Skip to content
Selva Ops

Selva Ops S.R.L. · Costa Rica

Penetration testing for web, mobile, API, and AI systems

Manual, engineer-focused security testing for web, mobile, API, LLM/AI, and Electron products — plus source code audits. Findings your team can fix fast, not scanner noise.

25 years of offensive security experience. OSCP-certified. Spanish and English.

What we do · where we operate · credentials

What we do
Web, mobile (iOS/Android), API, LLM/AI, and Electron penetration testing, plus manual source code security audits.
Where we operate
Costa Rica · Latin America · United States · Remote worldwide
Credentials
25 years of offensive security experience. OSCP-certified. Spanish and English.

Sanitized finding sample

High

Finding

SSRF via Unvalidated URL in MCP Tool Execution Handler

Impact

Renderer-side JavaScript can trigger authenticated main-process requests to arbitrary URLs, including internal localhost MCP services.

Reproduction

1) Renderer submits attacker-controlled serverUrl to mcp:execute-tool
2) Main process forwards request with bearer token to arbitrary host
        

Remediation

Resolve MCP targets from an internal allowlisted server ID and never forward Authorization to untrusted domains.

Sanitized and redacted from a real Selva Ops engagement.

Get the sample report

Methodology

A predictable process that keeps engineering, security, and compliance aligned from kickoff to retest.

  1. Scoping

    Define targets, roles, constraints, and test depth with engineering and security owners.

  2. Rules of engagement

    Agree safety boundaries, evidence handling, and communication channels before testing starts.

  3. Testing

    Manual exploitation-led testing across auth flows, business logic, and high-risk attack paths.

  4. Reporting

    Clear findings with impact, reproduction, and fixes your team can execute without guesswork.

  5. Retest

    Validate remediations and close the loop with updated evidence for stakeholders and auditors.

See the full methodology

Compliance

Guides for teams under audit pressure — what the standard requires, what auditors accept, and how testing fits the window.

See what the deliverable looks like

Review a sanitized sample report before you talk to anyone — finding structure, severity model, and remediation detail.

Get the sample report

Recent writing

Practical notes for engineering teams shipping under audit windows and real product constraints.

Browse all insights

Ready to scope an engagement?

Describe the target and we reply within 1 business day with scoping questions or a proposed approach — no sales layer in between.