Pentesting · Munich

Break it before they do.

Pentests for AI startups that ship fast and have no security team yet.

Signed scope first. Retest included.

Report · Example finding
N2-03 · API · Grey boxHigh

One tenant can read another tenant's chat history

GET /api/v1/conversations?tenant=acme-b
Authorization: Bearer <token for acme-a>

200 OK  [ 42 conversations ]
ImpactData exposure
FixBind tenant to token
RetestFixed
Illustrative example, not a client finding.

About

Security, without the security team.

We're offensive security and AI engineers. We test what you actually run: your API, your roles, your LLM features. You get findings your engineers can fix, and a retest once they have.

  • Written authorization first
  • Findings engineers can act on
  • Retest included

Services

Two ways in.

Pick how much we know going in.

Most common

Grey box

Signed in, like a real user. Or a stolen account.

  • Public APIs
  • Access control across roles
  • Prompt injection and LLM leaks
Outside in

Black box

Nothing but your domain, like an outside attacker.

  • Exposed attack surface
  • Sign-up, login and reset flows
  • Public LLM features

People

The team.

Max Ngo

Max Ngo

Offensive Security Engineer, NAB

Ex Canva · BSc, Swinburne

Duc Nguyen

Duc Nguyen

AI Engineer

Ex Celonis · MSc, TUM

Blog

Field notes.

All posts
LLM security

LLM features: what we check first

Prompt injection gets the headlines. The leaks come from the plumbing behind the chat box.

[DATE] · 6 min read
APIs

Multi-tenant APIs: five common mistakes

IDs in URLs, trusted headers, unchecked bulk endpoints.

Coming soon
Process

Your first pentest: how to prepare

Test accounts, a signed scope and who to call when we find something.

Coming soon

Find it first.

A 30-minute call to agree on scope. Nothing starts without your sign-off.