2026.01.15

We are a small offensive-security firm. We test other organizations’ systems for a living, and we do it the way a senior practitioner briefs a peer they respect: direct, with the evidence in hand, and without the theatrics.

What we believe

Honest before dramatic. We don’t inflate the severity of a finding to inflate the scope of the engagement. A medium-risk issue is reported as a medium-risk issue, in plain language, with the reasoning shown.

Written for the people who fix it. Every deliverable is something a working engineer can act on this week. We don’t ship two-hundred-page PDFs that go unread.

Rigor over reach. We hire for technical judgment first and breadth second, and we would rather do three things well than ten things adequately.

Legible to the whole room. Security is technical work, but the risk it describes has to be understood by the founder, the engineer, and the board from the same document. Making that translation is part of the job, not an afterthought.

The team

We are a senior team, part of which founded the firm. Between us we have worked in established security consultancies and in-house product-security teams before starting Yeti.Security.

We don’t intend to grow into a large agency. Boutique is a deliberate choice, not a stage we’re trying to leave behind.

How to reach us

The fastest path is hello@yetisecurity.cz. For sensitive material, we publish PGP keys for every team member.

If you’ve found a vulnerability in something we operate, see our responsible-disclosure policy.