
Perimeter
Digital, physical, personal.
Pentests and compliance for the company, bug sweeps and hardened devices for people worth attacking.
Four practices, one point of responsibility
Instead of three vendors passing the problem to each other.

Pentest and audit
A controlled attack on your systems following OWASP and PTES, with a report both the developer and the CEO can read.
- Web and API
- Mobile apps
- Infrastructure and cloud
- Social engineering
- Code review

Compliance and consulting
Certification readiness and policies that work instead of sitting in a folder.
- ISO 27001
- SOC 2
- GDPR, NIS2, DORA
- vCISO
- Staff training

Bug sweeps (TSCM)
Instrumented inspection of rooms, cars and equipment for listening devices and hidden cameras.
- Office and meeting room
- Car
- Home
- Equipment and gifts

Device protection
A phone and laptop configured for your threat model, and communications no third party reads.
- GrapheneOS
- Phone setup
- Laptop
- Messengers and email
- Hardware keys

One perimeter, four practices
Every line on the diagram is a separate vendor with the usual approach. With us it is one point of responsibility.
- Pentest and audit
- Compliance and consulting
- Bug sweeps (TSCM)
- Device protection
Methodologies we work by
No "proprietary methods", only open standards your auditor and your developer know.
- OWASP WSTG
- OWASP API Top 10
- OWASP MASVS
- PTES
- NIST SP 800-115
- ISO 27001
- SOC 2
- NIS2
- DORA
- GDPR
How the work goes
01Conversation
We find out what exactly we protect and from whom. No forty-question questionnaires.
02Scope and contract
We fix the boundaries, timeline and report format. We sign an NDA.
03The work
We test and document every finding with evidence and a risk level.
04Report and fixes
We explain what to fix first. We retest after the fixes.
Who we are for
Six typical situations people come to us with. If you recognise yours, the next step is a short conversation.

Executives and owners
Negotiations that must not leak, and a phone that must not be read.

Lawyers
Attorney-client privilege in the office, the car and on devices that may be seized.

Journalists
Source protection: communications, devices, room sweeps before sensitive interviews.

Fintech and banks
Pentest before release, DORA and NIS2, a report for the regulator and partners.

E-commerce and marketplaces
Protecting the payment flow, customer personal data and partner APIs.

SaaS and product teams
Application and API pentest, SOC 2 for US customers, a secure development cycle.
Scanner or pentest
A scanner is useful, but it is not a security assessment. Here is the difference.
| Vulnerability scanner | Pentest | |
|---|---|---|
| What it finds | Known vulnerabilities from a database | Real attack scenarios, including logic |
| False positives | Hundreds, for you to triage | Every finding verified by hand |
| Attack chains | Does not see them | Chains small findings into a critical one |
| Report | A technical list | For the director, the developer and the auditor |
| Retest | The same scan again | Confirmation that it is fixed |
How we work

No fear selling
We do not sell fear. We say which risk is real and where you can save.

NDA before the first word
We sign a non-disclosure agreement before any details. Your template or ours.

A report people read
One page for the executive, steps for the developer, evidence for the auditor.

Retest included
After the fixes we test again and confirm it is closed.

How this site is protected
We do not ask you to take our word for it. Check for yourself.
- No database
- The site is static. There is nothing to break into: no admin panel, no sessions, no passwords.
- Requests are not stored
- The form sends your message straight to our Telegram and keeps no copy on the server.
- Security headers
- CSP, HSTS, no embedding in other sites. Check it on securityheaders.com.
- No trackers
- No cookies, no pixels, no third-party analytics.
Guide
Short articles about what we do and why. Five minutes of reading that saves an hour of conversation.

What a pentest is and how it differs from a vulnerability scanner
A scanner finds known holes from a list. A pentester thinks like an attacker and chains small things into a real breach.
4 min read
How a bug sweep works
What we do in an office, a car or a flat, which instruments we use and why it takes hours.
5 min read
GrapheneOS: what it is and who really needs it
An operating system for Pixel without Google services by default. Not for everyone, but for some the only option.
4 min readCommon questions
How much does a pentest cost?
It depends on the scope: the number of applications, the size of the network, the access mode. A small web app and a large infrastructure differ many times over. After a short conversation we give a fixed price and timeline; we do not publish prices on the site because without scope they mislead.
Will you break something during the pentest?
We work within agreed boundaries and rules: no DoS, no data destruction, destructive actions only in a test environment and after separate permission. We warn about risky steps in advance.
How long does the work take?
A pentest of one application: one to two weeks including the report. Infrastructure: two to four weeks. A bug sweep: from a few hours to a day. ISO 27001 preparation: three to nine months depending on the starting point.
Do you sign an NDA?
Yes, before any work begins. We can sign your template or provide ours.
Can I contact you anonymously?
Yes. The form has a confidential mode: no name or phone, only a Signal or Session handle. For a bug sweep we arrange a meeting without witnesses.
Write to us
The message goes straight to our Telegram. Nothing stays on the server.
Telegram
