We find the vulnerabilities scanners cannot reach.
Offensive security against production systems, upstream open source, and cryptographic implementations. We audit the way an attacker thinks, following what they control rather than what a rule file happens to match.
What We Assess
Black-box testing
Live testing against running systems with no prior access and no source. We work the way an attacker does, mapping tenancy boundaries, authentication surfaces, and the request paths your platform exposes to anyone who signs up.
White-box source audit
Full source review at a pinned revision. We trace trust boundaries through admission and authorization logic, deserialization sinks, and the seams between services where assumptions stop matching.
DevSecOps & supply chain review
Pipeline and provenance integrity: CI/CD trust, build-system tampering, SBOM and signature verification, container image lineage, and the dependency paths that decide what actually reaches production.
Cryptographic spec conformance
Implementations checked line by line against the normative specification: parameter validation, subgroup and on-curve checks, nonce uniqueness, signature malleability, key-usage binding. Every finding names the exact clause it breaks, in FIPS 186-5, SP 800-56A, SP 800-38D, RFC 3526 / 7919 / 8017 / 8032, SEC 1, PKCS #11 v3.2, KMIP v2.1, TPM 2.0 or FIPS 140-3.
A scanner tells you what matched. We tell you what an attacker can do.
We reason about systems, not patterns
A scanner matches a shape in your source. We work out what an attacker actually controls, then follow it through admission logic, authorization boundaries, and the rules a specification puts on your code. A scanner has no way to describe those issues, so it never reports them.
Chains, not findings lists
Individual issues get composed into end-to-end attack chains mapped to MITRE ATT&CK. You see the route from an unauthenticated request to the thing you actually care about losing, not a severity column to argue with.
An enforced quality gate
Nothing reaches your report without clearing a mechanical gate covering reproducibility, scope, evidence, and consistency between what a finding claims and what its evidence supports. The gate is automated, so it does not get skipped under deadline.
Proof-of-concept validation: know what to fix first.
You get the complete findings list either way. Add this package and we also drive each candidate to a working proof of concept: a Docker harness, a live cluster reproducer, or a regression test that fails before the fix and passes after it.
That produces a second, shorter list alongside the first: the findings proven exploitable in your environment, each with a reproducer your engineers can run themselves.
It is your priority queue. Remediation starts from evidence rather than from a severity column.
Where We’ve Done This
-
OpenProject
Source-code audit of the Rails application and its storage integrations.
CVE-2026-46386 ↗ -
Kubernetes
Upstream research on apiserver authentication and kubelet trust boundaries.
-
OVHcloud
Managed Kubernetes and public cloud platform testing.
-
Infomaniak
Managed Kubernetes and application hosting platform testing.
-
Swiss Post e-voting
Cryptographic protocol and implementation review.
Research conducted through direct engagements and through the programs of YesWeHack and HackerOne. Findings are handled under each engagement’s disclosure terms, which is why this page names the systems we tested and nothing about what we found in them.
Want to know what an attacker would find first?
Scoped assessments, priced end-to-end. Located in Europe (CET). Remote-first.