Responsible security in the age of AI
Our approach
We treat security as a responsibility. We test ethically, with authorisation, and with regard for your data and operations.
Responsible security in the age of AI
We use AI as a tool — not a replacement for expertise
AI is changing both sides of the fence. We use it for faster analysis and broader coverage, but every finding is verified and interpreted by an experienced human tester. No auto-generated reports without review.
We also take responsibility for the data we handle. We test strictly on the basis of written authorisation, within an agreed scope, and with the utmost care not to endanger your systems or disrupt their operation.
A human verifies every finding
AI speeds up data gathering, but severity classification and recommendations are done by a tester. We eliminate false alarms.
Safe data handling
We keep sensitive data only as long as necessary, encrypted, in line with GDPR. After the test we securely dispose of it.
Ethics and authorisation first
We only test what is contractually approved. No destructive techniques without explicit consent.
Understandable output
We write reports so that even a non-technical founder or official can follow them — with clear priorities and remediation steps.
Our principles
Authorisation and legality
Every test has written authorisation and a clearly defined scope. We never test anything that hasn't been approved.
Ethical approach
We follow the principles of responsible disclosure and impact minimisation. We don't want to damage your systems, but protect them.
Transparency
We explain our process, findings and methodology clearly. You know what we do and why.
Data protection
We handle sensitive information encrypted, only as long as necessary, and in line with GDPR.
Methodology
- We build on recognised standards (OWASP Top 10, OWASP ASVS, PTES) and NÚKIB guidance.
- We combine automated tools with manual verification — every finding is assessed by a tester.
- We classify findings by severity and impact, with clear remediation prioritisation.
- After fixes we perform retests to verify the issue is genuinely resolved.