What we do · where we operate · credentials
- What we do
- Web, mobile (iOS/Android), API, LLM/AI, and Electron penetration testing, plus manual source code security audits.
- Where we operate
- Costa Rica · Latin America · United States · Remote worldwide
- Credentials
- 25 years of offensive security experience. OSCP-certified. Spanish and English.
Services
Six services, each tested by hand against the relevant standard.
Web Applications
Manual, authenticated testing of your web application against the OWASP Web Security Testing Guide — logic flaws included, not just scanner output.
Mobile Apps (iOS/Android)
Manual security testing of iOS and Android applications against the OWASP MASVS, covering the app binary, local data, transport security, and the APIs behind it.
APIs
Manual testing of REST, GraphQL, and gRPC APIs against the OWASP API Security Top 10, with systematic per-endpoint, per-role authorization testing.
LLM / AI Applications
Security testing for applications built on large language models — prompt injection, insecure output handling, excessive agency, RAG poisoning, and tenant isolation — mapped to the OWASP Top 10 for LLM Applications.
Electron Apps
Security testing specialized for Electron desktop applications, where a web-grade XSS becomes desktop-grade remote code execution if the process model is misconfigured.
Source Code Audits
Manual, human review of your codebase — authentication and authorization logic, injection sinks, cryptographic misuse, secrets handling, and business-logic flaws — with tooling assistance, not a resold SAST report.
Sanitized finding sample
SSRF via Unvalidated URL in MCP Tool Execution Handler
Renderer-side JavaScript can trigger authenticated main-process requests to arbitrary URLs, including internal localhost MCP services.
1) Renderer submits attacker-controlled serverUrl to mcp:execute-tool
2) Main process forwards request with bearer token to arbitrary host
Resolve MCP targets from an internal allowlisted server ID and never forward Authorization to untrusted domains.
Methodology
A predictable process that keeps engineering, security, and compliance aligned from kickoff to retest.
Scoping
Define targets, roles, constraints, and test depth with engineering and security owners.
Rules of engagement
Agree safety boundaries, evidence handling, and communication channels before testing starts.
Testing
Manual exploitation-led testing across auth flows, business logic, and high-risk attack paths.
Reporting
Clear findings with impact, reproduction, and fixes your team can execute without guesswork.
Retest
Validate remediations and close the loop with updated evidence for stakeholders and auditors.
Compliance
Guides for teams under audit pressure — what the standard requires, what auditors accept, and how testing fits the window.
What auditors actually accept as pentest evidence, and when in the audit window to test.
Read guide
How to scope testing for Requirement 11.4.1 and avoid report formats QSAs reject.
Read guide
How to prove technical risk treatment with testing evidence that supports Annex A controls.
Read guide
How covered entities and business associates validate app-layer risk under the Security Rule.
Read guide
How to test AI-system attack paths and document controls for high-risk obligations.
Read guide
How to align AI management controls with concrete technical testing and evidence.
Read guide
See what the deliverable looks like
Review a sanitized sample report before you talk to anyone — finding structure, severity model, and remediation detail.
Get the sample reportRecent writing
Practical notes for engineering teams shipping under audit windows and real product constraints.
Browse all insightsReady to scope an engagement?
Describe the target and we reply within 1 business day with scoping questions or a proposed approach — no sales layer in between.