Penetration testing by certified ethical hackers

We find security issues before the bad guys do

to prevent any negative business impact.

Our services

Practical security help for growing teams

From hands-on offensive testing to team training and phishing resilience, we help you find risk, fix it, and build security habits that last.

Penetration testing

Manual, attacker-minded testing for web applications, APIs, and infrastructure. We uncover exploitable issues, explain the business impact, and give your team a clear path to remediation.

  • Web application, API, and infrastructure testing
  • Actionable report with recommended mitigations
  • Retest and Letter of Attestation when needed

Security awareness training & phishing simulation

A productized program to strengthen your human firewall with engaging awareness training and realistic phishing simulations your team can learn from.

  • Awareness content for everyday security decisions
  • Phishing simulations and measurable outcomes
  • Designed as an ongoing, repeatable product

Security workshop

Focused security workshops for engineering, product, and leadership teams. Delivered online or in-person, tailored to your stack, risks, and the questions your team needs answered.

  • Online or in-person delivery
  • Practical examples and real-world attack paths
  • Details and agenda shaped together

Testimonials

“I worked with Greg to go through all my sites and apps and make sure they are safe. I love being a scriptkiddie hacking together and shipping fast but security is nothing to be fast about because you hold user's data and have to keep that safe. Having Greg pentest everything, audit my code and follow his recommendations helps me sleep a bit better at night.”

Pieter Levels

“When I was planning on making Keygen open source, getting a penetration test and security audit was a major prerequisite. I knew Greg was a great choice, with his deep understanding of Ruby and of Rails. Greg completed the security audit according to schedule, and with his help and recommendations, I was able to successfully patch the issues he found. When it comes to security, I highly recommend Greg and Spektr.”

Zeke Gabrielse
Founder of Keygen

“Tens of thousands of students and many universities rely on our software each semester to provide course content, assessments and grades. It is critical that we provide a service that is secure and reliable to each stakeholder involved. For a small team without specific security expertise, we knew (and were strongly encouraged by our partners) we needed to get a reliable security audit and penetration test to make sure all of our systems were as secure as possible. Greg's expertise was evident from our first meeting. He meticulously audited our systems, identifying vulnerabilities with precision. His insightful recommendations were invaluable, allowing us to fortify our digital infrastructure effectively. Greg's thorough approach to security has not only enhanced our systems but also given me and all of our partners a peace of mind. For anyone seeking top-notch security solutions, I wholeheartedly recommend Greg and Spektr.”

Jess Brown
Co Owner, CSePub.com

"As an eSignature software platform, protecting customers data is our utmost priority. Greg's expertise in Ruby on Rails played a critical role in strengthening the security of our application. His meticulous approach and comprehensive audits made it easy to identify and address potential vulnerabilities. Also, Greg's responsiveness ensured a smooth process from start to finish. We recommend his services to anyone who needs a Ruby on Rails penetration test."

Pete Matsyburka
Co-founder, DocuSeal

“As our data-heavy SaaS grew, more and more customers were requesting a 3rd-party security audit. In our search for a security expert with Rails experience, Greg Molnar was the obvious choice. Working with him was easy, and he freely gave his time to answer our questions. His audit was quick but thorough, and he helped us solve the issues he found. Our increased confidence translates directly into greater peace of mind for our customers. Greg Molnar and Spektr is an easy recommendation.”

Eric Hayes
MortarStone CTO

Certifications we hold

Our team holds a few cyber security certifications.

Penetration testing

OffSec Certified Professional

OSCP is considered to be more technical than other ethical hacking certifications and is one of the few that requires evidence of practical penetration testing skills.

Security Operations

Blue Team Level 1

Earners of the Blue Team Level 1 Certification have showcased their practical ability to defend networks and systems from cyber threats through technical and hands-on defensive cybersecurity training. They have knowledge and ability across 5 security operations domains which include Phishing Analysis, Digital Forensics, Threat Intelligence, SIEM, and Incident Response.

Contact us

We're here to help

If you are looking for a penetration test, a security audit, help with ISO 27001, SOC2, HIPAA or another compliance, or just want to have a chat about your security challenges, reach out and we can discuss how we can help.