About

You will know who tested your application

The offensive security brand of Skull Solutions, working out of the Maldives. We attack web applications and the APIs behind them by hand, and that is the whole of it. One field, and no other.

Founders

Who you are dealing with

Only our own people work on your application. No contractors, no partner firm, nobody brought in for the week.

  • Mohamed Zaam

    Co-founder, Technical Lead

    Comes from building software: the same kind of web applications and APIs this company now gets paid to take apart.

    mohamedzaam.com

  • Aiham Mueen

    Co-founder, Operations Lead

    Comes from networks: what is genuinely reachable from where, and where an application's edge actually sits.

    aihammueen.com

Anyone who works on your application is named on this page. The work is remote, so where you are matters a good deal less than what you have built.

Why this exists

Shipping it is the hard part. Nobody checks it.

Most of the applications we care about were built by people with no security engineer anywhere near them. They did the difficult part, then put it on the internet, where the only people who ever really test it are strangers with no reason to say what they found.

That is the gap this company exists to sit in. Not because a test makes an application safe. Because there is a difference between finding out from us, with the fix written next to it, and finding out from a customer on a Sunday.

How we work

Five things we hold to

  • Authorised testing only

    Scoped and authorised in writing before anything starts.

  • Findings you can reproduce

    Each one carries the request that triggers it and the steps to reach it.

  • Ranked by real risk

    Ordered by what it would cost you, not by a number a calculator produced.

  • Closed, not just reported

    A retest is part of the engagement, included for fifteen days after the report.

  • Direct contact

    You talk to the people doing the testing. There is no account manager.

Scope

What we are not

Not a generalist consultancy, and not an accredited assessor who can sign a compliance certificate. Not a software house: we do not write your code, and the remediation is your engineers' work rather than ours.

We are one half of Skull Solutions on purpose. The defensive work sits on the other side of that line: how an application should have been designed, and the engineering that closes what a test finds. Both are real, both belong to Skull Solutions, and neither is sold here. Ask and we will hand you over rather than quietly widen a testing engagement to cover it.

Where we will point you elsewhere

Architecture review, threat modelling, secure code review and remediation engineering go to Skull Solutions. Network, wireless and physical testing, red teaming and social engineering, incident response while an incident is live, specialist offensive research and exploit development, and audits that have to be signed by an accredited assessor all go elsewhere entirely. In each case we would rather name someone who does it than learn at your expense.

We would rather turn work down than take it on and learn at your expense.

Work with us

Tell us what you have built and we will tell you whether it is worth testing.