Responsible security in the age of AI

Our approach

We treat security as a responsibility. We test ethically, with authorisation, and with regard for your data and operations.

Responsible security in the age of AI

We use AI as a tool — not a replacement for expertise

AI is changing both sides of the fence. We use it for faster analysis and broader coverage, but every finding is verified and interpreted by an experienced human tester. No auto-generated reports without review.

We also take responsibility for the data we handle. We test strictly on the basis of written authorisation, within an agreed scope, and with the utmost care not to endanger your systems or disrupt their operation.

A human verifies every finding

AI speeds up data gathering, but severity classification and recommendations are done by a tester. We eliminate false alarms.

Safe data handling

We keep sensitive data only as long as necessary, encrypted, in line with GDPR. After the test we securely dispose of it.

Ethics and authorisation first

We only test what is contractually approved. No destructive techniques without explicit consent.

Understandable output

We write reports so that even a non-technical founder or official can follow them — with clear priorities and remediation steps.

Our principles

Authorisation and legality

Every test has written authorisation and a clearly defined scope. We never test anything that hasn't been approved.

Ethical approach

We follow the principles of responsible disclosure and impact minimisation. We don't want to damage your systems, but protect them.

Transparency

We explain our process, findings and methodology clearly. You know what we do and why.

Data protection

We handle sensitive information encrypted, only as long as necessary, and in line with GDPR.

Methodology

  • We build on recognised standards (OWASP Top 10, OWASP ASVS, PTES) and NÚKIB guidance.
  • We combine automated tools with manual verification — every finding is assessed by a tester.
  • We classify findings by severity and impact, with clear remediation prioritisation.
  • After fixes we perform retests to verify the issue is genuinely resolved.