§ 08

Marxen Security

A report that ends in an exploit, not a warning.

Most security reports hand you findings ranked by a scanner's opinion. Ours hand you the request that got through, the data it reached, and the fix.

§ 01

What we run

Bastion

Bastion does penetration testing.

The backs of a rack of one-unit web servers in a colocation data centre in Tampa, a network cable plugged into each, a bundle of cables down the left and power cords down the right, rack positions 27 to 31 numbered on the rail
Tampa · web servers and their network cables
  1. Agents read your source,

  2. plan attack paths,

  3. and execute real exploitation against

    • injection,
    • cross-site scripting,
    • server-side request forgery and
    • authorisation flaws

    through browser automation.

You get proof by exploitation, with a reproduction path your engineers can follow.

Perimeter

Perimeter does exposure assessment.

A data centre in Hillsboro, Oregon, seen from the public pavement: a closed steel gate in a palisade fence, a card reader on a post just inside it, the glass entrance with a camera above it beyond, a pickup truck parked by the wall
Hillsboro, Oregon · a data centre's gate from the street
  1. Which of your credentials already sit in breach corpora.

  2. Which employee accounts are enumerable across public platforms.

  3. What an attacker can assemble about your organisation before touching anything you own.

§ 02

How it engages

  1. A scoped contract,
  2. written authorisation naming the systems in scope,
  3. a named client contact
  4. and a defined test window.
The execution page of a printed contract: blank lines for signature, name, title of representative and date of signature, a fountain pen resting beside them, clauses of terms around
Contract · the signature block, unsigned

We do not run this self-serve and we do not run it without that paperwork.

The authorisation letter is what separates a penetration test from a crime.

Built in India. For the people actually using it.

Tell us what you are trying to do. Bring the use case, the constraints and the users. We will tell you honestly whether Marxen is the right call, including when the answer is no.