Find the
tracks first.
A boutique offensive-security firm for growth-stage companies. We run penetration tests and vulnerability scans, test your people with controlled phishing and social-engineering, and provide security consulting between engagements. We report the way a senior engineer briefs a peer they respect: plainly, with the evidence attached, and without inflating the risk to inflate the invoice.
What we
do well.
Eight services, each led by a senior practitioner who has seen the failure mode in production before. Whether it's a one-off test or ongoing coverage, the person who runs the work writes the report, and we scope it honestly.
Penetration Testing
Web, mobile, API, and cloud-native infra. Gray-box by default; black-box on request. Findings shipped live to your tracker, not saved up for the end.
Continuous Penetration Testing
Human-led testing on a subscription, with retests after every release and a live view of findings, instead of a single report once a year.
AI & LLM Security Testing
Security testing for LLM-powered apps, chatbots, RAG pipelines, and agents: prompt injection, data leakage, and insecure tool use, mapped to the OWASP LLM Top 10.
External Attack-Surface Report
A one-off, non-intrusive map of everything your company exposes to the internet: the assets, services, and leaks an attacker sees before they touch you.
Vulnerability Scanning
Recurring authenticated scanning of your external and internal surface, with the false positives triaged out before you ever see them.
Phishing & Social Engineering
Controlled phishing and social-engineering campaigns that measure how your people respond, then turn the result into training, not blame.
Security Awareness Training
Practical, engaging training that helps your team recognize phishing, social engineering, and everyday risk, built from real attacks rather than generic slideware.
Security Consulting
Fractional CISO, threat-modeling workshops, architecture review, and SDLC integration: senior security guidance embedded alongside your engineering team.
Four steps.
No surprises.
We scope tightly, work in the open with short regular check-ins, and share findings the moment we confirm them. By the time the written report lands, nothing in it is a surprise to your team.
Scope & Setup
A short kickoff. We agree targets, rules of engagement, and success criteria, and exchange PGP keys.
The Work
We test, scan, or run the campaign, sharing findings as we go with short regular check-ins, not a data dump at the end.
Validate & Fix
You remediate, we retest where it applies, and most issues close before we wrap.
Delivery
A clear report: executive summary, technical detail, and, for tests, an attestation letter you can share with auditors and customers.
Not a checkbox
vendor.
Most assessments end with a PDF that arrives after the work is done and gets triaged into next quarter. We run the engagement so the fixing happens while we're still in the room.
Senior hands, every time
The person who scopes your work does the work. Nothing is handed to a junior, and nothing is quietly outsourced.
Findings arrive live
We share each issue the moment we confirm it, with proof and a clear fix, so your team can start work right away instead of waiting for a report.
Written by the person who found it
Reports are in plain language with the evidence attached, written by the tester, not ghost-written from a template.
Fixing over listing
Where it applies, a retest is included. We're measured on issues closed, not issues listed.
We work with your team
Short, regular check-ins during the engagement mean nothing in the final report catches anyone off guard.
Honestly scoped
Every engagement is sized to your situation, and we'll recommend a smaller one, or none at all, when that's the right call.
From the
journal.
Field notes and threat briefs, written for the engineers who have to act on them. No pop-ups, no email gates.
We're just getting started, and the first posts are on their way. Follow the journal →
Common
questions.
How does pricing work?
Every engagement is scoped to your systems, so we quote after a short scoping call rather than publishing a price list. You'll have a fixed proposal in hand before any work starts.
How long does an engagement take?
It depends on the service. An external attack-surface report takes about a week, a vulnerability scan one to two, and a penetration test two to four. We agree the timeline up front.
Do you work remotely or on-site?
Primarily remote. On-site work is reserved for physical or social-engineering assessments where we've agreed it in advance.
How do you handle our data?
Findings and code stay on our own infrastructure, encrypted, and are destroyed per the contract once the engagement ends. Our privacy policy has the detail.
Will this help with SOC 2 or ISO 27001?
Yes. A penetration test comes with an attestation letter and a report you can share with auditors and customers as evidence.
Do you need access to production?
Usually no. We work gray-box against a staging environment with credentials you provide. Black-box is available on request.