Find your weak points before someone else does.
Penetration testing, configuration audits and AI red teaming - delivered to recognised methodologies, with manually validated findings and reporting ready for NIS2/KSC audits.
Three pillars, one specialisation
From a one-off test to a continuous oversight programme - the catalogue spans more than twenty services across four areas.
Offensive testing
- Web, API and mobile pentests
- External and internal infrastructure
- Active Directory / Entra ID, Wi-Fi
- Phishing campaigns
Cloud & continuous oversight
- AWS / Azure / GCP / M365 reviews
- Kubernetes, hardening, code review
- Perimeter scanning and OSINT
- Vulnerability management on retainer
People & compliance
- Security awareness and dev training
- NIS2 / KSC gap analysis
- Post-test support and advisory
- Audit-ready documentation
AI / LLM red teaming
Robustness testing for models, agents and AI integrations: prompt injection, jailbreaks, data exfiltration through tools, security of MCP servers and RAG pipelines. Research background: a doctorate in progress on adversarial ML.
Ready before the audit
The KSC (NIS2) Act has been in force since 3 April 2026. Self-identification duties and deadlines apply regardless of notification - and vulnerability identification is one of the required risk-management measures (Art. 21).
Eight years in offensive IT. On your side.
Hundreds of systems tested - from web applications and APIs, through on-prem and multi-cloud infrastructure, to AI models. Every engagement is delivered personally by a certified specialist (CISSP, OSCP, eWPTX) holding Polish, NATO and EU security clearances, with a doctorate in progress on adversarial ML - no subcontractors, no middlemen. The same person who runs the test signs the report and can defend it in front of auditors and the board.
A practitioner, not a robot
Testing is led by a certified specialist - vulnerabilities chained into attack paths, not a scanner printout.
Manual validation
Every finding confirmed by hand. Reports free of false-positive noise.
Audit-ready reporting
CVSS prioritisation, a management summary and mapping to Art. 21 measures.
Research background
A doctorate in progress on adversarial ML and a specialisation in AI system security.
Initial consultation
An initial consultation establishes the scope of work, priorities and next steps.
- [x]Scope and authorisation agreed in writing
- [x]Manual validation of every finding
- [x]Report: CVSS, management summary, Art. 21 mapping
- [x]Retest after remediation
- [x]NDA and encrypted data handling
For confidential correspondence, please use the public PGP key.
Download PGP key