HatchetSec is a penetration testing consultancy delivering web, API, cloud, infrastructure, IoT and social engineering assessments. Every engagement is run by senior, CREST-registered and OffSec-certified testers, with SC-cleared personnel available for government and regulated clients.
Every engagement is scoped, tested and reported by senior practitioners, not handed off to a junior queue. Clear, actionable findings, no fluff.
Manual, methodology-driven assessments of web apps and APIs covering OWASP Top 10, business logic flaws and authentication/authorization weaknesses.
Network-layer testing to identify exposed services, misconfigurations and paths to compromise across on-prem and internet-facing estates.
Adversary-emulation style assessments against cloud environments, identity misconfigurations and privilege escalation paths.
Assessment of embedded devices, firmware and industrial control system components against hardware and protocol-level attacks.
iOS and Android application assessments covering client-side storage, API communication and platform-specific weaknesses.
Realistic phishing campaigns and physical social engineering exercises to test people and process, not just technology.
HatchetSec is built around one principle: every engagement gets senior-level attention. Our testers bring backgrounds across web application, API, hardware/IoT, and internal/external infrastructure testing, including leading phishing campaigns and physical social engineering exercises.
We run every stage of an engagement ourselves: scoping, testing, quality assurance and reporting, so nothing gets handed off to a junior queue.
Outside of client work, our team is active in bug bounty and private vulnerability disclosure programmes, with vulnerabilities identified and resolved for high-profile companies and government entities, resulting in CVE assignments and recognition in vendor patch notes.
12+ industry certifications held across the team, spanning CREST (Registered Penetration Tester, Practitioner Security Analyst), Offensive Security (OSCP, OSWP, OSWA), Cyber Scheme (Team Leader, IoT/ICS Practitioner), HTB's Certified Web Exploitation Specialist, Practical Mobile Pentest Associate, plus cloud-focused red team certifications for AWS, Google and Azure.
Our testers discover and responsibly disclose vulnerabilities through bug bounty programmes and private invitations. A selection of resulting CVE assignments:
All engagements conducted under formal scope of work and written authorisation.