Pentesting para empresas y startups en Argentina y LATAM →

oktsec / Assessment

Pentesting for applications, APIs and AI agents.

Find security gaps before they expose data or disrupt operations. Penetration testing, source code review and AI red teaming for startups and enterprises, with an agreed scope and evidence your team can act on.

Founder’s security research

250+ security findings reported

GoogleMicrosoftStripeCloudflareAWSMercuryY Combinatorgbrain / gstackxAISpaceX
Reported through VRP, MSRC, HackerOne, GitHub and direct disclosure.
gbrain and gstack are open source projects by Garry Tan, president and CEO of Y Combinator.
See findings and fixes →

Public findings. Merged fixes.

Two contributions by Gustavo Aragón to Mercury and Stripe tools, with public reports, code and tests.

Mercurymercury-cli

Sensitive session information was exposed in logs.

Debug mode redacted sensitive request data but left response data visible. Cookies could end up in automation logs or shared reports.

Fix merged · May 14, 2026

Redact sensitive response headers as well, with tests to verify the fix.

View Mercury report and fix ↗
Stripelink-cli

Saving payment credentials could expose them to another user.

On a shared filesystem, a link prepared by another user could redirect the payment credentials file to a location that user could already read.

Fix merged · May 27, 2026

Create the file exclusively with restricted permissions and avoid writing through symbolic links. This protection applies to systems such as Linux and macOS.

View Stripe report and fix ↗

Contributions by @garagon merged into the official repositories. This is public research by the founder, not work commissioned by these companies.

He also reported findings and proposed fixes in gbrain ↗ and gstack ↗, open source projects by Garry Tan, president and CEO of Y Combinator.

What we test

Scope the systems. Test the attack paths.

Select the areas that match your environment. We connect weaknesses across applications, code and permissions to understand what an attacker could actually reach.

Assessment scope and the questions testing answers
AreaWhat we examineThe question we test
AI agents and LLM applicationsWhat we examineAgent runtimes, MCP tools, instructions, delegated access and connected systems.The question we testCan untrusted content trigger a privileged action or expose data?
Web application and API pentestingWhat we examineAuthentication, sessions, authorization, tenant isolation and business logic.The question we testCan one user reach another user’s data or perform an unauthorized operation?
Source code and dependenciesWhat we examineRepositories, architecture, third-party packages and CI/CD integrations.The question we testCan weaknesses in code or dependencies combine into a reachable attack path?
Cloud and infrastructureWhat we examineConfiguration, identities, credentials, permissions and network egress.The question we testCan an exposed secret or excessive permission lead to a critical system?

Applications, APIs and infrastructure can be assessed independently of AI agents.

Explore AI red teaming
From scope to correction

A defined engagement, with a clear handoff.

  1. 01

    Define the scope

    Agree the systems, environments, access, testing window and permitted actions. Set the deliverables and retest conditions before work begins.

  2. 02

    Test and confirm

    Exercise attack paths and confirm their impact with controlled evidence. Report critical findings through the agreed channel as they are confirmed.

  3. 03

    Remediate and retest

    Review priorities with your team, deliver the report and verify corrections to the original findings within the agreed retest window.

What you receive

Evidence to fix the risk. A record to explain it.

Give engineering the detail to act and leadership the context to prioritize.

Critical findings, reported early

Your team hears about confirmed critical findings through the agreed channel, without waiting for the final report.

Reproducible evidence

Steps, affected components and controlled proofs of concept that show how each finding was confirmed.

A prioritized correction plan

Findings ordered by impact, with concrete recommendations for code, configuration, architecture and permissions.

An executive summary

Scope, business impact and remediation priorities in language leadership can use to make decisions.

A shareable assessment record

A record of scope and dates for customer and audit requests, without sensitive findings. Documents the evaluation; it does not certify the absence of vulnerabilities.

One retest included

Verification of corrections to the original findings at no additional cost. Scope, environment and the request window are defined in the proposal.

After the first assessment

Keep testing as your systems change.

Continuous validation adds recurring evaluation of agreed systems and follows the changes that can introduce new risk.

Plan continuous validation

A separate recurring service, scoped around your systems and release cadence.

Scheduled evaluations

Reassess critical systems and workflows at a frequency agreed with your team.

Testing after changes

Review new releases, dependencies and permissions. For agents, include model, instruction and tool changes.

Follow-up on corrections

Verify fixes, document new findings and keep track of unresolved risks between cycles.

Testing conditions

Agree the access. Keep the work controlled.

Define environments, permitted actions and evidence handling before testing. Confirm the impact of a finding within the agreed limits.

Confirm and hold
Prove the path; don’t escalate without agreement.
Scoped targets
Stay inside the workflow and environments you authorize.
Controlled conditions
Designed for agreed environments; production only by explicit scope.
Full trail
Actions and evidence remain reviewable after the run.

Remote, at your offices or hybrid.

When your security requirements restrict remote access, we can scope work at your offices. Location, availability, access and evidence handling are agreed in the proposal.

For on-site or hybrid work, the client covers travel, accommodation and per diem expenses. Working and travel days are itemized and agreed before the engagement.

One assessment, shared priorities

A useful handoff for every team.

Security / AppSec

Confirmed findings, tested boundaries and unresolved risks to carry into the security review.

Engineering

Reproduction steps, affected components and practical fixes to take into the next release.

Risk / leadership

A summary of business impact, remediation priorities and the scope of the evaluation.

Before you start

Assessment questions.

Can you conduct testing at our offices?

Yes. Assessment can be delivered remotely, on site at your offices or through a hybrid arrangement. We agree access restrictions, evidence handling, location, availability and logistics in the proposal. For on-site or hybrid engagements, the client covers travel, accommodation and per diem expenses. Working and travel days, together with these expenses, are itemized and agreed in the proposal before work begins.

Do you include retesting and offer continuous validation?

Pentesting includes one retest of the original findings at no additional cost; the proposal defines the scope, environment and request window. Continuous validation is a separate recurring service that evaluates agreed systems after relevant changes and follows up on remediation.

Does Assessment include traditional penetration testing?

Yes. We scope pentesting for web applications and APIs, plus source code and architecture reviews. AI agent pentesting adds tools, MCP, credentials and execution paths when relevant. You do not need to use AI agents to engage Oktsec.

Do you work with startups and enterprises?

Yes. We scope each engagement around the systems, integrations and security requirements of your team. The proposal defines deliverables, timing, budget and the included retest conditions.

How is this different from an LLM red team or prompt injection test?

LLM red teaming and prompt injection testing examine model behavior. For agents, Assessment also tests what connected tools can do with data and permissions, beyond the model reply.

Is the free workflow check the same as Assessment?

No. The workflow check is a guided self review from your answers. Assessment is a scoped security engagement with controlled tests, reviewed findings and evidence.

Do you need production access or source code?

Scope is agreed per engagement. Many first runs use staging or a bounded environment. Do not send secrets in web forms.

What do we get at the end?

Reviewed findings, reproducible evidence, a prioritized correction plan, an executive summary and a shareable assessment record. One retest of the original findings is included under the conditions defined in the proposal.

How does Assessment connect to Oktsec Control and Cloud?

Assessment validates the workflow and priorities. Oktsec Control enforces policy at runtime. Oktsec Cloud operates policy, evidence and exceptions across environments.

Is it safe?

Runs are scoped, confirm and hold by default and produce a reviewable trail. Production is only in scope when you explicitly agree.

Know what is exposed. Know what to fix.

Tell us which application, API, repository or agent workflow you need to evaluate. We will define the scope, deliverables, timeline and budget with your team.