Zum Inhalt springen
Karan Mungara

Hallo, ich bin Karan Mungara(verifiziert)

Informationssicherheit · Staffbase · Chemnitz

Ich verantworte das Vulnerability Management bei Staffbase, einem Unternehmen für Mitarbeiterkommunikation mit einer Bewertung von über 1 Mrd. $, das rund 16 Millionen Beschäftigte in etwa 2.000 Organisationen erreicht — darunter Adidas, DHL und Alaska Airlines. Und ich automatisiere die Teile, die sich wiederholen: Vendor-Reviews, Security-Fragebögen, denselben Scanner-Befund viermal gelesen. Die Automatisierung muss dabei nachvollziehbar bleiben: Eine Antwort, die ein Security-Team nicht zurückverfolgen kann, ist weniger wert als gar keine Antwort.

Einer dieser Assistenten hat ein vierstündiges Vendor-Security-Review auf etwa zwanzig Minuten verkürzt, bei rund 1,67 $ pro Durchlauf. Er war genau genug, dass wir den Kauf des evaluierten Tools abgesagt haben, und er wurde mit dem CFO Innovation Award des Unternehmens ausgezeichnet. Außerdem führe ich KI-gestützte Pentests durch, indem ich Burp Suite Pro über MCP an Claude anbinde.

Der rote Faden: echten Nutzen aus der KI ziehen, für die ein Unternehmen ohnehin schon bezahlt, statt das nächste Tool zu kaufen. In der Praxis heißt das Agentic Engineering mit Claude Code, Subagents und Skills, umgesetzt mit React, TypeScript und GSAP.

E-Mail schreiben

Anderswo

  • Schwachstellenmanagement

    230+ Vorfälle verantwortet

    140+ Pentest-Befunde nachgetestet · 46 Bug-Bounty-Meldungen triagiert

  • KI-Lieferantenprüfungen

    4 Stunden → 20 Minuten

    Bei etwa 1,67 $ pro Durchlauf

  • GRC-Automatisierung

    10+ Fragebögen in 3–4 Tagen

    Der größte mit 900+ Ja/Nein-Fragen — eine falsche Antwort

  • ROI statt Einkauf

    Toolkauf abgesagt

    Der Assistent war genau genug, dass wir es nicht brauchten

  • Auszeichnung

    CFO Innovation Award

    Bei Staffbase, über 1 Mrd. $ bewertet, ~16 Mio. Beschäftigte

Werdegang

Ich baue großartige Software und löse schwierige, manuelle Probleme. Ich lerne ständig dazu und gebe so viel wie möglich davon weiter.

  1. 2018

    Erstes Produktivsystem ausgeliefert

    Angefangen habe ich mit C und PHP und bei NCrypted Technologies ein Bibliotheksverwaltungssystem ausgeliefert — der erste Code von mir, auf den sich echte Menschen verlassen haben. Das hat mich gepackt.

  2. 2019

    Errsol Technologies LLP

    Eine DPIIT-anerkannte Software-Agentur, die ich 2019 mit 21 Jahren im dritten Studienjahr gegründet habe. Ich habe über 50.000–100.000 $ an Kunden-Webprojekten umgesetzt, dabei ein paar Arbeitsplätze geschaffen und gelernt, wirklich zu liefern.

  3. 2021

    Umzug nach Deutschland

    Nach Deutschland gezogen, um tiefer einzusteigen: eine neue Umgebung, schwierigere Probleme und der Anfang meines Wegs in Security und KI.

  4. 2023

    Einstieg in Security bei Staffbase

    Im Information-Security-Team angefangen — die Tür in die Security, auf die ich seit meiner Ankunft in Deutschland hingearbeitet hatte.

  5. Now

    Weiterhin bei Staffbase — und baue nebenbei

    Ich verantworte das Vulnerability Management bei Staffbase, einem Unternehmen für Mitarbeiterkommunikation mit über 1 Mrd. $ Bewertung, das rund 16 Millionen Beschäftigte in etwa 2.000 Organisationen erreicht — darunter Adidas, DHL und Alaska Airlines. Mein KI-Assistent für Vendor-Security-Reviews hat sie von rund vier Stunden auf etwa zwanzig Minuten gebracht, einen geplanten Toolkauf ersetzt und den CFO Innovation Award gewonnen. Daneben baue ich Answerdeck, VODP und ClaudeSec — alles dieselbe Idee: KI soll die Fleißarbeit in der Security übernehmen und das Urteil den Menschen überlassen.

Berufserfahrung

Sep 2023 – heute

  • Verantworte das Vulnerability Management von Anfang bis Ende: über 230 Sicherheitsvorfälle über Verifizierung, Nachtests, Bug-Bounty-Triage und Automatisierung hinweg.
  • Über 140 Pentest-Befunde (26 mit hoher oder kritischer Schwere) über Web, Mobile und Infrastruktur verifiziert und nachgetestet, gemeinsam mit den Engineering-Teams bis zur Behebung; 46 externe Bug-Bounty-Meldungen triagiert.
  • Einen KI-Assistenten für Vendor-Reviews gebaut: Assessments sanken von rund 4 Stunden auf etwa 20 Minuten (rund 12× schneller) bei etwa 1,67 $ pro Durchlauf. Genau genug, dass wir auf den Kauf eines externen Tools verzichtet haben.
  • Führe KI-gestützte Penetrationstests durch, indem ich Burp Suite Pro über MCP-Connectors an Claude anbinde; wiederverwendbare Skills für das Ausfüllen von Security-Fragebögen gebaut, die das Team im Alltag nutzt.
  • Einen Bot für Schulungs-Compliance ausgeliefert, der InfoSec-Onboarding-Checks durchgängig automatisiert und jede Woche Stunden manueller Nachverfolgung spart.
  • Den zentralen KI-Enablement-Hub des Security-Teams samt wiederverwendbarem Prompt-Tooling aufgebaut und damit die KI-Nutzung im Team skaliert.
staffbase.com

Ausbildung

  • Master's, Web Engineering

    Technische Universität Chemnitz · Grade 1.9 · thesis 1.5

    Oct 2021 – Jul 2026
  • Master's, Automotive Software Engineering

    Technische Universität Chemnitz

    Apr 2021 – Sep 2021
  • B.Tech, Computer Engineering with a specialisation in Cloud Technology & Information Security

    Poornima University · CGPA 8.32

    2016 – 2020

Fähigkeiten

Sicherheit & GRC

  • Burp Suite Pro
  • OWASP ZAP
  • Nuclei
  • Semgrep
  • CodeQL
  • SonarCloud
  • Socket.dev
  • Gitleaks
  • TruffleHog
  • OSV-Scanner
  • Darktrace
  • Drata
  • Vulnerability mgmt
  • Bug bounty triage
  • 1Password

KI & Agenten

  • Agentic engineering
  • Claude
  • Claude Code
  • MCP
  • Codex
  • Cursor
  • GitHub Copilot
  • Antigravity
  • Gemini
  • NotebookLM
  • Deep research
  • LM Studio
  • Hugging Face
  • ElevenLabs
  • Seedance
  • Lovable
  • Replit
  • v0
  • n8n

Entwicklung

  • TypeScript
  • React
  • Next.js
  • Node.js
  • Deno
  • Express.js
  • Vite
  • Tailwind
  • GSAP
  • Python
  • C
  • PHP · MySQL
  • VS Code

Daten & Plattform

  • PostgreSQL
  • Supabase
  • SQLite
  • Redis
  • Docker
  • Vercel
  • Cloudflare
  • nginx
  • AWS
  • Azure

Qualität & Observability

  • Playwright
  • Postman
  • Vitest
  • pgTAP
  • Sentry
  • PostHog
  • OpenTelemetry
  • GitHub Actions
  • Git CI/CD

Design & Arbeitsplatz

  • UI/UX design
  • Figma
  • Canva
  • Screen Studio
  • Jira
  • Confluence
  • Slack
  • Notion
  • Wispr Flow

Projekte

  • Answerdeck landing page with "The Compliance Intelligence Layer" hero

    Answerdeck

    Building

    In aktiver Entwicklung

    Security-Fragebögen entscheiden über Enterprise-Deals, und sie von Hand zu beantworten frisst eine Woche. Answerdeck zieht Antworten aus den eigenen Belegen eines Teams und zitiert bei jeder Antwort das zugrunde liegende Dokument. Unterhalb einer Konfidenzschwelle verweigert es die Antwort und eskaliert an einen Menschen, statt etwas Plausibles zu erfinden — und jede Generierung hinterlässt einen Entscheidungsdatensatz mit zehn Feldern, damit ein Auditor nachvollziehen kann, warum eine Antwort so gegeben wurde. Der Audit-Trail ist append-only, durchgesetzt per Datenbank-Trigger statt durch Konvention. 83 pgTAP-Tests für Row-Level Security und Rollen, die in der CI blockieren. EU by Design.

    • answerdeck.app
  • Briksync PropOS landing page with "The operating system for modern property teams" hero and a dashboard preview

    Briksync PropOS

    Side project

    Gebaut mit Claude-Automatisierungsagenten

    Ein produktives Multi-Tenant-SaaS, bei dem das Berechtigungsmodell das Produkt ist. Vermieter, Property Manager, Makler und Mieter melden sich jeweils an und sehen nur ihren eigenen Bereich, durchgesetzt in der Datenbank statt nur in der Oberfläche versteckt — sechs Rollen über vier Nutzerarten. Ich habe dieses Modell entworfen, darin ein Cross-Tenant-Leck gefunden und den Fix mit echten Tokens gemessen: 137 fremde Zeilen sichtbar, auf 0 gebracht, abgesichert durch eine RLS-Matrix-Testsuite. Rund 4.400 ausgeführte Testfälle über 219 Dateien, 105 Migrationen sowie eigene Prüfungen für Search-Path-Hardening, Plan-Limit-Drift und Identitäts-Lecks.

    • briksync.com
  • aifoxx landing page, a curated directory of 992 AI tools with pricing and data-privacy facts

    aifoxx

    Active

    Ist dieses Tool SOC 2? Trainieren sie mit unseren Daten? Wo liegen die Daten? Diese drei Fragen killen jede KI-Shortlist. aifoxx erfasst sie einmal, vergleichbar, mit einem Link zur Vendor-Seite, die jede Angabe belegt: 992 KI-Tools, 1.979 MCP-Server, 1.638 Claude-Code-Skills und 980 Vendor-Trust-Reports. Jedes „true"-Flag trägt eine Quell-URL auf der eigenen Domain des Anbieters, und null bedeutet unverifiziert — nie false, im Schema erzwungen. Unsere eigenen Produkte erscheinen mit denselben Feldern und ohne Ranking-Vorteil. Open Source, MIT.

    • aifoxx.com
  • Co-Founder OS landing page with "An autonomous operating system for the life you actually live" hero

    Co-Founder OS

    Experiment

    Ein autonomes Betriebssystem, das von KI-Personas mit Gedächtnis betrieben wird. Es entwirft, plant, recherchiert und stellt Aktionen zur Freigabe bereit. Derzeit nutze ich es selbst; Zusammenarbeit ist willkommen.

    • cofounder-ai-os.lovable.app

Open Source

3,618 contributions in the last yearAugust 2025 – August 2026
SepOctNovDecJanFebMarAprMayJunJulAug0 contributions on 2025-08-310 contributions on 2025-09-010 contributions on 2025-09-020 contributions on 2025-09-030 contributions on 2025-09-040 contributions on 2025-09-050 contributions on 2025-09-060 contributions on 2025-09-071 contribution on 2025-09-080 contributions on 2025-09-090 contributions on 2025-09-100 contributions on 2025-09-110 contributions on 2025-09-120 contributions on 2025-09-130 contributions on 2025-09-140 contributions on 2025-09-150 contributions on 2025-09-160 contributions on 2025-09-170 contributions on 2025-09-180 contributions on 2025-09-190 contributions on 2025-09-200 contributions on 2025-09-210 contributions on 2025-09-220 contributions on 2025-09-230 contributions on 2025-09-240 contributions on 2025-09-250 contributions on 2025-09-260 contributions on 2025-09-270 contributions on 2025-09-282 contributions on 2025-09-290 contributions on 2025-09-300 contributions on 2025-10-016 contributions on 2025-10-023 contributions on 2025-10-0321 contributions on 2025-10-043 contributions on 2025-10-051 contribution on 2025-10-062 contributions on 2025-10-073 contributions on 2025-10-080 contributions on 2025-10-090 contributions on 2025-10-100 contributions on 2025-10-110 contributions on 2025-10-120 contributions on 2025-10-130 contributions on 2025-10-140 contributions on 2025-10-150 contributions on 2025-10-163 contributions on 2025-10-171 contribution on 2025-10-180 contributions on 2025-10-190 contributions on 2025-10-200 contributions on 2025-10-210 contributions on 2025-10-220 contributions on 2025-10-230 contributions on 2025-10-240 contributions on 2025-10-250 contributions on 2025-10-260 contributions on 2025-10-270 contributions on 2025-10-280 contributions on 2025-10-290 contributions on 2025-10-300 contributions on 2025-10-310 contributions on 2025-11-010 contributions on 2025-11-020 contributions on 2025-11-030 contributions on 2025-11-040 contributions on 2025-11-050 contributions on 2025-11-060 contributions on 2025-11-070 contributions on 2025-11-080 contributions on 2025-11-090 contributions on 2025-11-100 contributions on 2025-11-110 contributions on 2025-11-120 contributions on 2025-11-130 contributions on 2025-11-140 contributions on 2025-11-150 contributions on 2025-11-160 contributions on 2025-11-170 contributions on 2025-11-180 contributions on 2025-11-190 contributions on 2025-11-200 contributions on 2025-11-210 contributions on 2025-11-220 contributions on 2025-11-230 contributions on 2025-11-240 contributions on 2025-11-250 contributions on 2025-11-260 contributions on 2025-11-270 contributions on 2025-11-280 contributions on 2025-11-290 contributions on 2025-11-300 contributions on 2025-12-010 contributions on 2025-12-020 contributions on 2025-12-030 contributions on 2025-12-040 contributions on 2025-12-050 contributions on 2025-12-060 contributions on 2025-12-070 contributions on 2025-12-080 contributions on 2025-12-090 contributions on 2025-12-100 contributions on 2025-12-110 contributions on 2025-12-120 contributions on 2025-12-130 contributions on 2025-12-140 contributions on 2025-12-150 contributions on 2025-12-160 contributions on 2025-12-170 contributions on 2025-12-180 contributions on 2025-12-190 contributions on 2025-12-200 contributions on 2025-12-210 contributions on 2025-12-220 contributions on 2025-12-230 contributions on 2025-12-240 contributions on 2025-12-250 contributions on 2025-12-260 contributions on 2025-12-270 contributions on 2025-12-280 contributions on 2025-12-290 contributions on 2025-12-306 contributions on 2025-12-310 contributions on 2026-01-0111 contributions on 2026-01-020 contributions on 2026-01-031 contribution on 2026-01-043 contributions on 2026-01-054 contributions on 2026-01-060 contributions on 2026-01-070 contributions on 2026-01-082 contributions on 2026-01-090 contributions on 2026-01-101 contribution on 2026-01-111 contribution on 2026-01-121 contribution on 2026-01-131 contribution on 2026-01-140 contributions on 2026-01-151 contribution on 2026-01-164 contributions on 2026-01-170 contributions on 2026-01-181 contribution on 2026-01-190 contributions on 2026-01-200 contributions on 2026-01-210 contributions on 2026-01-223 contributions on 2026-01-230 contributions on 2026-01-240 contributions on 2026-01-250 contributions on 2026-01-262 contributions on 2026-01-275 contributions on 2026-01-281 contribution on 2026-01-295 contributions on 2026-01-300 contributions on 2026-01-310 contributions on 2026-02-010 contributions on 2026-02-020 contributions on 2026-02-031 contribution on 2026-02-040 contributions on 2026-02-050 contributions on 2026-02-060 contributions on 2026-02-070 contributions on 2026-02-080 contributions on 2026-02-090 contributions on 2026-02-100 contributions on 2026-02-110 contributions on 2026-02-122 contributions on 2026-02-130 contributions on 2026-02-140 contributions on 2026-02-150 contributions on 2026-02-160 contributions on 2026-02-173 contributions on 2026-02-182 contributions on 2026-02-196 contributions on 2026-02-200 contributions on 2026-02-210 contributions on 2026-02-222 contributions on 2026-02-239 contributions on 2026-02-240 contributions on 2026-02-250 contributions on 2026-02-264 contributions on 2026-02-271 contribution on 2026-02-280 contributions on 2026-03-012 contributions on 2026-03-020 contributions on 2026-03-035 contributions on 2026-03-043 contributions on 2026-03-050 contributions on 2026-03-061 contribution on 2026-03-07243 contributions on 2026-03-089 contributions on 2026-03-0914 contributions on 2026-03-104 contributions on 2026-03-110 contributions on 2026-03-1256 contributions on 2026-03-1319 contributions on 2026-03-142 contributions on 2026-03-1517 contributions on 2026-03-1616 contributions on 2026-03-170 contributions on 2026-03-188 contributions on 2026-03-1911 contributions on 2026-03-203 contributions on 2026-03-210 contributions on 2026-03-221 contribution on 2026-03-230 contributions on 2026-03-2484 contributions on 2026-03-250 contributions on 2026-03-260 contributions on 2026-03-2721 contributions on 2026-03-2812 contributions on 2026-03-290 contributions on 2026-03-3028 contributions on 2026-03-317 contributions on 2026-04-014 contributions on 2026-04-0224 contributions on 2026-04-030 contributions on 2026-04-040 contributions on 2026-04-0518 contributions on 2026-04-0674 contributions on 2026-04-0710 contributions on 2026-04-083 contributions on 2026-04-090 contributions on 2026-04-1021 contributions on 2026-04-1114 contributions on 2026-04-120 contributions on 2026-04-1312 contributions on 2026-04-141 contribution on 2026-04-1519 contributions on 2026-04-161 contribution on 2026-04-1710 contributions on 2026-04-180 contributions on 2026-04-1948 contributions on 2026-04-200 contributions on 2026-04-210 contributions on 2026-04-228 contributions on 2026-04-2337 contributions on 2026-04-2474 contributions on 2026-04-25122 contributions on 2026-04-260 contributions on 2026-04-270 contributions on 2026-04-280 contributions on 2026-04-290 contributions on 2026-04-304 contributions on 2026-05-010 contributions on 2026-05-020 contributions on 2026-05-030 contributions on 2026-05-040 contributions on 2026-05-050 contributions on 2026-05-060 contributions on 2026-05-070 contributions on 2026-05-080 contributions on 2026-05-094 contributions on 2026-05-100 contributions on 2026-05-110 contributions on 2026-05-120 contributions on 2026-05-1322 contributions on 2026-05-1440 contributions on 2026-05-150 contributions on 2026-05-160 contributions on 2026-05-1745 contributions on 2026-05-1872 contributions on 2026-05-19198 contributions on 2026-05-2016 contributions on 2026-05-2134 contributions on 2026-05-2296 contributions on 2026-05-2334 contributions on 2026-05-2413 contributions on 2026-05-2526 contributions on 2026-05-2612 contributions on 2026-05-2712 contributions on 2026-05-2847 contributions on 2026-05-294 contributions on 2026-05-3033 contributions on 2026-05-31103 contributions on 2026-06-0135 contributions on 2026-06-022 contributions on 2026-06-032 contributions on 2026-06-0418 contributions on 2026-06-0519 contributions on 2026-06-0611 contributions on 2026-06-0714 contributions on 2026-06-0895 contributions on 2026-06-0918 contributions on 2026-06-1028 contributions on 2026-06-1114 contributions on 2026-06-122 contributions on 2026-06-132 contributions on 2026-06-1431 contributions on 2026-06-152 contributions on 2026-06-1618 contributions on 2026-06-1710 contributions on 2026-06-186 contributions on 2026-06-192 contributions on 2026-06-202 contributions on 2026-06-2114 contributions on 2026-06-222 contributions on 2026-06-232 contributions on 2026-06-243 contributions on 2026-06-258 contributions on 2026-06-2612 contributions on 2026-06-272 contributions on 2026-06-2852 contributions on 2026-06-298 contributions on 2026-06-302 contributions on 2026-07-012 contributions on 2026-07-022 contributions on 2026-07-034 contributions on 2026-07-042 contributions on 2026-07-0510 contributions on 2026-07-0690 contributions on 2026-07-072 contributions on 2026-07-0812 contributions on 2026-07-09140 contributions on 2026-07-1078 contributions on 2026-07-1161 contributions on 2026-07-1245 contributions on 2026-07-133 contributions on 2026-07-142 contributions on 2026-07-158 contributions on 2026-07-16126 contributions on 2026-07-1726 contributions on 2026-07-1858 contributions on 2026-07-1913 contributions on 2026-07-2010 contributions on 2026-07-212 contributions on 2026-07-222 contributions on 2026-07-232 contributions on 2026-07-242 contributions on 2026-07-2515 contributions on 2026-07-262 contributions on 2026-07-272 contributions on 2026-07-282 contributions on 2026-07-292 contributions on 2026-07-302 contributions on 2026-07-312 contributions on 2026-08-012 contributions on 2026-08-022 contributions on 2026-08-032 contributions on 2026-08-042 contributions on 2026-08-052 contributions on 2026-08-062 contributions on 2026-08-0785 contributions on 2026-08-0811 contributions on 2026-08-092 contributions on 2026-08-102 contributions on 2026-08-112 contributions on 2026-08-122 contributions on 2026-08-132 contributions on 2026-08-1449 contributions on 2026-08-1539 contributions on 2026-08-1617 contributions on 2026-08-172 contributions on 2026-08-182 contributions on 2026-08-192 contributions on 2026-08-202 contributions on 2026-08-212 contributions on 2026-08-222 contributions on 2026-08-236 contributions on 2026-08-242 contributions on 2026-08-252 contributions on 2026-08-264 contributions on 2026-08-27109 contributions on 2026-08-2873 contributions on 2026-08-2912 contributions on 2026-08-300 contributions on 2026-08-31
LessMoresnapshot · 2026-08-31

Wie das entsteht

Ich schreibe Code nicht von Hand, sondern dispatche Agents — und ich kann genau sagen, wie viel, weil ich das Werkzeug gebaut habe, das es misst. ClaudeSec instrumentiert jeden Tool-Aufruf meiner Agents. Über meine eigenen Projekte hinweg hat es 385.647 Spans in 146 Repositories und drei Agent-Harnesses aufgezeichnet und 4.843 Alerts zu meinen eigenen Agents ausgelöst, davon 22 kritische. Meine Session-Transkripte liefern die andere Hälfte: 836 dispatchte Subagents in 1.358 Sessions, bei etwa sieben Agent- oder CLI-Aktionen pro Handbearbeitung.

Die Agents, die meinen Code schreiben, werden von dem Werkzeug überwacht, das ich zum Überwachen von Agents gebaut habe.

Blog

Lernen

Wenn ich offline bin

Den Himmel beobachten.

Fotos folgen in Kürze.

Rückmeldungen

  • Karan is a creator and an innovator. His ability to think differently and take risks puts him way ahead of his generation. Gifted with leadership, exuberance and positivity, he's on his way to do big things.

    Aanjaneya Singh Dhoni · Cybersecurity Consultant @ PwC

  • Karan is very hardworking and dedicated, always ready to work in any situation. An excellent manager: he runs Errsol Technologies, managing project flow and assigning tasks. A focused and visionary person.

    Harish Dhakad · DevOps & SRE Engineer

  • Karan is an excellent web developer with amazing products and solution delivery. We have worked together on many of his freelancing projects and it turns out to be great.

    Aman Khandelwal · Senior DevOps Engineer & Cloud Economics Enthusiast

  • Karan is wonderful to work with and has exceptional expertise in leadership. He consistently demonstrates a solid work ethic. Dedicated, self-motivated and very capable, with a very positive attitude.

    Aayushi Solanki · Software Engineer | AWS Certified

Fragen

Wer ist Karan Rajeshbhai Mungara?
Karan Rajeshbhai Mungara (online als withkarann) ist Information Security Analyst bei Staffbase und der Entwickler von VODP, Answerdeck, Briksync PropOS und ClaudeSec. Er arbeitet an Application Security, KI-gestützten Penetrationstests und Security-Automatisierung. Er lebt in Chemnitz, Deutschland.
Was ist VODP?
VODP (vodp.dev) ist eine Plattform zur Orchestrierung und Deduplizierung von Schwachstellen, entstanden aus Karan Rajeshbhai Mungaras Masterarbeit. Sie führt Befunde mehrerer Scanner zusammen, normalisiert und dedupliziert sie, plant proaktive Scans und testet einen gemeldeten Fix automatisch nach, sofern ein Scanner-Template die Schwachstellenklasse abdeckt — in etwa zwei Sekunden. Im DVWA-Benchmark wurden aus 531 Rohbefunden 37 echte, bei 99,2 % Precision und 99,4 % Recall.
Was ist Answerdeck?
Answerdeck (answerdeck.app) ist eine Compliance Intelligence Layer für SaaS-Security-Teams, entwickelt von Karan Rajeshbhai Mungara. Sie macht aus dem Security- und Compliance-Wissen eines Teams belegte, prüffertige Antworten — statt ein einmaliges Fragebogen-Tool zu sein.
Was macht Karan bei Staffbase?
Bei Staffbase verantwortet Karan das Vulnerability Management von Anfang bis Ende, über Web, Mobile und Infrastruktur hinweg. Er verifiziert und testet Pentest-Befunde nach, triagiert externe Bug-Bounty-Meldungen und arbeitet mit dem Engineering an der Behebung. Außerdem baut er Security-Automatisierung mit KI. Sein KI-Assistent für Vendor-Reviews verkürzte Assessments von rund vier Stunden auf etwa zwanzig Minuten und machte den Kauf eines externen Tools überflüssig.
Was ist Briksync PropOS?
Briksync PropOS (briksync.com) ist eine Plattform für Immobilien-Operations, entwickelt von Karan Rajeshbhai Mungara. Es ist ein eigenständiges Nebenprojekt, das Abläufe, Objekte und Workflows in einem System zusammenführt.
Was ist Errsol Technologies?
Errsol Technologies LLP (errsol.com) ist eine DPIIT-anerkannte Software-Agentur, die Karan Rajeshbhai Mungara 2019 mit 21 Jahren gegründet hat. Sie hat Webanwendungen und KI-gestützte Produkte geliefert; die Kundenprojekte im Bereich Webanwendungen umfassen über 50.000–100.000 $ Projektvolumen.
Wo lebt Karan und wie kann man ihn erreichen?
Karan lebt in Chemnitz, Deutschland. Sie erreichen ihn unter withkarann@gmail.com für Persönliches, karan@answerdeck.app für Answerdeck oder hello@errsol.com für Errsol Technologies. Auf LinkedIn, GitHub und X ist er ebenfalls als @withkarann zu finden.
Was ist eine Compliance Intelligence Layer?
Eine Compliance Intelligence Layer liegt unter den Security-Fragebögen, Audits und Vendor-Reviews, die ein Team ohnehin beantworten muss. Statt jede Antwort neu zu recherchieren, hält sie das vorhandene Wissen an einem Ort und verweist bei jeder Antwort auf die Quelle, aus der sie stammt. Der Unterschied zu einem Fragebogen-Tool: Sie beantworten einmal und belegen es, statt jedes Mal von vorne anzufangen.
Mit welchen Tools und Technologien arbeitet Karan?
Am häufigsten: Burp Suite Pro, OWASP ZAP, Nuclei und Dalfox für Security-Tests; Claude Code, MCP-Connectors und Subagents für Agentic Engineering; React, TypeScript, Node.js und PostgreSQL beziehungsweise Supabase für den Bau von Produkten; sowie Docker und Vercel für den Betrieb.
Ist Karan offen für Zusammenarbeit, Beratung oder Vorträge?
Ja. Karan spricht gern mit Security-Verantwortlichen darüber, wo KI sich in der Sicherheitsarbeit wirklich auszahlt und wo nicht. Am schnellsten geht das über withkarann@gmail.com oder LinkedIn.