Hi, my name is
Senior Staff Security Engineer
Leading security for LLM- and agent-based systems at FloQast.
Nikhil is a Senior Staff Security Engineer at FloQast, where he leads security for the company's AI products covering threat modelling, secure design, and safely shipping LLM- and agent-based systems in a regulated environment.
He has spent nearly a decade across application security, cloud-native security, and DevSecOps. Before FloQast, he held founding and principal security roles at Clazar and Chargebee, building security programs from scratch for fast-growing SaaS companies. Earlier, his browser security research earned acknowledgments from Google, Microsoft, Apple, and Mozilla.
His work has helped companies cut high-risk vulnerabilities by 70–80%, eliminate major OWASP Top 10 classes, pass SOC 2/ISO 27001 audits with zero major findings, and catch misconfigurations before they hit customers.
Nikhil regularly speaks at conferences like BlackHat, 36C3, PhDays, and POC, and brings both an offensive mindset and an engineering lens to product, cloud, and AI security problems.
Focus Areas
Edge extensions security policy bypass listed in top-10 Application Security Vulnerabilities of 2019.
Safari Reader Mode research nominated for Top 10 Web Hacking Techniques of 2020.
Edge extensions security policy bypass nominated for Top 10 Web Hacking Techniques of 2019.
Microsoft Edge Chrome extensions security research covered by DigitalTrends.
Session security vulnerability research featured in Netsparker's technical blog.
Security research discussion featured in SANS ISC podcast episode.