Skip to content

Offensive testing / Defensive engineering

Security that survives contact with a real attacker.

Defenseum is a small team of senior practitioners. We test the systems you actually ship, hand your engineers findings they can act on the same week, and stay on the hook until the fix is verified.

  • Senior-only engagements, with no juniors learning on your codebase
  • Critical findings reported the hour we confirm them
  • A retest of everything we report, included in the price

Engagement view / external surface

Live
CUSTOMER DATAINTERNET EDGE
  • Object storage policy allows public readCritical
  • Admin role without enforced MFAHigh
  • Legacy staging balancer decommissionedVerified

Built for teams who cannot afford a quiet breach

  • Seed to Series C software companies
  • Fintech and health platforms handling regulated data
  • Engineering teams from twelve people to four hundred
  • Organisations preparing for SOC 2 Type II, ISO 27001 and HIPAA review
  • Security teams of one, who need the reach of a whole department

Client names stay private. Every engagement runs under mutual NDA, we do not publish logos, and we will not use your company as a reference without asking first. It costs us a marketing page and buys our clients the confidence to tell us everything.

What we do

Four services, and the discipline to say when you need none of them

Each engagement is scoped, run and reported by the same senior practitioners. Nothing is subcontracted, and nothing arrives as scanner output with a cover page on it.

  • 01

    Penetration Testing

    We attack the systems you actually ship, the way a motivated adversary would, and show you the exact route from the outside to the thing you care about.

    Explore Penetration Testing
  • 02

    Security Consulting & Risk Assessments

    A clear-eyed read on where your risk actually sits, which controls are load-bearing, and what to fix first with the budget you actually have.

    Explore Security Consulting & Risk Assessments
  • 03

    Security Architecture & Hardening

    Design reviews, identity, segmentation and cloud baselines built with your engineers rather than handed to them as a document.

    Explore Security Architecture & Hardening
  • 04

    Incident Readiness & Response Planning

    Runbooks, roles, logging and rehearsals, so the first hour of a real incident is recall rather than improvisation.

    Explore Incident Readiness & Response Planning

Representative outcomes

What the work actually changes

Three engagements, described in general terms. The pattern is consistent: find the route rather than the symptom, then remove the class of problem instead of the single instance.

  1. 01Payments platform

    A path to production records, closed in four days

    The team came to us three weeks before an enterprise security review. We chained a permissive object storage policy to an export endpoint that never checked authorisation, and reached production customer records from an unauthenticated browser session. The route was closed in four days and the finding never reached the questionnaire.

  2. 02Health technology

    An internal tool that was not internal

    Their admin console was believed to be unreachable from the internet. It was reachable, through a staging load balancer nobody had decommissioned. Rather than close the one door, we worked with their platform team on segmentation and an identity-aware proxy, which removed the entire class of exposure.

  3. 03Series B software

    Logging everywhere, answers nowhere

    A twenty-person engineering organisation was collecting an enormous volume of telemetry and could not reconstruct a simple account takeover from it. We rewrote what they collect, cut the noisy sources paying for themselves in storage alone, and ran a tabletop in which their on-call engineer rebuilt a simulated credential theft timeline inside an hour.

Engagements are described in general terms and anonymised. We do not publish client names, logos or extracts from reports.

Common questions

The four things everybody asks first

Pricing, custom engagements and payment terms are covered in more detail alongside the tiers.

Read the full FAQ

How quickly can you start?

Most assessments begin two to four weeks after scoping. If you are mid-incident or facing a hard customer deadline, say so in your first message and we will tell you honestly whether we can meet it rather than booking you in and hoping.

Do you work with companies that have no security team?

Often. A large part of our client base has one engineer holding security alongside another job. We write findings so they can be acted on without a specialist to translate them, and we are happy to talk directly to the developers who will do the fixing.

Will you sign our NDA and complete our security questionnaire?

Yes. We sign client paper, complete vendor questionnaires, and can provide evidence of our own controls, insurance and background checks before scoping begins. Holding suppliers to the standard we recommend is the least we can do.

What do we actually receive at the end?

A technical findings report written for engineers, an executive summary written for the people who will never read it, a prioritised remediation plan, an attestation letter for your customers, and a retest once you have fixed things.

Next step

Find out what an attacker would find first

Tell us what you are worried about and we will scope it in half an hour. The call is free, and if you do not need us yet we will say so.