Software × Security × Automation

Make your
systems
work for
you.

I build clean software, connect the tools your team relies on,
and find the security holes before someone else does.

Services

Straightforward help.
Real results.

Whether you need a security review, an automation to save you hours every week, or custom software built for your team, here is how we can work together.

Services

Security, automation, and custom software.

01

Security & Defense

Inspect your web apps, servers, and code to catch security holes before someone else does—with a clear fix list.

  • Code and server configuration review
  • Clear, prioritized fix list
  • Authorized testing with agreed boundaries

02

Automating the Busywork

Connect your daily apps and automate repetitive chores so your team stops wasting hours on manual data entry.

  • Direct app integrations (Slack, email, CRMs, spreadsheets)
  • Custom AI tools where you stay in control
  • Reliable automated workflows that don't break

03

Custom Software

Build custom web applications, customer portals, or internal tools shaped specifically around the way your team works.

  • Modern web apps and fast backend APIs
  • Clean TypeScript and Python code
  • Full handoff, documentation, and ongoing support

Not sure where to start?

Tell me what's slowing you down.

You don't need a technical spec sheet. Just tell me what's taking up too much time or what security worry is on your mind, and we'll figure out the right fix.

Let's talk

Security research

Real vulnerabilities.
Public records.

I report security issues in open-source systems responsibly and help get them fixed. Here are the public CVEs and reporter credits.

Published research

2 published advisory credits, including 1 associated CVE.

A GHSA and its associated CVE count as one finding. My credit here is for reporting the issue, not writing or independently verifying the fix. This work does not imply an affiliation with the project.

Public sources reviewed .

01

OpenClaw

Browser CDP discovery network-policy bypass

GHSA-3x84-qq85-fj65 CVE-2026-62197

Role
Reporter, Jason O'Neal
Advisory published
CVE record
First patched
2026.6.6

Impact. Browser discovery could reach destinations prohibited by OpenClaw's network policy. Impact depended on configuration and whether lower-trust input could reach the affected feature.

Boundary

Network restrictions should apply to the destination selected during browser discovery.

Documented failure

The public advisory documents acceptance of WebSocket destinations that policy should have blocked.

Contribution

GitHub and the official CVE record credit Jason O'Neal as the reporter. These records do not establish fix authorship.

Remediation

The advisory identifies 2026.6.6 as the first stable patched version. The CVE and GHSA describe the same finding.

02

OpenClaw iOS

Unattended credentials exposed in iOS diagnostic logs

GHSA-5j57-84cx-r295

Role
Reporter, Jason O'Neal
Advisory published
First patched
2026.8.11

Impact. Sensitive unattended-agent link data could enter diagnostic logs, exposing credentials to someone with access to those logs.

Boundary

Diagnostic output should not expose credentials used for unattended agent requests.

Documented failure

The public advisory documents logging of complete deep links, including a persistent credential and private request data.

Contribution

GitHub credits Jason O'Neal as the reporter. Reporter credit is distinct from developing or independently verifying the repair.

Remediation

The advisory identifies 2026.8.11 as the first stable patched version and advises rotating exposed keys and removing affected diagnostic archives. No CVE is listed in that advisory as of this review.

What's included

Published reports only.

Everything here is based on published advisories and CVE records. Private discussions and unpublished reports stay private.

Ask about a security review

About

Hi, I'm Jason.
The person behind BlueDot.

I founded BlueDot IT to help teams build reliable software, automate repetitive busywork, and stay secure. I'm also an active contributor to OpenClaw, and when I'm not writing code, I study cybersecurity at DeVry University.

The developer

Jason O'Neal

I work directly with clients on web applications, Linux servers, and the automations that connect their daily tools.

I'm also an active contributor to OpenClaw, where I report security bugs responsibly so fixes get shipped before vulnerabilities can be exploited. You can see all my public CVEs and credits in the research section.

Read the public research

How I work

Straight talk. No surprises.

I believe you should always understand what's being built and why. Before any work begins, we agree on the exact scope, timeline, and cost. At the end, you get clear documentation and an honest walkthrough so you're never left in the dark.

Ready to chat?

What's on your mind?

Tell me about your project or what's slowing your team down. Plain English works best—no buzzwords needed.

Tell me about it

Contact

Tell me what's
on your mind.

Have a project idea, an annoying chore you want automated, or a security question? Drop me a line. No sales pitch, no technical jargon required.

Get in touch

A few details are enough to start.

I'll read your message and get back to you. If I need more detail, I'll ask.

Please leave out passwords, access tokens, customer records, and other sensitive data. Don't include details of an unpatched security issue here.

Preparing the scene...

Start a conversation

A starting point

What are you
working toward?

Prepare a project brief on your device. Nothing is sent. When you are ready, use the contact form to send an inquiry.

Leave out passwords, tokens, customer records, and other sensitive information.