Security engineering

We Find What Scanners Miss.
We Prepare What Auditors Ask For.

Manual penetration testing across applications, APIs, networks, cloud, mobile, AI and smart contracts, plus phishing simulation and dark web monitoring, with a working proof of exploit behind every finding. And the readiness work behind PCI DSS, ISO 27001, SOC 2 and the frameworks your customers ask about.

Offensive SecurityCloud SecurityAI SecuritySmart ContractsReadiness
engagement.log
001// nothing runs before this is signed
002scope.confirm(authorization_letter)
003map.surface({ roles: 4, tenants: 2, endpoints: 318 })
004 41 endpoints not in the documentation
005
006// cross every boundary deliberately
007for (const b of surface.boundaries) {
008 attempt(b.horizontal); attempt(b.vertical); attempt(b.tenant)
009}
010
011finding.require(proof_of_exploit)
012 no CVSS-only findings are reported
013report.deliver({ walkthrough: true })
014retest.schedule({ within_days: 90, included: true })
The problem

Scanners find known vulnerabilities. Products break on logic.

What tooling finds

Outdated dependencies, missing headers, known CVEs and misconfigurations that match a signature. Useful, cheap and largely automatable. You should already be doing this, and you do not need us for it.

What actually breaks products

One user reaching another user's data. A role performing an action it should not. A workflow completed out of order. A limit that is not atomic under parallel requests. None of it matches a signature, because it is specific to how your product was built.

So we test the product the way an attacker with a valid account would: every role, every boundary, every assumption your code makes about who is asking. Then we prove each one with a working exploit rather than a severity rating.

Bug bounty hall of fame

Web application, API and infrastructure bug bounty programmes that have acknowledged our findings.

OpenAI
PayPal
Binance
Cisco
Dell
Groww
Comcast
Xfinity
Chime
FusionAuth
Gen Digital Inc
Aurory
Jetstar
Bolt
Monash University
GoPro
ImmoScout24
Greenfly
CoinDepo
GMGN.AI
LeveX
RTree Finance
Layer3
WhiteMarket
MATLAB
Office of Natural Resources

Smart contract, DeFi and protocol bug bounty programmes and contests.

Folks Finance
Base Azul
0xMarkets
OpenSea

Certifications held

  • Smart Contract SecuritySmart Contract Security course and proficiency exam · Cyfrin Updraft
  • Smart Contract AuditorCertified Smart Contract Auditor · Blockchain Council
  • OSCPOffensive Security Certified Professional · OffSec
  • eWPTXWeb Application Penetration Tester eXtreme · INE Security
  • eWPTWeb Application Penetration Tester · INE Security
  • eJPTJunior Penetration Tester · INE Security
  • CEHCertified Ethical Hacker · EC-Council
  • ISO/IEC 27001ISO/IEC 27001 Information Security Management · ISO/IEC
  • Foundry FundamentalsFoundry Fundamentals course and proficiency exam · Cyfrin Updraft
  • MITRE ATT&CKMITRE ATT&CK Framework · Udemy
The engagement

A defined process, and exactly what you receive.

Three phases, six steps. What happens at each stage is fixed before the engagement starts, so there are no surprises in scope, price or timing.

Phase 01

Scope

Agree what will be tested, in writing, before anything runs.

  1. 01

    Scoping call

    We go through the application, the roles, the API surface and what is driving the timing. No sales pitch, no discovery questionnaire.

  2. 02

    Fixed proposal

    A written scope with a fixed price, explicit exclusions, dates and deliverables. The price does not change unless you change the scope.

  3. 03

    Authorization

    A signed authorization letter and rules of engagement: what is in scope, what is off limits, the testing window, and who to call if something breaks.

Phase 02

Test

Manual assessment against the agreed surface.

  1. 04

    Testing

    Manual testing against your environment. You get progress updates, and anything critical is reported the day it is found rather than held for the report.

Phase 03

Report & retest

Evidence, remediation, and verification that it is closed.

  1. 05

    Report

    Executive summary for the people who sign things, technical findings with reproduction steps and a working proof of exploit for the people who fix them.

  2. 06

    Retest included

    When you have fixed things, we verify each one and issue an updated report plus a letter of attestation you can hand to customers and auditors.

What you receive

The report is the product. Every engagement ends with the same set of deliverables.

Executive summary
One page your board, your auditor or your enterprise customer can read without a security background.
Technical findings
Each one with the affected component, the reproduction steps, and the request and response that prove it.
Working proof of exploit
Not a CVSS score attached to a scanner signature. A demonstration that the issue is real and reachable.
Developer-ready fix
What to change, where, and why that change closes the issue rather than moving it.
Report walkthrough call
A live session with your engineers while they have the code open. Almost nobody in this industry does this.
Retest and attestation
A second report confirming what is fixed, and a letter you can share with customers and auditors.
Questions

Answers to what people ask on the first call.

How do you scope an engagement?

One 30 minute call. We need to know what the application does, how many user roles it has, whether there is an API, and what is driving the timing. You get a fixed price after that call, not an hourly estimate that moves.

What do I need to give you before testing starts?

Test accounts for every role, a staging or production environment, any API documentation you have, and a signed authorization letter. Nothing else. If documentation does not exist, that is normal and it does not change the price.

Do you test production?

Yes, if you want that, and it is often the more honest test. Testing is non-destructive by default and we agree the boundaries with you in writing first. If you prefer staging, the only cost is that some findings will be environment-specific.

What happens to the data you find?

Findings and evidence stay on encrypted storage that we control, separated per client, and are destroyed on the schedule set in the contract. Nothing is stored with a third-party reporting vendor. No client data goes on a personal laptop.

Is the retest included?

Yes, one full retest of every finding is included within 90 days of the report. You get an updated report showing what is fixed, and a letter of attestation you can share with your own customers and auditors.

What if you find nothing?

You receive the full record of what was tested, how it was tested and what was ruled out. That record is what an auditor or an enterprise customer actually wants to see, and a clean result against a documented scope is worth having in writing. We do not pad a report with low-value findings to justify the engagement.

All questions

Prove what your product exposes

A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.

Contact
contact.log

No form, no sales desk. The person who answers is the person who would run your engagement.

Profiles
XLinkedIn
Book a scoping call

30 minutes, fixed price after. No questionnaire.