CREST Accredited · OffSec Certified

Offensive security testing that finds what matters, before someone else does.

HatchetSec is a penetration testing consultancy delivering web, API, cloud, infrastructure, IoT and social engineering assessments. Every engagement is run by senior, CREST-registered and OffSec-certified testers, with SC-cleared personnel available for government and regulated clients.

What we do

Services

Every engagement is scoped, tested and reported by senior practitioners, not handed off to a junior queue. Clear, actionable findings, no fluff.

01

Web Application & API Testing

Manual, methodology-driven assessments of web apps and APIs covering OWASP Top 10, business logic flaws and authentication/authorization weaknesses.

02

Internal & External Infrastructure

Network-layer testing to identify exposed services, misconfigurations and paths to compromise across on-prem and internet-facing estates.

03

Cloud Red Team (AWS & Azure)

Adversary-emulation style assessments against cloud environments, identity misconfigurations and privilege escalation paths.

04

Hardware & IoT / ICS

Assessment of embedded devices, firmware and industrial control system components against hardware and protocol-level attacks.

05

Mobile Application Testing

iOS and Android application assessments covering client-side storage, API communication and platform-specific weaknesses.

06

Phishing & Social Engineering

Realistic phishing campaigns and physical social engineering exercises to test people and process, not just technology.

Who we are

About HatchetSec

HatchetSec is built around one principle: every engagement gets senior-level attention. Our testers bring backgrounds across web application, API, hardware/IoT, and internal/external infrastructure testing, including leading phishing campaigns and physical social engineering exercises.

We run every stage of an engagement ourselves: scoping, testing, quality assurance and reporting, so nothing gets handed off to a junior queue.

Outside of client work, our team is active in bug bounty and private vulnerability disclosure programmes, with vulnerabilities identified and resolved for high-profile companies and government entities, resulting in CVE assignments and recognition in vendor patch notes.

10+
Years combined offensive security experience
Multiple
CVEs assigned from independent research
Credentials

Certifications

12+ industry certifications held across the team, spanning CREST (Registered Penetration Tester, Practitioner Security Analyst), Offensive Security (OSCP, OSWP, OSWA), Cyber Scheme (Team Leader, IoT/ICS Practitioner), HTB's Certified Web Exploitation Specialist, Practical Mobile Pentest Associate, plus cloud-focused red team certifications for AWS, Google and Azure.

Proof of work

Vulnerability Research & Track Record

Our testers discover and responsibly disclose vulnerabilities through bug bounty programmes and private invitations. A selection of resulting CVE assignments:

Let's talk about your security posture

All engagements conducted under formal scope of work and written authorisation.

Email us jac.julian@hatchetsec.co.uk United Kingdom