My mission: finding vulnerabilities before anyone else does
From web applications to AI systems and human processes — turning risks into concrete improvements.
Services
What can you expect?
From open-source (OSINT) research to penetration tests to team awareness — the full attack surface covered.
OSINT & External Exposure
What attackers can find about your organisation through open sources — mapped in full, without sending a single packet.
Learn moreSecurity Assessments & Pentesting
Vulnerabilities in your web applications and systems, identified from the perspective of a real attacker.
Learn moreAI & LLM Security Testing
AI systems tested for prompt resistance and safety boundaries, based on the OWASP Top 10 for LLM applications.
Learn moreSecurity Awareness Training
Practical, scenario-based training that turns your employees into an effective human firewall.
Learn moreAI Security
AI systems introduce new risks that traditional security doesn't cover
Chatbots, copilots and automated AI agents are exposed daily to attacks. Tested the way an attacker would — including stereotypes and other biases.
Jailbreak & guardrail bypass
Attempts to bypass the model's safety restrictions through creative prompt constructions — including techniques that push the model out of its alignment training.
Prompt injection & agent hijacking
Malicious instructions via user input, documents or tools that take over system behaviour or push an agent into unauthorised actions.
Data & memory leakage
The unintended disclosure of sensitive information from system prompts, training data or sessions belonging to other users.
Bias & harmful output
Structured testing for discriminatory or stereotyping model responses across gender, nationality, and ethnicity.
These attacks are real-world and are not covered by a standard web application penetration test. Request an AI security assessment →
Methodology
The approach
A transparent process — from first conversation to usable report. You always know where you stand.
Schedule a free intakeIdentify
Your attack surface fully mapped: which systems, applications and people are exposed to external threats.
Analyse
Hands-on testing from an attacker's perspective. Every finding is validated.
Prioritise by impact
Not every vulnerability is equally urgent. Findings ranked by actual impact, not just technical severity.
Improve
Concrete remediation steps, understandable for both your technical team and management. No jargon, just actionable.
Blog
Latest blog posts
The consolidated customer contact platform: Security and convergence of AI-CRM-UCaaS-CCaaS
The pitch for converged customer engagement platforms is simple: one interface, shared data, unified automation. What's less visible is what happens to trust when AI, CRM, UCaaS and CCaaS are collapsed into a single system. Convergence isn't just a different way to wire systems together. It changes how systems relate to each other, and in doing so, it quietly redraws the map of who can do what to whom. Integration is not the same as consolidation The typical framing describes this shift as in
LLM Failures: The Inevitable Cost of Narrative Agency
System prompts give language models their persona, tone, and behavioral constraints. In enterprise applications—especially contact centers—this enables useful role adoption: customer support agent, compliance assistant, financial advisor. This capability can be understood as narrative agency: the model’s ability to act within a defined role using natural language instructions. In practice, this “agency” is implemented through text, not enforceable control boundaries. That design choice is what
When Your RAG System Becomes the Attack Vector: Prompt Injection via Content Optimization
The moment you connect an LLM to a retrieval system and allow external content to influence responses, you create an execution boundary that content authors can potentially cross. That risk becomes more significant as organizations begin optimizing content for AI retrieval systems — a practice increasingly referred to as Generative Engine Optimization (GEO). Much like SEO shaped search engine behavior, GEO aims to shape what LLMs retrieve, prioritize, and reproduce. In Retrieval-Augmented Gener
Why clients trust me
- No boilerplate reports — only clear, concrete advice you can act on right away
- Tested the way a real attacker would
- Written scope, clear pricing, no surprises afterwards
Certifications
- Cisco Certified Cybersecurity Specialist — Threat Hunting & Defending
- Cisco AI Technical Practitioner
- Cisco AI Business Practitioner
- Cisco AI for Networking
Digital security for freelancers and SMBs.
Not as the exception,
but as the standard.
Get started
Want insight into your risks?
Request a free OSINT scan — clear answers on your situation within 24 hours.