Pillar 01
Offensive Security
Web, Mobile, API, Cloud, and AI systems. We find what scanners miss. Reports engineers can act on immediately.
A boutique for companies that want things attacked, built, marketed, and shipped. Pentesting, AI agents, software engineering, websites, and social media from one team. No checklist audits, no slide-deck consulting.
$ ./engage --target client.tld --scope full $ agent.run(task="your workflow", model="claude-opus-4-7") $
Pillar 01
Web, Mobile, API, Cloud, and AI systems. We find what scanners miss. Reports engineers can act on immediately.
Pillar 02
From use-case discovery to a production agent. Claude, OpenAI, open source. With evals, guardrails, and cost telemetry.
Pillar 03
Software, hardware integration, cloud infrastructure, workflow automation. We build what you need, in the stack that fits your team.
Pillar 04
Websites, landing pages, social media, content systems, and marketing automation. We connect positioning, content, and technical delivery.
Security · ledger
AI · ledger
Services
Six security, four AI, four engineering, and four marketing/web offerings. Fixed scope, fixed price or retainer.
Authentication, authorization, business logic, GraphQL alias and introspection abuse, session audits.
Android and iOS. Static and dynamic. TLS pinning bypass, exported-component audit, deep-link hijack, Frida hooks.
REST and GraphQL. Rate-limit bypass, IDOR, enumeration oracles, auth-flow audit.
GCP, AWS, Azure. IAM and service-account review, metadata-SSRF chains, exposed Cloud SQL, Secrets Manager, BigQuery access paths.
Prompt injection, jailbreak resistance, RAG data leakage, guardrail validation, tool-use sandboxing.
Fake-WiFi / rogue-AP, targeted phishing campaigns, USB drop, vishing, physical pretext. Measurable awareness tests for staff.
One to two days. Identify use cases, estimate ROI, choose architecture and vendor.
Claude Agent SDK or Anthropic API. Tool use, prompt caching, clean integration with CRM, ERP, and ticketing systems.
Ingestion, embeddings, retrieval tuning, citations, eval framework for relevance and hallucination rate.
Eval suites, drift monitoring, cost telemetry, latency budgets, A/B tests for prompts and models.
Internal tools, web apps, APIs, dashboards. Full-stack TypeScript / Python / Go.
Embedded systems, edge devices, firmware, BLE / Zigbee / LoRa bring-up, OTA updates.
GCP / AWS / Azure. Infrastructure-as-Code, CI/CD, monitoring, secrets management.
Replace manual processes with scripts, jobs, event pipelines, or AI-hybrid agents.
Positioning, structure, copy, and technical delivery for websites, landing pages, and relaunches.
Content formats, editorial planning, posting workflows, and channel-specific execution.
Campaigns, performance content, SEO foundations, and measurable digital touchpoints.
Brand presence, launch communications, and the connection of design, content, and technology.
Content and publishing workflows, lead routing, campaign automation, and AI-assisted operations.
Process
Security
AI
Case Studies
Sanitized, methodology-focused, no client names without clearance.
Refresh-token survives rotation, access-token survives logout. High-severity finding from a 36-hour engagement.
Six exported activities without caller verification, cross-app UI hijack demonstrable with a zero-permission PoC.
Electron desktop app with task routing, agent teams, and prompt caching. 3,700 LOC TypeScript, running in production.
Document ingestion, retrieval tuning with citation handling, eval framework holding hallucination under 1 %.
Active projects
Products, systems, and automations from the current Endemine ecosystem.
A paperwork alternative for solo founders and growing teams.
News CMS and automated publishing pipeline for Endemine.
Lightweight accounting for Estonian OÜs, e-residents, and FIEs.
AI-powered collection management, card scanning, and pricing for TCGs.
Short scoping call, clear proposal, kick-off in two to four weeks.
Start the conversation