestration patterns, and where they break.
When I’m offline
Staring at the sky.
Photographs are on their way.
Kind words
“Karan is a creator and an innovator. His ability to think differently and take risks puts him way ahead of his generation. Gifted with leadership, exuberance and positivity, he's on his way to do big things.”
Aanjaneya Singh Dhoni · Cybersecurity Consultant @ PwC
“Karan is very hardworking and dedicated, always ready to work in any situation. An excellent manager: he runs Errsol Technologies, managing project flow and assigning tasks. A focused and visionary person.”
Harish Dhakad · DevOps & SRE Engineer
“Karan is an excellent web developer with amazing products and solution delivery. We have worked together on many of his freelancing projects and it turns out to be great.”
Aman Khandelwal · Senior DevOps Engineer & Cloud Economics Enthusiast
“Karan is wonderful to work with and has exceptional expertise in leadership. He consistently demonstrates a solid work ethic. Dedicated, self-motivated and very capable, with a very positive attitude.”
Aayushi Solanki · Software Engineer | AWS Certified
Questions
- Who is Karan Rajeshbhai Mungara?
- Karan Rajeshbhai Mungara (known online as withkarann) is a Information Security Analyst at Staffbase and the creator of VODP, Answerdeck, Briksync PropOS, and ClaudeSec. He works on application security, AI-augmented penetration testing, and security automation. He is based in Chemnitz, Germany.
- What is VODP?
- VODP (vodp.dev) is a Vulnerability Orchestration & Deduplication Platform created by Karan Rajeshbhai Mungara as part of his M.Sc. thesis. It ingests findings from multiple scanners, normalises and deduplicates them, schedules proactive scans, and automatically re-tests a claimed fix where a scanner template covers it in about two seconds. On the DVWA benchmark it turned 531 raw findings into 37 real ones at 99.2% precision and 99.4% recall.
- What is Answerdeck?
- Answerdeck (answerdeck.app) is a compliance intelligence layer for SaaS security teams, created by Karan Rajeshbhai Mungara. It turns a team's security and compliance knowledge into sourced, review-ready answers, rather than being a one-off questionnaire tool.
- What does Karan do at Staffbase?
- At Staffbase, Karan owns vulnerability management end to end across web, mobile, and infrastructure. He verifies and retests pentest findings, triages external bug-bounty reports, and partners with engineering on remediation. He also builds AI security automation. His AI vendor-review assistant cut assessments from about 4 hours to roughly 20 minutes (around 12× faster), removing the need to buy an external tool.
- What is Briksync PropOS?
- Briksync PropOS (briksync.com) is a real-estate operations platform created by Karan Rajeshbhai Mungara. It's an independent side project that brings operations, listings, and workflows into one system.
- What is Errsol Technologies?
- Errsol Technologies LLP (errsol.com) is a DPIIT-recognised software agency startup Karan Rajeshbhai Mungara founded in 2019, at 21. It delivered web applications and AI-driven products; its client web-application work has delivered $50–100k+ in project value.
- Where is Karan based and how can I contact him?
- Karan is based in Chemnitz, Germany. Reach him at withkarann@gmail.com for anything personal, karan@answerdeck.app for Answerdeck, or hello@errsol.com for Errsol Technologies. He is also @withkarann on LinkedIn, GitHub, and X.
- What is a compliance intelligence layer?
- A compliance intelligence layer sits on top of a team's existing security and compliance knowledge (policies, evidence, prior answers and controls) and turns it into sourced, review-ready answers. This is the category Answerdeck (answerdeck.app), built by Karan Rajeshbhai Mungara, operates in; it is positioned as intelligence infrastructure for compliance, not a single-purpose questionnaire tool.
- What tools and technologies does Karan use?
- Karan builds with React, TypeScript and GSAP on the front end, and works heavily with AI tooling: Claude, Claude Code, and MCP connectors for automation and AI-assisted security work. He drives penetration testing in plain language by connecting Burp Suite Pro to Claude through MCP, and uses local models via LM Studio and Hugging Face (granite-docling, gemma). He focuses on AI agents, security automation, and getting the most out of large language models.
- Is Karan available for collaboration, advice, or speaking?
- Yes. Karan enjoys talking shop about AI systems, security automation, and building real projects. The best way to reach him is by email: withkarann@gmail.com for personal matters, karan@answerdeck.app for Answerdeck, or hello@errsol.com for Errsol. He is also @withkarann on LinkedIn, GitHub, and X.