The request returned 200. The audit log recorded nothing. The object belonged to another account. We review the layer where failure is quiet — web applications, APIs, identity, and the infrastructure underneath them.
What we review
A scanner reports what it recognises. The request that succeeds for the wrong account, the token accepted after it should have expired, the object returned because nobody checked who asked — those are failures of logic, and logic has to be read. We work in the application, in the code behind it, and in an environment we control, and we prove the failure end to end before we write it down.
Our findings come from client engagements and from public bug bounty programs across commerce, fintech, exchanges and infrastructure.
Authentication and authorization, horizontal and vertical access control, injection, server-side request forgery, business logic abuse.
REST and GraphQL. Object-level authorization, mass assignment, enumeration, missing or bypassable rate limits.
OAuth, OIDC and SAML configuration, federation and trust boundaries, session handling, account recovery flows.
Over-permissioned IAM, public storage, exposed metadata services, security group scope, tenant isolation.
Network segmentation, exposed administrative interfaces, patch posture, internal services reachable from outside.
Manual review informed by static analysis, where logic defects surface and scanners do not reach.
Dependency and artifact integrity, build pipelines, signing, secrets exposed in public history.
Where it matters we go all the way down: consensus engines, node clients in Rust, remote signers, smart contracts. Few teams read that code. It is where we started.
Method
We run instructed agents across each surface, because a review whose coverage depends on how long one person stays sharp is a review with gaps in it. What comes back is a list of candidates. Everything after that is what makes a report worth acting on.
Most reports assert. Ours measure, and they record what the measurement could not establish.
The failure taxonomy of a consensus engine is not the taxonomy of a GraphQL API. Each agent carries its surface's own vocabulary, its known failure shapes, and an explicit list of the things it is not permitted to conclude without a measurement.
Nothing an agent concludes enters a report before a person reproduces it by hand. A negative result is treated as the limit of that run, never as evidence that nothing is there — a sweep that swallowed its own errors is a lower bound, not an answer.
A result without a baseline in the same cycle is discarded. A four-arm causal split isolates the cause instead of naming a correlation.
When a path we expected to reach impact does not reach it, that goes in the report, against our own interest. Anyone acting on our work needs to know where the boundary actually sits.
New container, stock image, binary verified by hash, the reproduction steps executed from zero exactly as the reader would run them.
Line-level references into the code under review, and classification taken from the registry itself rather than from memory. The person who checks a citation is never the person who wrote it.
Services
Engagements open with surface mapping: asset discovery, subdomain enumeration, certificate transparency, exposed services and shadow IT. The real inventory, not the one on the spreadsheet.
From there each layer is tested with the method it requires, and the engagement closes with a report built to be fixed rather than filed — every finding with an executable reproduction chain, a justified severity, the technical reason it is exploitable, and the correction at the level of code or configuration.
External and internal. Web applications, APIs, cloud environments and network infrastructure. Scoped and time-boxed against a written rules-of-engagement document, with a named point of contact on both sides for the duration.
Objective-based adversarial testing. Instead of enumerating defects we pick a goal a real attacker would pursue and work toward it, which also tests whether your detection and response notice.
Architecture, configuration and access model reviewed against the threat model you actually have, rather than a generic checklist.
Manual review informed by static analysis, in the languages the system is written in. Where logic defects live and scanners do not reach.
Consensus engines, node clients, remote signers and Solidity. Rust and EVM. The layer most assessments stop short of.
Included in every engagement. A finding is closed when the fix is verified, not when the report is delivered.
Disclosure
Zyrone Security has worked with these companies, helping make them more secure.
Contact