Nothing looked wrong.

The request returned 200. The audit log recorded nothing. The object belonged to another account. We review the layer where failure is quiet — web applications, APIs, identity, and the infrastructure underneath them.

surfacelive requests12480 services7/7 authzenforced feedsimulated

What we review

The defects that a scan will never return.

A scanner reports what it recognises. The request that succeeds for the wrong account, the token accepted after it should have expired, the object returned because nobody checked who asked — those are failures of logic, and logic has to be read. We work in the application, in the code behind it, and in an environment we control, and we prove the failure end to end before we write it down.

Our findings come from client engagements and from public bug bounty programs across commerce, fintech, exchanges and infrastructure.

web applications

Authentication and authorization, horizontal and vertical access control, injection, server-side request forgery, business logic abuse.

APIs

REST and GraphQL. Object-level authorization, mass assignment, enumeration, missing or bypassable rate limits.

identity

OAuth, OIDC and SAML configuration, federation and trust boundaries, session handling, account recovery flows.

cloud

Over-permissioned IAM, public storage, exposed metadata services, security group scope, tenant isolation.

infrastructure

Network segmentation, exposed administrative interfaces, patch posture, internal services reachable from outside.

source code

Manual review informed by static analysis, where logic defects surface and scanners do not reach.

supply chain

Dependency and artifact integrity, build pipelines, signing, secrets exposed in public history.

protocol

Where it matters we go all the way down: consensus engines, node clients in Rust, remote signers, smart contracts. Few teams read that code. It is where we started.

Method

A finding is only worth what its proof is worth.

We run instructed agents across each surface, because a review whose coverage depends on how long one person stays sharp is a review with gaps in it. What comes back is a list of candidates. Everything after that is what makes a report worth acting on.

Most reports assert. Ours measure, and they record what the measurement could not establish.

brief
One brief per surface, written for that surface

The failure taxonomy of a consensus engine is not the taxonomy of a GraphQL API. Each agent carries its surface's own vocabulary, its known failure shapes, and an explicit list of the things it is not permitted to conclude without a measurement.

hypothesis
An agent's verdict is a hypothesis

Nothing an agent concludes enters a report before a person reproduces it by hand. A negative result is treated as the limit of that run, never as evidence that nothing is there — a sweep that swallowed its own errors is a lower bound, not an answer.

control
Every arm runs against a control

A result without a baseline in the same cycle is discarded. A four-arm causal split isolates the cause instead of naming a correlation.

negative
Measured negatives are published as negatives

When a path we expected to reach impact does not reach it, that goes in the report, against our own interest. Anyone acting on our work needs to know where the boundary actually sits.

repro
Reproduced in a clean room before it is sent

New container, stock image, binary verified by hash, the reproduction steps executed from zero exactly as the reader would run them.

source
Every citation checked at the primary source

Line-level references into the code under review, and classification taken from the registry itself rather than from memory. The person who checks a citation is never the person who wrote it.

Services

Mapped, tested, written down, retested.

Engagements open with surface mapping: asset discovery, subdomain enumeration, certificate transparency, exposed services and shadow IT. The real inventory, not the one on the spreadsheet.

From there each layer is tested with the method it requires, and the engagement closes with a report built to be fixed rather than filed — every finding with an executable reproduction chain, a justified severity, the technical reason it is exploitable, and the correction at the level of code or configuration.

penetration testing

External and internal. Web applications, APIs, cloud environments and network infrastructure. Scoped and time-boxed against a written rules-of-engagement document, with a named point of contact on both sides for the duration.

red teaming

Objective-based adversarial testing. Instead of enumerating defects we pick a goal a real attacker would pursue and work toward it, which also tests whether your detection and response notice.

security assessment

Architecture, configuration and access model reviewed against the threat model you actually have, rather than a generic checklist.

secure code review

Manual review informed by static analysis, in the languages the system is written in. Where logic defects live and scanners do not reach.

protocol & smart contract review

Consensus engines, node clients, remote signers and Solidity. Rust and EVM. The layer most assessments stop short of.

retesting

Included in every engagement. A finding is closed when the fix is verified, not when the report is delivered.

Disclosure

AmazonCrypto.comShopifyOKXArc

Zyrone Security has worked with these companies, helping make them more secure.

Contact

Tell us what you are shipping.