Security work that
stands up to scrutiny.

Independent security testing for release decisions, assurance and known concerns, with defensible findings and practical remediation.

Work alongside the people testing your system.

We take the time to understand your product, so testing reflects how it works, impact is assessed in context and remediation is practical.

Security testing
and assurance.

Penetration testing

Web applications · APIs · Infrastructure

Find exploitable behaviour and control failures across web applications, APIs and infrastructure. Receive reproducible findings and practical remediation.

Cloud security assurance

AWS · Azure · GCP

Test identity, configuration, segmentation and monitoring controls across AWS, Azure and GCP environments.

AI application security

LLM · RAG · Agentic systems

Test model-connected applications across prompt boundaries, retrieval, tool use and sensitive-data handling.

AI security starts with the application around the model.

Read our AI security research

We test prompt boundaries, retrieval, tools, identity, permissions and sensitive-data handling, including how those parts behave together.

Research

Published work examines model-connected applications, control boundaries and multi-turn attack paths.

In assessments

Our assessment platform operates alongside our consultants to map complex systems, trace attack paths across components and carry testing through to defensible evidence.

Define. Test.
Demonstrate. Resolve.

  1. Define

    Set the objective and understand the product.

  2. Test

    Follow relevant attack paths through the system and its controls.

  3. Demonstrate

    Show what happened, why it matters and how to reproduce it.

  4. Resolve

    Prioritise fixes and verify the changes that matter.

COMING SOON

Project
Kickoff

Start testing, not chasing access.

Project Kickoff gives clients and testers one current view of the brief, scope, contacts, prerequisites and access state.

Ask about Project Kickoff

Oversee the three core pillars of every project.

Brief

The system, its purpose and the assessment objective.

Scope

Authorised targets, exclusions and testing constraints.

Access

Routes, accounts and prerequisites, with their current state.

Manage project kickoffs consistently by giving stakeholders clear context, ownership and next steps.

Research

Technical notes on application security, cloud environments and defensive controls.

All research

AI SECURITY

A multi-turn attack through the tool layer

A controlled-lab attack chain through filters, tool calls and an unsafe template context. Read article

AI SECURITY

LLM security starts with architecture

Token streams, prompt boundaries and the controls around model-connected applications. Read article

CLOUD SECURITY

AWS privilege escalation through SSRF and IAM

A lab walkthrough tracing SSRF, exposed credentials, S3 access and IAM privilege escalation. Read article

ENDPOINT SECURITY

Testing EDR controls with custom shellcode runners

A lab study of DLL unhooking, AMSI bypass and payload transformation against an enterprise EDR trial. Read article

CLOUD SECURITY

Azure privilege escalation through automation accounts

An AzureGoat walkthrough covering SSRF, exposed application settings, RBAC discovery and runbook abuse. Read article

CLOUD ARCHITECTURE

Cross-account AWS database access

A practical guide to VPC peering, IAM role assumption and Secrets Manager across AWS accounts. Read article

ADVERSARY SIMULATION

Building a reproducible red team lab

A Windows and Active Directory lab for testing multi-step attack paths without destructive techniques. Read article

Planning an assessment?

Tell us what you need to test.

Start a conversation