Hi, my name is

Nikhil Mittal

Senior Staff Security Engineer

Leading security for LLM- and agent-based systems at FloQast.

Nikhil Mittal speaking at PhDays security conference
19 CVEs
6 Conference Talks
70–80% Vuln Reduction
SOC 2 & ISO 27001

01. About

Nikhil is a Senior Staff Security Engineer at FloQast, where he leads security for the company's AI products covering threat modelling, secure design, and safely shipping LLM- and agent-based systems in a regulated environment.

He has spent nearly a decade across application security, cloud-native security, and DevSecOps. Before FloQast, he held founding and principal security roles at Clazar and Chargebee, building security programs from scratch for fast-growing SaaS companies. Earlier, his browser security research earned acknowledgments from Google, Microsoft, Apple, and Mozilla.

His work has helped companies cut high-risk vulnerabilities by 70–80%, eliminate major OWASP Top 10 classes, pass SOC 2/ISO 27001 audits with zero major findings, and catch misconfigurations before they hit customers.

Nikhil regularly speaks at conferences like BlackHat, 36C3, PhDays, and POC, and brings both an offensive mindset and an engineering lens to product, cloud, and AI security problems.

Focus Areas

AI Security LLM Security Agentic Security Application Security Cloud Security DevSecOps Threat Modelling Product Security Browser Security

02. Talks & Publications

Monitoring and Detecting Leaks with GitAlerts

Conference Talk

Continuous Application Security - The DevSecOps Way

Conference Talk

My Hacking Adventures With Safari Reader Mode

POC 2020

Breaking Microsoft Edge Extensions Security Policies

36C3

Bug Bounty Meetup - Scan Me and Get Pwned

36C3

Breaking Microsoft Edge Extensions Security Policies

PhDays 9

03. Blog

Browser Security

DevSecOps & Engineering

Vulnerability Research & Bug Bounty

04. CVEs

Apple 5

Microsoft 1

Mozilla 1

Opera 1

Open Source 11

05. Achievements

WhiteHat Security Top 10

Edge extensions security policy bypass listed in top-10 Application Security Vulnerabilities of 2019.

PortSwigger Top 10 (2020)

Safari Reader Mode research nominated for Top 10 Web Hacking Techniques of 2020.

PortSwigger Top 10 (2019)

Edge extensions security policy bypass nominated for Top 10 Web Hacking Techniques of 2019.

Featured in DigitalTrends

Microsoft Edge Chrome extensions security research covered by DigitalTrends.

Featured in Netsparker Blog

Session security vulnerability research featured in Netsparker's technical blog.

Featured in SANS Podcast

Security research discussion featured in SANS ISC podcast episode.