IT × INFOSEC × PRODUCT

We defend,
we build,
we integrate.

We make chaos controllable.

Pentesting and AI products under one roof: we stress-test GenAI products and build our own services with vibe-coding. A spec ships to production in weeks.

PentestGenAI PentestAppSec / SSDLCComplianceDevSecOpsAI ProductsVibe-coding

An IT company
with security DNA.

Engineers first, security people second. You feel it in every project: pentest, AppSec, SSDLC, Cloud, Compliance, architecture.

In parallel we build our own products: AI agents, custom CRMs, bots for business. An idea reaches production in a couple of weeks.

/ 01
Security end to end
Pentest, AppSec, SSDLC, Cloud/K8s, Compliance. In-house, no subcontracting.
/ 02
AI products
Services, bots, CRMs and integrations where AI is the workhorse, not decoration.
/ 03
Speed
Vibe-coding: an idea reaches production in a couple of weeks. No quarterly sign-offs.
20
experts
pentest, AppSec, architecture, compliance, AI development
HTB / PS
certifications
Hack The Box, PortSwigger Web Security Academy
4
own products
already in production

Two directions,
one approach.

Security and product under one roof. We understand both threats and business, so security makes the team faster.

TRACK 01 / SERVICES

Information security

The full security range: from external pentest to security right in the pipeline.

  • Pentestweb, api, infra, K8s, AI / LLM
  • AppSec / SSDLCcode review, SAST, threat modeling
  • Compliance152-FZ, GDPR, PCI DSS, GOST
  • Cloud & Infra Securityclouds, containers, networks
  • Security architectureADR/TDR review, Auth/IAM
TRACK 02 / PRODUCTS

Vibe-coding and AI development

Vibe-coding as a method: custom services, agents and bots with AI inside. From idea to production in weeks, not months of edits.

  • AI agentssales, operations, support
  • CRM and integrationsamoCRM, Wazzup, Telegram bots
  • Telegram botswith an LLM under the hood
  • Parsers and analyticsphotos, content, markets
  • MVP in weeksa live service instead of a deck

Full spectrum of InfoSec

From pentest and code review to compliance, architecture and DevSecOps. Every bit done by our own team.

01
Pentest web / api
External and internal pentest of web apps and APIs. BSCP / CBBH on the team.
02
Pentest infra / K8s
Testing of infrastructure, containers and clouds. Post-exploitation scenarios.
03
GenAI Pentest LLM / Agents
Pentest of AI products: prompt injection, RAG leakage, guardrails review, agent jailbreak testing.
04
AppSec Secure SSDLC
Security in the pipeline. SAST / SCA / DAST, fuzzing, ASOC, secure-by-design.
05
Code Review & Threat Modeling
Manual code audit and threat modeling. ADR / TDR review at design time.
06
Auth / IAM
Authentication, IAM, SSO, MFA architecture. Design and audit.
07
Compliance / 152-FZ, GDPR, PCI DSS
Documentation, audit, readiness for assessments. GOST and industry requirements.
08
Cloud / Infra Security
Cloud, K8s, network and container security architecture.
[*] SCOPE TO FIT — FROM A ONE-OFF PENTEST TO FULL SECURITY SUPPORT

Your AI bot is live?
Let's see if it takes a punch.

A free express audit of your LLM product: in 2 days we run the baseline attacks against one product and show you which of them actually work. A classic pentest doesn't cover this.

/ 01
Prompt injection
we make the bot break its own rules through user input
/ 02
Agent jailbreak
we push the agent out of its script: extra actions, other users' data
/ 03
System prompt leakage
we extract instructions and internal logic from the context
What you get
A short report with proven findings: a reproducible attack, a risk level, and what to fix first. If your product holds up — we'll say so honestly.
What's next
Based on the findings — a full GenAI pentest: RAG leakage, agent access to systems, guardrails review, regression audits on every model release.
[*] 2 DAYS · 1 PRODUCT · FREE · MONTHLY SLOTS ARE LIMITED

Fixed scope, timeline and a quote in 24 hours.

Packages for typical jobs: it's clear what's included and how long it takes. The price is fixed after a short brief — we send the quote within a day.

PENTEST · S
External perimeter
~3 weeks

Everything exposed to the internet: web, API, subdomains. Recon, exploitation, proof.

  • Report with a PoC for every finding
  • Risk-based prioritization
  • Free retest after fixes
Get a quote in 24 hours
PENTEST · M
Perimeter + internal
~4–5 weeks

External pentest plus internal infrastructure: networks, AD, privilege escalation.

  • Post-exploitation scenarios
  • Map of critical attack paths
  • Free retest after fixes
Get a quote in 24 hours
PENTEST · L
Full-scope audit
timeline to fit scope

Web + API + infrastructure + K8s/cloud + GenAI components. Before an audit, a deal or a major release.

  • A report for the CISO and one for engineers
  • Findings walkthrough with your team
  • Retest and remediation plan
Get a quote in 24 hours
152-FZ · START
Express assessment
~2 weeks

An audit of personal-data processing: where you fall short and what that means in an inspection.

  • 152-FZ compliance checklist
  • Prioritized remediation plan
Get a quote in 24 hours
152-FZ · FULL
Turnkey package
~4–6 weeks

Assessment, threat model, the full document set, preparation for a regulator inspection.

  • All personal-data documents
  • Threat model
  • Regulator inspection readiness
Get a quote in 24 hours
[*] THE PRICE IS FIXED BEFORE WORK STARTS AND DOESN'T CHANGE WITHIN SCOPE

Izanagi finds
access-control flaws.

IDOR, BOLA, broken access control: one user reads or changes another's data. It's #1 in the OWASP API Security Top-10, and ordinary scanners miss it.

  • Two identities, not one: the scanner hits the API as both attacker and victim; an access flaw shows up when their responses differ
  • Proof in every finding: the victim's real data in the response, a risk level and a ready request to reproduce
  • Works from an API description: OpenAPI, HAR, nginx logs or a Postman collection; load sources together and they complement each other
  • Safe for a live environment: by default the scanner only reads, request rate is limited, traffic is tagged
7
products and testbeds checked
2 CVE
reproduced on real products
3
formats: demo, SaaS access, pilot in your environment

What we've already built.

Production B2B systems built for clients: AI does the heavy lifting, not the decorating.

CASE 01 / SALES AUTOMATION

Sales AI Assistant

An AI assistant for the sales team. It connects to amoCRM and Wazzup, reads the conversation and suggests the manager's next step.

amoCRM APIWazzupLLMRAGPython
  • Integration: amoCRM and Wazzup, on top of the existing stack
  • AI personality profiling: DISC and matching against similar deals
  • Probability score: chance of closing right now
  • Next step: a concrete action for the next 24 hours
  • Conversation analysis: what worked and how the manager runs communication
CASE 02 / CUSTOM CRM

CRM for an IT integrator

The CRM runs a deal from request to delivery, and a Telegram bot takes plain-language commands.

Telegram Bot APILLM (function calling)PostgreSQLFastAPIReact
  • Full cycle: request, estimate, approval, delivery, close
  • Telegram bot with AI: by voice: “start a project”, “find contractors”, “give a price”
  • Quote calculator and landing: the bot assembles an offer and sends the client a link
  • Document archive: everything from the client lives in the project card
  • AI logs and AI settings: model control inside the system

Where we test-drive ideas.

Our own B2C experiments: this is where we prove out Vision LLM, parsing and vibe-coding speed before bringing the approach to client projects.

Otmetkis
A place-saver bot: turns Instagram and TikTok links into collections with maps and tags.
@otmetkys_botVision LLMGeo APIs
Watch Analysis
Identifies a watch from a photo: reference, serial, valuation, stolen-goods database check.
@watch_analysis_botVision LLMOCR

Frequently asked questions.

How much does a pentest cost?
It depends on scope: the number of hosts and applications, and whether internal testing is needed. Send the details through the form — you'll get a fixed-price quote within 24 hours.
What do we get in the end?
A report with proven findings: PoC, risk level, reproduction steps and remediation guidance. After fixes — a free retest.
How is a GenAI pentest different from a regular one?
A classic pentest doesn't test attacks through the AI itself: prompt injection, agent jailbreaks, leaks through RAG. We test both the application and the model. You can start with a free 2-day express audit.
How do you handle our data?
An NDA before any details change hands, work strictly under contract and within the agreed scope, access revoked and data destroyed after the project.
Do you do 152-FZ end to end?
Yes: a personal-data systems assessment, a threat model, the full document set and regulator inspection readiness. An express assessment takes about 2 weeks to start with.
// ready to talk

Let's get
to work.

A security service, a product, or both. We'll assemble a team and propose a plan in 1–2 days.

A quote in 24 hours

Describe the task — we'll come back with a quote or a plan within a day. No calls unless you ask for one.