Skip to content
Karan Mungara

Hi, I’m Karan Mungara(verified)

Information security · Staffbase · Chemnitz

I own vulnerability management at Staffbase, a $1B+ employee communications company reaching about 16 million employees at roughly 2,000 organisations — Adidas, DHL and Alaska Airlines among them — and I automate the parts that repeat: vendor reviews, security questionnaires, the same scanner finding read four times over. The automation has to show its work: an answer a security team cannot trace back is worth less to them than no answer at all.

One of those assistants took a four-hour vendor security review down to about twenty minutes, at roughly $1.67 a run. It was accurate enough that we cancelled the tool we had been evaluating, and it won the company’s CFO Innovation Award. I also run AI-augmented pentests by wiring Burp Suite Pro to Claude over MCP.

The thread through all of it: get real return out of the AI a company already pays for, instead of buying the next tool. In practice that is agentic engineering with Claude Code, subagents and skills, shipping with React, TypeScript and GSAP.

Email me

Elsewhere

  • Vulnerability mgmt

    230+ issues owned

    140+ pentest findings retested · 46 bounty reports triaged

  • AI vendor reviews

    4 hours → 20 minutes

    At roughly $1.67 a run

  • GRC automation

    10+ questionnaires in 3–4 days

    Biggest was 900+ true/false — one wrong answer

  • ROI, not procurement

    Cancelled a tool purchase

    The assistant was accurate enough that we did not need it

  • Recognition

    CFO Innovation Award

    At Staffbase, a $1B+ company reaching ~16M employees

Journey

I build great software and solve hard, manual problems. Always learning, and teaching as much as I can along the way.

  1. 2018

    Shipped my first production system

    I started in C and PHP and shipped a library management system at NCrypted Technologies — the first code I wrote that real people depended on. That was the hook.

  2. 2019

    Errsol Technologies LLP

    A DPIIT-recognised software agency startup I started in 2019, at 21, in my third year of university. I delivered $50–100k+ in client web projects, created a few jobs along the way, and learned to ship for real.

  3. 2021

    Moved to Germany

    Relocated to Germany to gain deeper experience and explore: a new environment, harder problems, and the start of my path into security and AI.

  4. 2023

    Into security at Staffbase

    Joined the Information Security team as a working student — the door into security I had been working toward since I landed in Germany.

  5. Now

    Still at Staffbase, and building alongside it

    I own vulnerability management at Staffbase, a $1B+ employee communications company reaching about 16 million employees at roughly 2,000 organisations — Adidas, DHL and Alaska Airlines among them. My AI assistant for vendor security reviews took them from about four hours to about twenty minutes, replaced a tool we were about to buy, and won the CFO Innovation Award. Alongside it I build Answerdeck, VODP and ClaudeSec — all the same idea, that AI should absorb the security busywork and leave the judgement to people.

Experience

Sep 2023 – Present

  • Own vulnerability management end to end: 230+ security issues across verification, retesting, bug-bounty triage, and automation.
  • Verified and retested 140+ pentest findings (26 High/Critical) across web, mobile, and infrastructure end-to-end, partnering with engineering teams to drive remediation; triaged 46 external bug-bounty reports.
  • Built an AI vendor-review assistant: assessments dropped from ~4 hours to ~20 minutes (~12× faster) at ~$1.67 a run. It is accurate enough that we skipped buying an external tool.
  • Run AI-augmented penetration testing by wiring Burp Suite Pro to Claude via MCP connectors; built reusable security-questionnaire-completion skills the team uses in real work.
  • Shipped a training-compliance bot that automates InfoSec onboarding checks end-to-end, reclaiming hours of manual follow-up each week.
  • Authored the security team's central AI-enablement hub and reusable prompt tooling, scaling AI adoption across the team.
staffbase.com

Education

  • Master's, Web Engineering

    Technische Universität Chemnitz · Grade 1.9 · thesis 1.5

    Oct 2021 – Jul 2026
  • Master's, Automotive Software Engineering

    Technische Universität Chemnitz

    Apr 2021 – Sep 2021
  • B.Tech, Computer Engineering with a specialisation in Cloud Technology & Information Security

    Poornima University · CGPA 8.32

    2016 – 2020

Skills

Security & GRC

  • Burp Suite Pro
  • OWASP ZAP
  • Nuclei
  • Semgrep
  • CodeQL
  • SonarCloud
  • Socket.dev
  • Gitleaks
  • TruffleHog
  • OSV-Scanner
  • Darktrace
  • Drata
  • Vulnerability mgmt
  • Bug bounty triage
  • 1Password

AI & agents

  • Agentic engineering
  • Claude
  • Claude Code
  • MCP
  • Codex
  • Cursor
  • GitHub Copilot
  • Antigravity
  • Gemini
  • NotebookLM
  • Deep research
  • LM Studio
  • Hugging Face
  • ElevenLabs
  • Seedance
  • Lovable
  • Replit
  • v0
  • n8n

Build

  • TypeScript
  • React
  • Next.js
  • Node.js
  • Deno
  • Express.js
  • Vite
  • Tailwind
  • GSAP
  • Python
  • C
  • PHP · MySQL
  • VS Code

Data & platform

  • PostgreSQL
  • Supabase
  • SQLite
  • Redis
  • Docker
  • Vercel
  • Cloudflare
  • nginx
  • AWS
  • Azure

Quality & observability

  • Playwright
  • Postman
  • Vitest
  • pgTAP
  • Sentry
  • PostHog
  • OpenTelemetry
  • GitHub Actions
  • Git CI/CD

Design & workplace

  • UI/UX design
  • Figma
  • Canva
  • Screen Studio
  • Jira
  • Confluence
  • Slack
  • Notion
  • Wispr Flow

Projects

  • Answerdeck landing page with "The Compliance Intelligence Layer" hero

    Answerdeck

    Building

    In active development

    Security questionnaires gate enterprise deals, and answering them by hand eats a week. Answerdeck draws answers from a team's own evidence and cites the document behind each one. Below a confidence floor it refuses and escalates to a person rather than writing something plausible — and every generation leaves a ten-field decision record, so an auditor can ask why any answer was given. The audit trail is append-only, enforced by database trigger rather than convention. 83 pgTAP tests across row-level security and roles, blocking in CI. EU by design.

    • answerdeck.app
  • Briksync PropOS landing page with "The operating system for modern property teams" hero and a dashboard preview

    Briksync PropOS

    Side project

    Built with Claude automation agents

    A live multi-tenant SaaS where the permission model is the product. Landlord, property manager, broker and tenant each sign in and see only their own part, enforced in the database rather than hidden in the screen — six roles across four kinds of user. I designed that model, then found a cross-tenant leak in it and measured the fix with real tokens: 137 foreign rows visible, driven to 0, with an RLS matrix suite to keep it there. ~4,400 executed test cases across 219 files, 105 migrations, and custom checks for search-path hardening, plan-limit drift and identity leaks.

    • briksync.com
  • aifoxx landing page, a curated directory of 992 AI tools with pricing and data-privacy facts

    aifoxx

    Active

    Is this tool SOC 2? Do they train on our data? Where does it live? Those three questions kill every AI shortlist. aifoxx records them once, comparably, with a link to the vendor page that proves each one: 992 AI tools, 1,979 MCP servers, 1,638 Claude Code skills and 980 vendor trust reports. Every true flag carries a source URL on the vendor's own domain, and null means unverified — never false, enforced in the schema. Our own products appear with the same fields and no ranking advantage. Open source, MIT.

    • aifoxx.com
  • Co-Founder OS landing page with "An autonomous operating system for the life you actually live" hero

    Co-Founder OS

    Experiment

    An autonomous OS run by AI personas with memory. It drafts, plans, researches, and queues actions for your approval. Currently used by me; collaboration welcome.

    • cofounder-ai-os.lovable.app

Open source

3,618 contributions in the last yearAugust 2025 – August 2026
SepOctNovDecJanFebMarAprMayJunJulAug0 contributions on 2025-08-310 contributions on 2025-09-010 contributions on 2025-09-020 contributions on 2025-09-030 contributions on 2025-09-040 contributions on 2025-09-050 contributions on 2025-09-060 contributions on 2025-09-071 contribution on 2025-09-080 contributions on 2025-09-090 contributions on 2025-09-100 contributions on 2025-09-110 contributions on 2025-09-120 contributions on 2025-09-130 contributions on 2025-09-140 contributions on 2025-09-150 contributions on 2025-09-160 contributions on 2025-09-170 contributions on 2025-09-180 contributions on 2025-09-190 contributions on 2025-09-200 contributions on 2025-09-210 contributions on 2025-09-220 contributions on 2025-09-230 contributions on 2025-09-240 contributions on 2025-09-250 contributions on 2025-09-260 contributions on 2025-09-270 contributions on 2025-09-282 contributions on 2025-09-290 contributions on 2025-09-300 contributions on 2025-10-016 contributions on 2025-10-023 contributions on 2025-10-0321 contributions on 2025-10-043 contributions on 2025-10-051 contribution on 2025-10-062 contributions on 2025-10-073 contributions on 2025-10-080 contributions on 2025-10-090 contributions on 2025-10-100 contributions on 2025-10-110 contributions on 2025-10-120 contributions on 2025-10-130 contributions on 2025-10-140 contributions on 2025-10-150 contributions on 2025-10-163 contributions on 2025-10-171 contribution on 2025-10-180 contributions on 2025-10-190 contributions on 2025-10-200 contributions on 2025-10-210 contributions on 2025-10-220 contributions on 2025-10-230 contributions on 2025-10-240 contributions on 2025-10-250 contributions on 2025-10-260 contributions on 2025-10-270 contributions on 2025-10-280 contributions on 2025-10-290 contributions on 2025-10-300 contributions on 2025-10-310 contributions on 2025-11-010 contributions on 2025-11-020 contributions on 2025-11-030 contributions on 2025-11-040 contributions on 2025-11-050 contributions on 2025-11-060 contributions on 2025-11-070 contributions on 2025-11-080 contributions on 2025-11-090 contributions on 2025-11-100 contributions on 2025-11-110 contributions on 2025-11-120 contributions on 2025-11-130 contributions on 2025-11-140 contributions on 2025-11-150 contributions on 2025-11-160 contributions on 2025-11-170 contributions on 2025-11-180 contributions on 2025-11-190 contributions on 2025-11-200 contributions on 2025-11-210 contributions on 2025-11-220 contributions on 2025-11-230 contributions on 2025-11-240 contributions on 2025-11-250 contributions on 2025-11-260 contributions on 2025-11-270 contributions on 2025-11-280 contributions on 2025-11-290 contributions on 2025-11-300 contributions on 2025-12-010 contributions on 2025-12-020 contributions on 2025-12-030 contributions on 2025-12-040 contributions on 2025-12-050 contributions on 2025-12-060 contributions on 2025-12-070 contributions on 2025-12-080 contributions on 2025-12-090 contributions on 2025-12-100 contributions on 2025-12-110 contributions on 2025-12-120 contributions on 2025-12-130 contributions on 2025-12-140 contributions on 2025-12-150 contributions on 2025-12-160 contributions on 2025-12-170 contributions on 2025-12-180 contributions on 2025-12-190 contributions on 2025-12-200 contributions on 2025-12-210 contributions on 2025-12-220 contributions on 2025-12-230 contributions on 2025-12-240 contributions on 2025-12-250 contributions on 2025-12-260 contributions on 2025-12-270 contributions on 2025-12-280 contributions on 2025-12-290 contributions on 2025-12-306 contributions on 2025-12-310 contributions on 2026-01-0111 contributions on 2026-01-020 contributions on 2026-01-031 contribution on 2026-01-043 contributions on 2026-01-054 contributions on 2026-01-060 contributions on 2026-01-070 contributions on 2026-01-082 contributions on 2026-01-090 contributions on 2026-01-101 contribution on 2026-01-111 contribution on 2026-01-121 contribution on 2026-01-131 contribution on 2026-01-140 contributions on 2026-01-151 contribution on 2026-01-164 contributions on 2026-01-170 contributions on 2026-01-181 contribution on 2026-01-190 contributions on 2026-01-200 contributions on 2026-01-210 contributions on 2026-01-223 contributions on 2026-01-230 contributions on 2026-01-240 contributions on 2026-01-250 contributions on 2026-01-262 contributions on 2026-01-275 contributions on 2026-01-281 contribution on 2026-01-295 contributions on 2026-01-300 contributions on 2026-01-310 contributions on 2026-02-010 contributions on 2026-02-020 contributions on 2026-02-031 contribution on 2026-02-040 contributions on 2026-02-050 contributions on 2026-02-060 contributions on 2026-02-070 contributions on 2026-02-080 contributions on 2026-02-090 contributions on 2026-02-100 contributions on 2026-02-110 contributions on 2026-02-122 contributions on 2026-02-130 contributions on 2026-02-140 contributions on 2026-02-150 contributions on 2026-02-160 contributions on 2026-02-173 contributions on 2026-02-182 contributions on 2026-02-196 contributions on 2026-02-200 contributions on 2026-02-210 contributions on 2026-02-222 contributions on 2026-02-239 contributions on 2026-02-240 contributions on 2026-02-250 contributions on 2026-02-264 contributions on 2026-02-271 contribution on 2026-02-280 contributions on 2026-03-012 contributions on 2026-03-020 contributions on 2026-03-035 contributions on 2026-03-043 contributions on 2026-03-050 contributions on 2026-03-061 contribution on 2026-03-07243 contributions on 2026-03-089 contributions on 2026-03-0914 contributions on 2026-03-104 contributions on 2026-03-110 contributions on 2026-03-1256 contributions on 2026-03-1319 contributions on 2026-03-142 contributions on 2026-03-1517 contributions on 2026-03-1616 contributions on 2026-03-170 contributions on 2026-03-188 contributions on 2026-03-1911 contributions on 2026-03-203 contributions on 2026-03-210 contributions on 2026-03-221 contribution on 2026-03-230 contributions on 2026-03-2484 contributions on 2026-03-250 contributions on 2026-03-260 contributions on 2026-03-2721 contributions on 2026-03-2812 contributions on 2026-03-290 contributions on 2026-03-3028 contributions on 2026-03-317 contributions on 2026-04-014 contributions on 2026-04-0224 contributions on 2026-04-030 contributions on 2026-04-040 contributions on 2026-04-0518 contributions on 2026-04-0674 contributions on 2026-04-0710 contributions on 2026-04-083 contributions on 2026-04-090 contributions on 2026-04-1021 contributions on 2026-04-1114 contributions on 2026-04-120 contributions on 2026-04-1312 contributions on 2026-04-141 contribution on 2026-04-1519 contributions on 2026-04-161 contribution on 2026-04-1710 contributions on 2026-04-180 contributions on 2026-04-1948 contributions on 2026-04-200 contributions on 2026-04-210 contributions on 2026-04-228 contributions on 2026-04-2337 contributions on 2026-04-2474 contributions on 2026-04-25122 contributions on 2026-04-260 contributions on 2026-04-270 contributions on 2026-04-280 contributions on 2026-04-290 contributions on 2026-04-304 contributions on 2026-05-010 contributions on 2026-05-020 contributions on 2026-05-030 contributions on 2026-05-040 contributions on 2026-05-050 contributions on 2026-05-060 contributions on 2026-05-070 contributions on 2026-05-080 contributions on 2026-05-094 contributions on 2026-05-100 contributions on 2026-05-110 contributions on 2026-05-120 contributions on 2026-05-1322 contributions on 2026-05-1440 contributions on 2026-05-150 contributions on 2026-05-160 contributions on 2026-05-1745 contributions on 2026-05-1872 contributions on 2026-05-19198 contributions on 2026-05-2016 contributions on 2026-05-2134 contributions on 2026-05-2296 contributions on 2026-05-2334 contributions on 2026-05-2413 contributions on 2026-05-2526 contributions on 2026-05-2612 contributions on 2026-05-2712 contributions on 2026-05-2847 contributions on 2026-05-294 contributions on 2026-05-3033 contributions on 2026-05-31103 contributions on 2026-06-0135 contributions on 2026-06-022 contributions on 2026-06-032 contributions on 2026-06-0418 contributions on 2026-06-0519 contributions on 2026-06-0611 contributions on 2026-06-0714 contributions on 2026-06-0895 contributions on 2026-06-0918 contributions on 2026-06-1028 contributions on 2026-06-1114 contributions on 2026-06-122 contributions on 2026-06-132 contributions on 2026-06-1431 contributions on 2026-06-152 contributions on 2026-06-1618 contributions on 2026-06-1710 contributions on 2026-06-186 contributions on 2026-06-192 contributions on 2026-06-202 contributions on 2026-06-2114 contributions on 2026-06-222 contributions on 2026-06-232 contributions on 2026-06-243 contributions on 2026-06-258 contributions on 2026-06-2612 contributions on 2026-06-272 contributions on 2026-06-2852 contributions on 2026-06-298 contributions on 2026-06-302 contributions on 2026-07-012 contributions on 2026-07-022 contributions on 2026-07-034 contributions on 2026-07-042 contributions on 2026-07-0510 contributions on 2026-07-0690 contributions on 2026-07-072 contributions on 2026-07-0812 contributions on 2026-07-09140 contributions on 2026-07-1078 contributions on 2026-07-1161 contributions on 2026-07-1245 contributions on 2026-07-133 contributions on 2026-07-142 contributions on 2026-07-158 contributions on 2026-07-16126 contributions on 2026-07-1726 contributions on 2026-07-1858 contributions on 2026-07-1913 contributions on 2026-07-2010 contributions on 2026-07-212 contributions on 2026-07-222 contributions on 2026-07-232 contributions on 2026-07-242 contributions on 2026-07-2515 contributions on 2026-07-262 contributions on 2026-07-272 contributions on 2026-07-282 contributions on 2026-07-292 contributions on 2026-07-302 contributions on 2026-07-312 contributions on 2026-08-012 contributions on 2026-08-022 contributions on 2026-08-032 contributions on 2026-08-042 contributions on 2026-08-052 contributions on 2026-08-062 contributions on 2026-08-0785 contributions on 2026-08-0811 contributions on 2026-08-092 contributions on 2026-08-102 contributions on 2026-08-112 contributions on 2026-08-122 contributions on 2026-08-132 contributions on 2026-08-1449 contributions on 2026-08-1539 contributions on 2026-08-1617 contributions on 2026-08-172 contributions on 2026-08-182 contributions on 2026-08-192 contributions on 2026-08-202 contributions on 2026-08-212 contributions on 2026-08-222 contributions on 2026-08-236 contributions on 2026-08-242 contributions on 2026-08-252 contributions on 2026-08-264 contributions on 2026-08-27109 contributions on 2026-08-2873 contributions on 2026-08-2912 contributions on 2026-08-300 contributions on 2026-08-31
LessMoresnapshot · 2026-08-31

How this gets built

I don’t write code by hand. I dispatch agents — and I can tell you exactly how much, because I built the tool that measures it. ClaudeSec instruments every tool call my agents make. Across my own projects it has logged 385,647 spans over 146 repositories and three agent harnesses, and raised 4,843 alerts on my own agents — 22 of them critical. My session transcripts add the other half: 836 subagents dispatched across 1,358 sessions, at roughly seven agent or CLI actions for every hand edit.

The agents that write my code are watched by the tool I built to watch agents.

Writing

Learning

When I’m offline

Staring at the sky.

Photographs are on their way.

Kind words

  • Karan is a creator and an innovator. His ability to think differently and take risks puts him way ahead of his generation. Gifted with leadership, exuberance and positivity, he's on his way to do big things.

    Aanjaneya Singh Dhoni · Cybersecurity Consultant @ PwC

  • Karan is very hardworking and dedicated, always ready to work in any situation. An excellent manager: he runs Errsol Technologies, managing project flow and assigning tasks. A focused and visionary person.

    Harish Dhakad · DevOps & SRE Engineer

  • Karan is an excellent web developer with amazing products and solution delivery. We have worked together on many of his freelancing projects and it turns out to be great.

    Aman Khandelwal · Senior DevOps Engineer & Cloud Economics Enthusiast

  • Karan is wonderful to work with and has exceptional expertise in leadership. He consistently demonstrates a solid work ethic. Dedicated, self-motivated and very capable, with a very positive attitude.

    Aayushi Solanki · Software Engineer | AWS Certified

Questions

Who is Karan Rajeshbhai Mungara?
Karan Rajeshbhai Mungara (known online as withkarann) is a Information Security Analyst at Staffbase and the creator of VODP, Answerdeck, Briksync PropOS, and ClaudeSec. He works on application security, AI-augmented penetration testing, and security automation. He is based in Chemnitz, Germany.
What is VODP?
VODP (vodp.dev) is a Vulnerability Orchestration & Deduplication Platform created by Karan Rajeshbhai Mungara as part of his M.Sc. thesis. It ingests findings from multiple scanners, normalises and deduplicates them, schedules proactive scans, and automatically re-tests a claimed fix where a scanner template covers it in about two seconds. On the DVWA benchmark it turned 531 raw findings into 37 real ones at 99.2% precision and 99.4% recall.
What is Answerdeck?
Answerdeck (answerdeck.app) is a compliance intelligence layer for SaaS security teams, created by Karan Rajeshbhai Mungara. It turns a team's security and compliance knowledge into sourced, review-ready answers, rather than being a one-off questionnaire tool.
What does Karan do at Staffbase?
At Staffbase, Karan owns vulnerability management end to end across web, mobile, and infrastructure. He verifies and retests pentest findings, triages external bug-bounty reports, and partners with engineering on remediation. He also builds AI security automation. His AI vendor-review assistant cut assessments from about 4 hours to roughly 20 minutes (around 12× faster), removing the need to buy an external tool.
What is Briksync PropOS?
Briksync PropOS (briksync.com) is a real-estate operations platform created by Karan Rajeshbhai Mungara. It's an independent side project that brings operations, listings, and workflows into one system.
What is Errsol Technologies?
Errsol Technologies LLP (errsol.com) is a DPIIT-recognised software agency startup Karan Rajeshbhai Mungara founded in 2019, at 21. It delivered web applications and AI-driven products; its client web-application work has delivered $50–100k+ in project value.
Where is Karan based and how can I contact him?
Karan is based in Chemnitz, Germany. Reach him at withkarann@gmail.com for anything personal, karan@answerdeck.app for Answerdeck, or hello@errsol.com for Errsol Technologies. He is also @withkarann on LinkedIn, GitHub, and X.
What is a compliance intelligence layer?
A compliance intelligence layer sits on top of a team's existing security and compliance knowledge (policies, evidence, prior answers and controls) and turns it into sourced, review-ready answers. This is the category Answerdeck (answerdeck.app), built by Karan Rajeshbhai Mungara, operates in; it is positioned as intelligence infrastructure for compliance, not a single-purpose questionnaire tool.
What tools and technologies does Karan use?
Karan builds with React, TypeScript and GSAP on the front end, and works heavily with AI tooling: Claude, Claude Code, and MCP connectors for automation and AI-assisted security work. He drives penetration testing in plain language by connecting Burp Suite Pro to Claude through MCP, and uses local models via LM Studio and Hugging Face (granite-docling, gemma). He focuses on AI agents, security automation, and getting the most out of large language models.
Is Karan available for collaboration, advice, or speaking?
Yes. Karan enjoys talking shop about AI systems, security automation, and building real projects. The best way to reach him is by email: withkarann@gmail.com for personal matters, karan@answerdeck.app for Answerdeck, or hello@errsol.com for Errsol. He is also @withkarann on LinkedIn, GitHub, and X.