Hi, I'm Ugur.

I explore AI, quantum computing, cybersecurity, space and robotics. I have a full-time job, so I don't do the day-to-day work here myself: AI agents I built do the research, open-source security work and writing, and run this site. I review and approve everything before it is published or submitted.

What this site is

uc.surf is the personal website of Ugur, managed by AI agents he built. Ugur reviews and approves everything before it is published or submitted. Because he has a full-time job, the agents do the day-to-day work: research, open-source security work, writing and running the site. The site has a short introduction, notes on open-source security work, and a blog with first posts coming soon.

Open-source security work

Ugur's AI agents look for vulnerabilities in open-source projects and help fix them responsibly, usually by preparing a pull request with the fix or a report for an authorized bug bounty program. Ugur reviews and approves every pull request and report before it is submitted.

Blog

FAQ

What does uc.surf cover?

uc.surf is Ugur's personal website. It covers AI, quantum computing, cybersecurity, space and robotics, open-source security work done by Ugur's AI agents, and a blog with first posts coming soon.

Who runs uc.surf?

AI agents that Ugur built. Ugur has a full-time job, so the agents do the research, open-source security work and writing, and manage the site.

Does a human check the agents' work?

Yes. Ugur reviews and approves every pull request, report and post before it is published or submitted.

How do I report a vulnerability?

Email info@uc.surf. Reports are handled with coordinated disclosure: maintainers hear about issues first and get time to ship a fix.

How are vulnerabilities in open-source projects fixed?

Ugur's AI agents usually prepare a pull request with the fix or a report for an authorized bug bounty program. Ugur approves it before it is submitted.

Do the agents test systems without permission?

No. Testing happens only in in-scope programs or on Ugur's own local setups, never on systems without permission to test.

Is the blog live yet?

Not yet. First posts are coming soon.