We defend companies from attacks — from a pentest to full security ops
Need to test your defenses, stop an incident, or run security day to day.
An engineer replies within one business day. If the attack is already on — use the
Emergency 24/7.
What to do to protect, during an attack, and on an ongoing basis.
Find yourself by the job to do, not by how many services we list. Pentesting has its own page —
with scope, timeline and a fixed quote.
01
External pentest ePTS
We look at the perimeter the way an outside attacker would: public services, VPN, mail, cloud consoles and anything visible from the internet.
Recon and perimeter inventory
Exploitation of found vulnerabilities
A report with evidence and a fix plan
02
Internal pentest iPTS
We model an attacker who is already inside: a contractor, an infected laptop, or a former employee with live access.
Privilege escalation in the domain
Lateral movement across the network
A check of segmentation and monitoring
03
Social engineering SEPT
We test people and process, not just systems: phishing, fake “support” calls, and physical attempts to enter the office.
Targeted phishing campaigns
Vishing and pretexting
An attempt at physical access to the premises
04
Application security
Web and mobile apps against OWASP. Manual pentest plus tools — where a scanner only sees half the picture.
OWASP Top 10 and logic flaws
Authentication, sessions and access rights
APIs and external integrations
05
Source-code review
A systematic review with repository access. We find what you cannot see from the outside, and show how to fix it.
Manual review of critical paths
SAST with false-positive review
Dependency and supply-chain risk
06
Incident response
We contain the attack, stop the spread and restore operations. Then a root-cause write-up that a regulator or insurer can use.
Containment of the attack
Forensics and the entry point
Recovery and a closing report
07
Network defence
Layered defence: segmentation, access policy and traffic control. Legitimate users pass; the attacker does not.
Segmentation and access policies
Hardening of the controls
Traffic control and filtering
08
Dark-web monitoring
We watch closed markets and channels for your databases, credentials or internal documents.
Search for leaked credentials
Mentions of the company, brands and domains
An alert the moment a leak appears
09
Vulnerability management
Regular infrastructure scans, ranked by real risk, with a fix plan — not a nine-hundred-line dump.
Regular infrastructure scanning
Prioritisation by real impact
Fix tracking and a retest
10
Threat Intelligence
Threat data for your industry and stack, not a generic feed nobody can use.
Profiles of relevant threat groups
Indicators of compromise for your systems
Recommendations for your stack
11
MDR — detect and respond
Round-the-clock monitoring, detection and response on an agreed playbook. For teams without their own SOC, people or time.
24/7 security-event monitoring
Investigation of suspicious activity
Response on an agreed playbook
12
Security maturity assessment
Where you are now, what is missing, and what to do first — across process, technology and culture.
Audit of existing controls and process
A comparison with your industry
A twelve-month roadmap
13
Standards and compliance
ISO 27001, SOC 2, PCI DSS, GDPR and NIS2 — from gap analysis to being ready for an external audit.
Gap analysis against the standard you need
Policies, process and evidence collection
Support during the external audit
14
Staff training
The most expensive incidents start with one click. Training, workshops and regular phishing simulations for the whole team.
Training for specific roles
Phishing simulations with metrics
Regular reminders and refreshers
15
DevSecOps consulting
We build security into the delivery cycle: SAST and DAST in the pipeline, review gates and coaching for your engineers.
SAST and DAST in your CI/CD
Security gates in the release process
Developer coaching on your own code
16
vCISO — security leadership
Security leadership without hiring a CISO: priorities, budget, regulators and reporting to the board.
Security strategy and priorities
Risk and budget management
Reporting for the board and clients
No services in this group yet.
03 — how we work
What you get at the end
Not a severity table — findings your team can act on before lunch.
A technical report with reproduction steps
A working proof-of-concept for every exploitable finding
A short brief for people who will not open the technical report
A live walkthrough with your engineers
A free retest after your fixes
A signed attestation letter for clients and regulators
finding-0417.mdCVSS 9.1
day 1 · free
NDA and scope
We sign an NDA, look at your infrastructure and the job. You get a work list, a timeline and a fixed fee.
main phase
Project work
A named lead engineer and a shared Slack or Telegram channel. Critical findings go out immediately, not with the report.
close-out
Report and live review
A technical report, an executive brief, and a session with your team to argue the trade-offs in the fixes.
after your fixes
Retest
We check that the class of issue is closed, not a single instance, and issue an attestation letter. Included in the fee.
manufacturing · internal pentest0
From guest Wi-Fi to the domain controller
A flat network and a forgotten print service reached domain admin in half a day. Segmentation was rebuilt in two weeks.
retest passed cleanretail · dark-web monitoring0
The leak was found before the buyer of the dump
Customer credentials showed up in a closed sale. Forced password resets started before the dump was advertised.
no confirmed fraudfintech · compliance0
Certification passed on the first attempt
We came in four months before the audit, closed seven technical blockers and collected evidence that keeps itself current.
no auditor findings
We started with a one-off pentest and six months later handed them all of security on a retainer. Cheaper than keeping one specialist on staff, and a lot calmer.
OK
Chief operating officerretail, 600+ employees
04 — about
How we work with clients
KH Account Systems is a cybersecurity team in Kharkiv. We take a one-off project
or a retainer. An engineer decides, not a sales desk.
01
NDA first, details second
We do not ask for sensitive data until the NDA is signed.
02
The price is fixed once
Scope, timeline and fee — before we start. The number does not grow later.
03
Critical findings the same day
We do not wait for the report if a finding already opens production.
04
We talk to engineers
The person on the call is the one who does the work, not a slide deck.
05
The retest is included
After your fixes we re-check the class of issue, not a single report line.
06
Emergency when it is already on fire
A normal request — one business day. An incident — a separate 24/7 channel.
05 — contact
Tell us what to test or stop
A normal request — an engineer replies in one business day, with scope and a fixed fee.
If the attack is already on — tick Emergency or call now.