Leadership

Syed Shahzaib Shah

Founder and chief executive of SS Support Network LLC, and a cybersecurity researcher whose disclosure work has been covered by HackerNoon, Cybersecurity News, GBHackers and The Hack Post. He sets how this company handles other people's patient data, and he writes the compliance guides on this site.

Chief Executive Officer Cybersecurity researcher Coordinated vulnerability disclosure HIPAA Security Rule Healthcare BPO operations
2020Year he founded SS Support Network
3Companies he leads across the US and Pakistan
5Independent publications covering his security research

Background

Syed Shahzaib Shah, who also publishes as Shahzaib Shah, founded SS Support Network LLC in 2020 and runs it as chief executive. He was born on 1 August 2000 and is Pakistani. Before the company existed he was already working in security research, and that came first in a way that still shows in how the business is built.

His field is coordinated vulnerability disclosure. In plain terms: find a flaw in a system you are allowed to test, report it privately to the people who own it, and give them time to fix it before anyone else hears about it. He has done that work against large technology platforms and against government systems, and it has been written up by five independent outlets.

It is a discipline that rewards one specific habit. Read the specification. Test what the system actually does rather than what its documentation claims. Report what you found, not what would sound better. That is an awkward habit in a sales conversation and a useful one in a company that handles protected health information for a living.

What that means for how this company runs

Most back offices treat security as a page on the website. Here it is the thing the founder does with the rest of his time, so the claims on this site are written to be checked rather than believed.

Every regulatory statement in our knowledge base links to the text of the rule at Cornell LII, the eCFR, the Federal Register, NIST or the OCR breach portal. A compliance reviewer can verify any of it in the time it takes to click. Where a rule is proposed rather than in force, the page says so, with the docket number and the projected date, because the difference matters and most vendor content blurs it.

The same standard applies to claims about us. SS Support Network holds no SOC 2 report and no HIPAA certification, and no HIPAA certification exists for anyone to hold; HHS has said so since 2003. Our trust center states both plainly, alongside the controls we do run and how you can verify them. If that changes we will publish the scope and the date. Not before.

Companies

What he leads

One operation, three registered companies. Knowing which entity does what is the difference between a contract that holds and one that doesn't.

SS Support Network LLC

The US company, registered in Vancouver, Washington. It holds the client contracts and signs the business associate agreement, so this is the entity a covered entity is contracting with and the one carrying direct liability under HIPAA. Founded 2020 by Shahzaib as CEO and Nimra Khalid as co-founder and COO.

SS Support Network Pvt Ltd

The Pakistan-registered back office, and where most of the delivery team sits. Registering the offshore side as a real company rather than running it as loose contractors is what makes the workforce clauses in a BAA enforceable: employment contracts, confidentiality terms and disciplinary process all attach to an entity that exists.

Transport BPO

A separate transportation-focused operation at transportbpo.com, serving NEMT providers and trucking dispatch. Shahzaib is CEO and Nimra Khalid is co-founder and COO there as well, which is why dispatch practice moves between the two companies quickly.

Independent coverage

Where his security work has been written about

Five pieces, none of them ours. We link them so you can read what other people said rather than what we would say about ourselves.

Cybersecurity News

On the disclosure work and the assets it covered.

Read the article

HackerNoon

Digital Defenders: a profile of how he works.

Read the article

HackerNoon

A longer interview on method and defensive thinking.

Read the article

GBHackers

On ethical hacking as a defensive discipline.

Read the article

The Hack Post

On the threat research that drew international coverage.

Read the article

What a client actually gets from it

A founder with a security background is only worth something if it reaches the floor. These are the places it does.

  • Access is scoped per account. An agent sees the client they are assigned to and nothing else, including no contact details for any other client.
  • Nobody on the delivery floor can delete a record. Corrections are made by adding to the history, so the trail of what happened stays intact.
  • Downloads are logged with the person, the file and the time, because "who took a copy of this" is the first question after any incident and the worst time to find out you can't answer it.
  • Patient identifiers are encrypted in the database, not just behind a login, so a stolen backup isn't the same thing as a stolen record.
  • Two-step verification is on by default for every account rather than offered as an option people decline.
  • Our claims carry citations. Where we can't prove something, the page says we can't, which is the part most vendors leave out.

None of this is unusual for a company that takes security seriously. It is unusual for a back office priced like ours, and that is the actual point.

Talk to us about your operation

Tell us what you run and what is breaking. You will get a straight answer about whether we are a fit, including when we aren't.

Contact SS Support Network