Application

Web, API, mobile, and AI-enabled applications.

Web, API, mobile, LLM.

Code-assisted testing with reproducible findings. We work with your engineers — not around them — and our reports are written so a developer can fix things without translation.

  • Web & APIAuth and session, tenancy, business logic, integration abuse. REST, GraphQL, gRPC.
  • MobileOn-device storage, runtime protections, auth flows, backend alignment. iOS and Android.
  • EndpointPrivilege boundaries, update channels, local data handling, IPC. Electron, .NET, native.
  • Code reviewCritical paths, pre-release gates, post-incident validation. Manual review supported by tooling.
  • LLMPrompt and tool boundaries, agent safety, RAG data handling, supply-chain provenance.
  • ReportFindings with reproduction steps, code context, and prioritised remediation. Written for developers.
  • Working sessionA walkthrough with the engineers who'll do the fixes. Direct access to the operator.

A short note about what you're working on is enough to start. We read every message and reply within a business day.