
Web and API penetration testing
Your web app and API, attacked by hand.
Security testing
Hands-on tests. Proof you can reproduce.
All security testingHow we workWhat happens after the first call.See the processBuild
We break software for a living. This is what we build.
All build servicesProof of workOur own apps, built the same way.See themHands-on penetration testing for web apps, APIs, smart contracts, mobile, cloud and firmware. We show you how we got in, and how to close it.
Halls of fame and bounties: teams that credited or rewarded our founder’s reports
Web3: audits and rewards
Every bug we find in someone else’s code is one we won’t ship in yours.

Your web app and API, attacked by hand.

Solidity read line by line, then fuzzed until it breaks or holds.

The app and the API behind it, taken apart against MASVS.

Your perimeter, internal network and cloud accounts.

We pull the firmware apart and go after the device.

Dependencies, CI pipelines and clean upstream disclosure.
300+
Vulnerabilities reported
Independent research since 2022
No scanner dumps. No inflated severities.
Learn
One call on targets, rules and dates. Then a fixed quote, in writing.
Fixed quote
Learn
Hosts, endpoints, roles, versions and the third-party code you lean on.
Attack surface map
Learn
Who would attack this, and where would they push first?
Test plan
Attack
Hands-on, inside the agreed dates. Criticals reach you straight away.
Confirmed findings
Close
Severity, evidence, reproduction steps and a fix for every finding.
The report
Close
Your engineers fix. We answer their questions.
Answers while you fix
Close
Free, inside an agreed window. Each fix confirmed closed.
Free retest
Nothing we build ships until we’ve tried to break it. Plumb, Aegis and imgosint included.
All build services
Web apps and APIs, attacked before they ship.

Android and iOS apps that keep data on the phone.

Native software that handles files carefully and asks before it acts.

Scanners and CI checks that catch problems before they ship.
A Mac app, an Android app and an image verification tool.
Shows developers what deleting caches, toolchains and app data on a Mac would really give back.
Checks your Android apps on the phone itself: which hold sensitive or special access, and whether any match published stalkerware indicators.
One picture, several public search engines, and every candidate it can fetch measured on your machine.
A kernel out-of-bounds write, fixed across Apple’s 26.6 releases.
E-Business Suite, CVSS 3.1 base score 7.5.
Profiled in “Guardians of the Grid”.
As featured in
I started breaking into software in 2022, with permission. Three hundred-odd reports later, Apple put my name on a kernel CVE. Vulnara is the same work, done for you, under contract.
Muneeb Amin Bhat
Founder and principal security researcher
Send the scope and your deadline, and we’ll set up a call.