Offensive security team. Enterprise only.
We are a small, selective and intentionally focused team. We work exclusively with corporate clients on pentest, Red Team and cloud audit.
We know attackers' methods. We use that in your favor.
Most security reports in the market are bad. Long, generic, full of scanner findings and with no translation to business decision. They generate anxiety in the CISO and get ignored by the board.
We were born to do it differently: deliver the artifact the risk committee understands, prioritized by impact, with evidence that external audit accepts — and with engineering knowing exactly which line to change.
Offensive security is about anticipation. If we're going to be the adversary, let it be as rigorous and ethical as possible.
How we operate
[04 commitments]Clarity, not fear
We don't sell panic. We deliver the exact map of what is exploitable today, what it costs when exploited and the shortest path to close it.
Secrecy by design
NDA before the first handshake, encrypted channel for delivery and certified destruction of artifacts at project end.
Auditable method
Every engagement follows a replicable pipeline. Signed evidence, calculated CVSS, documented chain of custody.
Ethics with no gray area
Formal authorization, documented scope, signed rules of engagement. We operate with the discipline that boards and auditors recognize.
Milestones
[timeline]- / 2018
Founding
Born from a team of senior pentesters tired of noise-reports with no translation for the board.
- / 2020
Red Team
We launch full-scope adversarial operation. First engagements in fintechs and healthtechs.
- / 2022
Cloud Practice
Specialization in AWS, Azure and GCP audit with proprietary scripts + CIS Benchmarks.
- / 2024
200 engagements
Milestone of 200 engagements delivered. 99% enterprise satisfaction, zero production incident attributed to Basilisk.
- / 2026
Volucer Group
Basilisk consolidates as the offensive security brand of Volucer Group, with dedicated operation and elite team.
Lean team. Real certifications.
What happens from first contact to delivery
No stage depends on you guessing what comes next. The flow below is the same for pentest, red teaming and cloud audit; only the depth of each phase changes.
Scoping conversation
A meeting to understand what exists, what worries you and what has been tested before. We leave it with a written scope proposal — what is in, what is out and why. A badly defined scope is the most common reason a test fails to answer the question that prompted it.
Agreements and access
Confidentiality signed, rules of engagement agreed and test credentials created for each role. We also set windows, emergency contacts on both sides and the criterion that halts execution if anything goes off plan.
Execution with an open channel
Throughout the work there is a direct line to your technical team. Critical findings do not wait for the report: they are raised on the spot, with the minimum you need in order to act. A blocker or a scope question is resolved in hours, not at next week's meeting.
Report and walkthrough
Delivery comes in two readings: an executive one for whoever sets priority and budget, and a technical one, reproducible step by step. We present the result live, because the conversation usually clarifies more than any paragraph.
Remediation and retest
We stay available for questions during remediation — often the difficulty is not understanding the flaw but choosing between two ways to fix it. Afterwards we retest the treated items and record the final state in a closing letter.
How the report is written
The report is the product. If it goes unread or cannot be reproduced, the whole test loses its point — and that is where most security work falls down.
- two separate readings
- The executive part carries no jargon and fits in a few pages: what was tested, what represents risk and what needs a decision. The technical part follows, in full detail. Nobody has to wade through one to reach the other.
- complete reproduction
- Each finding carries the path step by step, with request, response and evidence. Whoever fixes it needs no clarification and no dependency on the person who ran the test.
- impact before score
- The technical rating appears but does not decide on its own. The text describes what the flaw allows in your context, because the same score means different things in different systems.
- priority with effort
- The suggested order accounts for remediation cost, not only severity. A list ordered purely by severity tends to start with the most expensive item and stall everything behind it.
How we conduct the work
Offensive security is a trust business: you hand over access to your most sensitive assets. These commitments apply to every engagement and sit in the contract.
Everything seen during an engagement is covered by a confidentiality agreement, including the existence of the engagement itself. No material is used as a commercial reference without written authorisation.
We work with the minimum data needed to demonstrate risk. We do not extract a real dataset when a sample proves the same point, and collected material is destroyed at the end of the agreed period.
Nothing outside scope is touched, even when it looks reachable and tempting. If something relevant appears on the outside, it is reported for you to decide — not tested on our own initiative.
Demonstrating impact does not require causing it. Destructive actions, downtime and modification of real data stay out, unless explicitly requested with an agreed window.
When social engineering is in scope, the result measures the effectiveness of the control and the process. No result is individualised for disciplinary purposes.
We do not sell the tooling we recommend, and the recommendation does not shift with the vendor. If the best fix is something we do not do, that is what the report says.
Frequently asked questions
The scope adjusts. A single application with a handful of user roles is a short, well-bounded piece of work; an estate with dozens of systems and several cloud accounts is another size entirely. What does not change is the method — manual validation of every finding and a reproducible report.
A confidentiality agreement is signed before any access, covering the engagement material and the existence of the engagement itself. You decide whether and how the result may be mentioned; without written authorisation, nothing is used as a reference.
You hear about it the same day. The stop criterion is agreed before the start precisely for this: a critical finding does not wait for the report, and where the case demands it, execution pauses until containment is in place.
We guide the fix and stay available during it, including to discuss the trade-off between two possible routes. Implementation stays with your team or your supplier — the tester and the fixer being the same party weakens the value of the test.
Yes. It is common for a test to be required by an enterprise customer, with the format and deadline set by them. In those cases the report and closing letter are prepared to serve as direct evidence in that process, with no further translation.
Want to operate with a team like this by your side?
Free scoping call, covered by NDA. Within 48h you receive proposal, scope and timeline.