every release
retested after you ship, no per-scan billing
100% PoC
every finding with a working PoC
NIS2 · ISO 27001
signed report + evidence mapping, included, not certified
Funded startups that ship monthly+ and need current, signed evidence for a funding round or an enterprise security review; the standing hunt is your external CISO on a flat fee. Stable businesses that changed little but got their customer's NIS2 questionnaire start with the one-off audit and add continuous coverage later. When the report is asked for, you hand over one that is days old, not months.
This pipeline hunts live bug-bounty programs every day. Your hunt runs on the same pipeline. Full report list on request.

Order ID comes from the client, no ownership check on reads.
Tokens minted from a counter, not a CSPRNG.
No rate limit or lockout on the auth endpoint.
Full report list on request.
Hosts, app, API, auth roles: exact scope in a signed authorization and rules of engagement, in writing, before the first probe.
Our AI agent fleet maps the whole surface and probes the logic the way an attacker would; a named researcher verifies every PoC himself.
You ship, the hunt runs again on what changed. Retest is not an event or an add-on. It is the default.
CVSS plus NIS2 / ISO 27001 mapping and prioritized remediation. The report is a standing document, not a snapshot of yesterday.
from
€9,900/ year
one surface, every release, billed annually. Monthly also available.
Need a one-off report (NIS2, SOC 2, board)? The deep audit runs once: from €3,500, one retest included. Code-assisted adds +€1,500.
Flat and predictable. No per-scan billing, ever. Annual by default, monthly also available; both in writing before we start.
You get a human-verified PoC on every finding and a signed report. The researcher is named in the contract and reachable during the test and at the readout. Right now that is Samir Abis.
Fixed scope, fixed price, report guaranteed. A bounty gives you no coverage and no timeline, and you only pay when someone finds something. You need that report for SOC 2 anyway.
It complements one. A scanner lists what might be there, and you verify every flag yourself. We prove what an attacker can actually do, with a working PoC, a named researcher, and a signed NIS2 / ISO report a scanner cannot produce. The scanner keeps its job.
We pause the affected path. You hear about it within 4 hours on the agreed channel. Nothing destructive happens without written sign-off.
Yes. Give us repo access; the agent reads every release's diff for data-flow issues, missing auth checks, and framework-specific misconfigs. Findings come with file:line references and a working PoC. On the standing hunt this is the natural extension: you ship, the code is read, the logic is retested. Flat add-on, in writing.
Send us your domain. A researcher confirms your request, the check takes about 20 minutes (read-only, nothing reaches your systems), and then you have the short written report: what an attacker can realistically do with it. Yours whether or not anything follows. If we keep hunting: one flat annual fee, in writing.