We break software for a living. Then we build it properly.

Hands-on penetration testing for web apps, APIs, smart contracts, mobile, cloud and firmware. We show you how we got in, and how to close it.

Halls of fame and bounties: teams that credited or rewarded our founder’s reports

  • NVIDIA
  • SimScale
  • Oracle
  • Kraken
  • Apple
  • Google
  • USAA
  • Indeed
  • NASA
  • FFmpeg
  • Vercel
  • Acronis
  • Lightspark
  • Anthropic
  • Nextcloud
  • McDonald’s
  • Fireblocks
  • Pinterest
  • AXIS OS
  • Zendesk
  • Binance
  • Asana

Web3: audits and rewards

  • VeChainThor
  • Multipli Smart Contracts
  • Internet Computer Protocol (ICP)
  • Snowbridge On-Chain Code
  • Olas
  • Injective Peggy Bridge

Every bug we find in someone else’s code is one we won’t ship in yours.

Where we break in

Six ways in, all tested by hand.

All security testing
  1. Solidity · EVM · SCSVS

    Smart contract audits

    Solidity read line by line, then fuzzed until it breaks or holds.

  2. Dependencies · Supply chain · Disclosure

    Open-source security

    Dependencies, CI pipelines and clean upstream disclosure.

300+

Vulnerabilities reported

Independent research since 2022

If we can’t prove it, it’s not in the report

No scanner dumps. No inflated severities.

  • A fixed quote, agreed before we start
  • Free retest of everything you fix

From first call to closed findings

  1. Learn

    Scoping

    One call on targets, rules and dates. Then a fixed quote, in writing.

    Fixed quote

  2. Learn

    Recon

    Hosts, endpoints, roles, versions and the third-party code you lean on.

    Attack surface map

  3. Learn

    Threat model

    Who would attack this, and where would they push first?

    Test plan

  4. Attack

    Testing and exploitation

    Hands-on, inside the agreed dates. Criticals reach you straight away.

    Confirmed findings

  5. Close

    Report

    Severity, evidence, reproduction steps and a fix for every finding.

    The report

  6. Close

    Remediation

    Your engineers fix. We answer their questions.

    Answers while you fix

  7. Close

    Retest

    Free, inside an agreed window. Each fix confirmed closed.

    Free retest

Then we build it properly

Nothing we build ships until we’ve tried to break it. Plumb, Aegis and imgosint included.

All build services
  1. Web · APIs · Back ends

    Web applications and APIs

    Web apps and APIs, attacked before they ship.

  2. Android · iOS

    Mobile apps

    Android and iOS apps that keep data on the phone.

  3. macOS · Windows

    Desktop apps

    Native software that handles files carefully and asks before it acts.

  4. Automation · CI · SARIF

    Security tooling and DevSecOps

    Scanners and CI checks that catch problems before they ship.

Built in-house

A Mac app, an Android app and an image verification tool.

  1. Plumb

    Status: In developmentmacOS · Apple silicon

    Shows developers what deleting caches, toolchains and app data on a Mac would really give back.

  2. Aegis

    Status: Early accessAndroid 7.0 and later

    Checks your Android apps on the phone itself: which hold sensitive or special access, and whether any match published stalkerware indicators.

  3. imgosint

    Status: Coming soonmacOS · Windows

    One picture, several public search engines, and every candidate it can fetch measured on your machine.

On the record

CVE

CVE-2026-43816, credited by Apple

A kernel out-of-bounds write, fixed across Apple’s 26.6 releases.

Date
July 2026
Where
Apple security releases
CVE

CVE-2022-21500, credited by Oracle

E-Business Suite, CVSS 3.1 base score 7.5.

Date
May 2022
Where
Oracle Security Alert
Firmware

Firmware findings, rewarded by Arm

Accepted in the Trusted Firmware scope.

Date
2026
Where
Arm bug bounty program
Hall of fame

NASA VDP Hall of Fame

Indeed and USAA list him in theirs too.

Date
2024
Where
NASA Vulnerability Disclosure Program
Recognition

NITI Aayog Frontier Tech Hub

Profiled in “Guardians of the Grid”.

Date
2025
Where
NITI Aayog Frontier Tech Hub

As featured in

  • WION
  • The Hindu BusinessLine
  • Indiatimes
  • ABP Live
  • DNA
  • ANI
  • Inshorts
  • The Better India
  • Daily Excelsior
  • Greater Kashmir
  • Kashmir Life
  • Free Press Kashmir
All press coverage

Who does the work

I started breaking into software in 2022, with permission. Three hundred-odd reports later, Apple put my name on a kernel CVE. Vulnara is the same work, done for you, under contract.

Tell us what to break. Or what to build.

Send the scope and your deadline, and we’ll set up a call.