News

What happened, when it happened.

No inflated press releases - this page records real milestones.

28 custom offensive-security scripts run against our own API and frontend - JWT and session attacks, multi-tenant isolation, race conditions, SSRF, mass assignment, WebSocket auth. Four vulnerabilities found and fixed this way, each with severity, root cause and fix documented. Every push also runs through static analysis, dependency auditing and secret scanning in CI.
Second session to validate the fixes applied by the development team - including a regression we found and reported that the first round of fixes had missed.
Black-box penetration test of a municipal public-service scheduling system, no credentials, no backend code access. Multiple vulnerabilities found and classified by severity, with proof of concept for each.