About

What we break speaks for us.

01Where we come from

Effront is offensive security for gaming and esports: platform and API pentest, anti-cheat and game-logic auditing, exploit simulation and tournament infrastructure testing.
We started building real-time infrastructure for competitive gaming - this page shows what that background lets us actually test.

Effront is a young security practice.
Instead of inflating a client list or a vulnerability count, this page lists exactly what we can verify - and nothing more.

02Verified engagement

Not portfolio slides - work you can actually verify.

Real work, described without exposing the target, test data, or anything not yet fixed.

Black-box penetration test of a municipal public-service scheduling system, no credentials, no backend code access. Multiple vulnerabilities found and classified by severity, with proof of concept for each.
Second session to validate the fixes applied by the development team - including a regression we found and reported that the first round of fixes had missed.
28 custom offensive-security scripts run against our own API and frontend - JWT and session attacks, multi-tenant isolation, race conditions, SSRF, mass assignment, WebSocket auth. Four vulnerabilities found and fixed this way, each with severity, root cause and fix documented. Every push also runs through static analysis, dependency auditing and secret scanning in CI.
03Who builds it

Real people, with names and LinkedIn.

No inflated titles, no ghost team - the people here do the work.

04Contact

Want to know if your game or platform holds up? Talk to the people who'll actually test it.