limited time — no vuln found = full refund. we're that confident.
feralsec_
book a pentest
// black-box red teaming · security research · automated pentesting

we break
your app
nicely.

Web apps, APIs, browser extensions — anything that speaks HTTP, we hunt. Black-box red teaming: no source access, no insider knowledge. We attack exactly like a real adversary would.

let us at it → what we do
the feralsec cat
chief exploit officer
does not do calls
312
criticals found
24h
scoping turnaround
0
sales calls required
webapps rest + graphql apis browser extensions auth flows ci/cd pipelines anything web, basically webapps rest + graphql apis browser extensions auth flows ci/cd pipelines anything web, basically
/services pick your poison
[01] // our specialization
api security
REST, GraphQL, gRPC-web — if it has an API, we can pentest it. We fuzz endpoints, abuse rate limits, and chain IDORs until your data model cries.
[02] // recon → exploit
web app pentest
Full-stack assault on your app: authz, injection, business logic, the weird stuff scanners miss. We do basically everything webapps.
[03] // plugins included
wordpress pentest
Core, themes, and that plugin nobody remembers installing. We audit the whole WP attack surface before it audits you.
[04] // mv3 minefield
extension audits
Browser extensions are a permission model minefield. Content scripts, message passing, everything that touches the DOM.
/engine our custom agentic framework
100s of agents. one target.
every angle at once.

We built our own agentic framework that deploys hundreds of autonomous agents against your app — each one running a frontier model, each attacking from a different angle. Auth, injection, business logic, race conditions, the weird stuff. The result: an audit more comprehensive than any human team could do in the same time.

unleash the swarm →
100s autonomous agents per engagement
1 frontier model behind every agent
100+ distinct attack angles, in parallel
→1 comprehensive report, human-verified
/process how the sausage gets shredded
01
scope
You tell us what's in bounds. We turn it around in 24 hours with a fixed quote. Black-box only — we start where a real attacker would: outside.
02
hunt
Automation maps the surface; researchers go feral on the interesting parts.
03
report
Repro steps, impact, PoC, fix guidance. Written for engineers, not auditors.
04
retest
Free retest on every finding. We don't leave until it's actually fixed.
/pricing no "contact sales" maze. mostly.
lite
$1.5k / engagement
A lighter audit of one app or API. Agent swarm + human triage, reported in days.
fixed scope, fixed price
full report + PoCs
no vuln = full refund
scope it
most feral
depth
$3k / engagement
The full swarm plus researcher deep-dive: business logic, auth chains, the weird stuff.
everything in lite
manual deep-dive
free retest on every finding
no vuln = full refund
go deep
custom
custom
Multiple products, compliance needs, or something weird. We like weird.
dedicated researchers
SOC2 / ISO evidence
custom SLAs
talk to a human
find the bugs
before the bad guys do_

Tell us what you're shipping. We'll scope it in 24h, no discovery-call purgatory. NDA-friendly, report samples on request.

dj@feralsec.com
~/feralsec/intake ● live