Bulwark for business

We find the holes before someone else does.

We test the systems you own, the way a real attacker would. When we find a real hole, we prove it, then hand your engineers a report they can fix the same day. Nothing runs without signed permission, and your customers' data stays off limits.

See how it works

signed permission first · test accounts only · nothing published without your consent

The risk

The expensive breaches start as ordinary product gaps.

Not exotic attacks. A storage bucket left open, an endpoint that never checked who was asking, a vendor login with too much access, a server that missed a patch. Of the 23 breaches we track, 10 started as something an authorized test could have caught first.

2013
3B
accounts
Yahoo
Credential compromise

Every account the company had, disclosed years after the fact.

EmailsPhone numbersDates of birthHashed passwordsSecurity questions
2024
2.9B
records
National Public Data
Vendor or third party

A data broker nobody signed up for put identity records into open circulation.

NamesSocial Security numbersAddressesPhone numbers
2021Indonesia
279M
records
BPJS Kesehatan
Undisclosed

Indonesia's health insurance database appeared for sale on a hacking forum.

National ID (NIK)NamesAddressesPhone numbersFamily records
2018
1.1B
records
Aadhaar
Exposed API

India's national ID system was reachable through an endpoint that never checked who was asking.

National ID numbersNamesAddressesBiometric references
2019
885M
documents
First American Financial
Broken access control

Property documents were reachable by changing a number in the URL. No login required.

Bank account numbersMortgage recordsTax recordsSignatures
2021
700M
profiles
LinkedIn
Scraping

Profile data pulled at scale through public surfaces, then packaged for sale.

NamesEmailsPhone numbersJob historyLocations
2024
560M
customers
Ticketmaster
Credential compromise

A cloud data warehouse reached with stolen credentials and no second factor.

NamesAddressesPhone numbersPartial payment cards
2021
533M
users
Facebook
Scraping

Phone numbers tied to real names, published in full on a forum.

Phone numbersNamesLocationsRelationship status
2018
500M
guests
Marriott
Undetected intrusion

Four years inside the reservation system before anyone noticed.

NamesAddressesPassport numbersSome payment cards
2020
250M
support records
Microsoft
Misconfiguration

A misconfigured database left years of support logs readable by anyone who looked.

EmailsIP addressesSupport case details
2023
200M
accounts
Twitter / X
Exposed API

An API let anyone match an email address to the account behind it, in bulk.

EmailsUsernamesDisplay names
2024
190M
people
Change Healthcare
Ransomware

A ransomware attack on a medical payments processor, at national scale.

Health recordsBilling dataInsurance detailsSome SSNs
2013
153M
accounts
Adobe
Undetected intrusion

Password hints shipped alongside the encrypted passwords they hinted at.

EmailsEncrypted passwordsPassword hints
2017
147M
people
Equifax
Unpatched software

One unpatched web server exposed the credit data of half a country.

NamesSocial Security numbersDates of birthAddresses
2013
110M
customers
Target
Vendor or third party

Stolen credentials from an air-conditioning vendor, during the holidays.

Payment cardsNamesAddressesPhone numbers
2019
106M
applicants
Capital One
Misconfiguration

A cloud firewall rule let an outsider reach internal storage from the internet.

NamesAddressesCredit scoresSome SSNsBank account numbers
2020Indonesia
91M
accounts
Tokopedia
Undisclosed

One of Indonesia's largest marketplaces, traded openly online.

NamesEmailsHashed passwordsDates of birth
2016
57M
riders and drivers
Uber
Credential compromise

Credentials left in a code repository, then a payment to keep it quiet.

NamesEmailsPhone numbersDriver licence numbers
2023Indonesia
1.5TB
of customer data
Bank Syariah Indonesia
Ransomware

A ransomware group published the lot after the bank refused to pay.

Contact detailsFinancial documentsCard informationPasswords
2023
6.9M
profiles
23andMe
Credential compromise

Reused passwords plus a relative-matching feature turned into a genetic data leak.

NamesAncestry resultsRelative matchesLocations
2025
1M+
log records
DeepSeek
Misconfiguration

An unauthenticated database exposed chat history and internal keys.

Chat historyAPI keysBackend details
2024Indonesia
210+
government services
National Data Center
Ransomware

Ransomware took down Indonesian public services for days. No usable backup.

Immigration systemsLicensingPublic service records
2021Indonesia
1.3M
people
Indonesian Health Ministry
Misconfiguration

The COVID test-and-trace app exposed health status alongside identity.

NamesID numbersTest resultsHealth status
4
Misconfiguration
Microsoft, Capital One, DeepSeek, Indonesian Health Ministry
2
Exposed API
Aadhaar, Twitter / X
1
Broken access control
First American Financial
1
Unpatched software
Equifax
2
Vendor or third party
National Public Data, Target

Root causes as publicly reported. Cases where the cause was never disclosed are excluded rather than guessed at. Figures count records, not people.

Before and after

The same surface. This time you find it first.

Left, an attacker finds the gap first and you hear about it from someone else. Right, we probe the same surface under signed scope and prove what is real, safely.

your surfaceAttackerMappedfull surfaceProvenreal impactReportfix + retestBulwark
Before Bulwark

An open bucket, an endpoint that never checks who is asking. An attacker finds the gap first, quietly.

After Bulwark

We probe the same surface under signed scope, prove what is real on test accounts, and hand your engineers a report they can ship a fix from the same day.

How it works

Four stages, from first call to a confirmed fix.

Narrow and documented, so your engineers can follow it and your lawyers can read it.

  1. 01

    Scope

    A short call sets the boundaries: which systems, which dates, who can stop the test. Nothing runs until someone with the authority signs off. Anything not on the list is off limits.

  2. 02

    Hunt

    Tools map your public surface fast. Then people dig into the parts tools miss: the everyday flows that ship fast and never get a second look, like password resets, invites, and who can see what between accounts.

  3. 03

    Validate

    We reproduce every lead by hand on test accounts before it counts as a finding. If we can't prove a real way in, safely, you never hear about it. Scanner noise gets dropped, not forwarded.

  4. 04

    Report and retest

    One short report per finding, with proof and a fix. Anything critical goes out right away, ahead of the full report. When you patch, we retest the same day and confirm it's closed.

What you get

One finding, one report, six fields.

Not a scanner dump. This is the exact report we deliver, so you know what lands before you book.

01 · System

Exactly what broke

The endpoint or component, and the flaw, in a sentence or two.

02 · Repro

How to hit it yourself

Short numbered steps an engineer can follow on a test account.

03 · Proof

Evidence it's real

What we actually did, with redacted requests and screenshots.

04 · Impact

What it costs you

The business cost in plain terms: who can do what to whom.

05 · Fix

The smallest correct change

The change that closes it, plus any follow-ups worth doing.

06 · Scope

How we kept it safe

The limits we kept while proving it. Usually zero production records touched.

Anything critical and actively exploitable is reported right away, ahead of the full report.

How we work

Aggressive on bugs. Careful with your business.

Each one is a clause in the permission you sign, not a slogan. Break one and you have it in writing.

Bounded scope

We test you, not your customers

We never access, change, or store real customer data. Where a flaw could expose it, we stop at proof on test accounts. No denial-of-service, nothing destructive, and no phishing your staff unless you authorize it in writing.

Verified findings

Proof, not panic

A high-severity finding means we reproduced real impact by hand. No spreadsheet of maybes. A report you can't act on wastes the one thing your engineers are short of: time.

Responsible disclosure

Quiet by default

Findings go to you first and privately, published only if you say so. That's why this page names no clients. If we find a live break-in we didn't cause, we stop, save the evidence, and call your emergency contacts.

Emergency stop

You can halt us at any moment

Either side can stop the test at once by calling the named contacts. We stop on request, no discussion. We warn your technical contact before anything higher-risk.

FAQ

What teams ask first.

Is this just a scanner?

No. Tools are where we start, not what we deliver. Anything a scanner flags, a human reproduces first, and unprovable leads get dropped. You get a written finding with evidence, not a tool export.

Will you touch our customer data?

No. The signed scope puts production customer data off limits. We work on test accounts you provide, and record exactly what we did and didn't touch.

What do we actually get?

One report per finding, six fields: what broke, how to reproduce it, proof it's real, what it costs you, the smallest fix, and the limits we kept. Written so one engineer can read it and ship the same day.

What does it cost?

Scope drives price, so we quote after the call. A single login flow is a different job from a whole cloud setup. The call is free either way, and you leave with our read on what we'd go after first.

How fast can we start?

A scoping call, then a signed scope. You don't need a security team first, just test accounts and a named technical contact.

Do you need access to our code?

Usually not. Most of what we look for is reachable from outside a running product. Source review is a separate item, written into the scope.

What happens after we fix it?

We retest and confirm it's closed, marked re-tested, not just fixed. If the patch leaves anything reachable, we say so.

Start here

Find out what an attacker would.

A 30-minute call: your product, how we test safely, and what we'd go after first. We quote once the scope is clear. Nothing runs until it's signed.