Bulwark for business

We find the holes before someone else does.

Authorized offensive testing of systems you own. We probe your product the way an attacker would, prove what is actually exploitable, and hand your engineers a fix they can ship the same day. Under signed scope, with your customers' data off limits.

See how it works

signed authorization first · test accounts only · nothing published without your consent

The risk

The expensive breaches start as ordinary product gaps.

Not exotic attacks. A storage bucket left open, an endpoint that never checked who was asking, a vendor login with more access than it needed, a server that missed a patch. Of 23 documented breaches we track, 10 began as something an authorized test could have found first.

4
Misconfiguration
Microsoft, Capital One, DeepSeek, Indonesian Health Ministry
2
Exposed API
Aadhaar, Twitter / X
1
Broken access control
First American Financial
1
Unpatched software
Equifax
2
Vendor or third party
National Public Data, Target

Root causes as publicly reported. Cases where the cause was never disclosed are excluded rather than guessed at. Figures count records, not people.

How it works

Four stages, from first call to a confirmed fix.

The process stays narrow and documented, so your engineers can follow it and your lawyers can read it.

  1. 01

    Scope

    A short call sets the boundaries: which systems, which environments, which window, and who can stop the test. Nothing begins until an authorization to test is signed by someone empowered to grant it. Anything not listed is out of scope.

  2. 02

    Hunt

    Automated reconnaissance covers the surface quickly, then researchers work the parts tooling is bad at: the ordinary product flows that ship fast and never get re-read. Password resets, invites, tenant boundaries, object IDs.

  3. 03

    Validate

    Every lead is reproduced by hand on test accounts before it becomes a finding. If we cannot prove a real exploit path safely, you never hear about it. Scanner noise is downgraded or discarded rather than forwarded to you.

  4. 04

    Report and retest

    You get one bounded report per finding, with proof and a fix. Criticals are reported immediately, ahead of the full report. When you patch, we retest the same day and confirm the issue is closed.

What you get

One finding, one report, six fields.

Not a scanner dump. This is the actual structure of our finding report, the same template we work from, so you know what lands before you book anything.

01 · System

Exactly what broke

The endpoint or component, and the flaw, in one or two sentences.

02 · Repro

How to hit it yourself

Minimal numbered steps an engineer can follow on a test account.

03 · Proof

Evidence it is real

What we actually did, with redacted requests and screenshots attached.

04 · Impact

What it costs you

The business consequence in plain terms. Who can do what to whom.

05 · Fix

The smallest correct change

The change that closes it, plus any follow-ups worth doing.

06 · Scope

How we kept it safe

The boundaries honoured while proving it. Usually: zero production records touched.

Criticals that present active, exploitable risk are reported immediately, ahead of the full report.

How we work

Aggressive on bugs. Careful with your business.

Each of these is a clause in the authorization you sign, not a slogan. If we break one, you have it in writing.

Bounded scope

We test you, not your customers

Production customer data must not be accessed, altered or stored. Where a flaw could expose real data, we stop at proof of concept on test accounts and minimal safe samples. No denial of service, no destructive actions, no social engineering of your staff unless separately authorized in writing.

Verified findings

Proof, not panic

A high severity finding means we reproduced real impact by hand. You will not receive a spreadsheet of theoretical issues, because a report you cannot act on wastes the only thing your engineers are short of.

Responsible disclosure

Quiet by default

Findings go to you first and privately. Nothing is published without your written consent, which is also why this page names no clients. If we find evidence of a live compromise we did not cause, we stop, preserve evidence, and call your emergency contacts.

Emergency stop

You can halt us at any moment

Either side can stop testing immediately by contacting the named contacts in the engagement. We cease activity on request, no discussion needed. Your technical contact is notified before any higher-risk test.

FAQ

What teams ask first.

Is this just a scanner?

No. Automated tooling is where we start, not what we deliver. Anything a scanner flags is reproduced by a human before it reaches you, and unprovable leads are dropped. The output is a written finding with evidence, not a tool export.

Will you touch our customer data?

No. The signed authorization makes production customer data explicitly out of scope. We work on test accounts you provide. Where a flaw could expose real records, we prove it is exploitable and stop there, then record exactly what was and was not accessed.

What do we actually get?

One report per finding, six fields: what broke, how to reproduce it, proof it is real, what it costs you, the smallest change that closes it, and the boundaries we kept. Written so one engineer can read it and ship a fix the same day.

What does it cost?

Scope drives price, so we quote after the call rather than publishing a number that would be wrong for most people. A small product with one login flow and a single API is a different job from a multi-tenant platform with a cloud estate. The call is free and you get our read on what we would go after first either way.

How fast can we start?

A scoping call, then a signed authorization to test. You do not need a security team in place first, and you do not need to prepare an environment beyond test accounts and a named technical contact.

Do you need access to our code?

Not necessarily. Most of what we look for is reachable from the outside of a running product. If you do want us to look at source, that is a separate scope item and gets written into the authorization.

What happens after we fix it?

We retest and confirm the issue is closed, and the finding is marked re-tested rather than just fixed. If the patch does not fully close the path, we say so and explain what is still reachable.

Start here

Find out what an attacker would.

A 30-minute call to walk through your product, how we test safely, and what we would go after first. We quote after that call, once scope is clear. Nothing runs until it is signed.