oktsec

Oktsec Assessment · AI Security

Pentesting for enterprises and startups.

Pentesting for AI agents, web applications, APIs and infrastructure, with evidence and a clear remediation plan.

Based in Argentina, serving Latin America. Before a launch, an audit or a customer security review.

The Oktsec octopus investigates the security of a server and an access mechanism from its computer.

250+ security findings reported

GoogleMicrosoftStripeCloudflareAWSMercuryY Combinatorgbrain / gstackxAISpaceX
Reported through VRP, MSRC, HackerOne, GitHub and direct disclosure.
gbrain and gstack are open source projects by Garry Tan, president and CEO of Y Combinator.
See findings and fixes →
Gustavo Aragón, founder of Oktsec

The experience behind Oktsec

Gustavo Aragón · Founder

Cybersecurity entrepreneur focused on AI agent security. Over 20 years in technology, including 12 as CTO. Ambassador for the Agentic AI Foundation (AAIF), part of the Linux Foundation.

View LinkedIn (opens in a new tab)

Founder’s research · 2026

Public findings. Merged fixes.

Two contributions by Gustavo Aragón to Mercury and Stripe tools, with public reports, code and tests.

Mercurymercury-cli

Sensitive session information was exposed in logs.

Debug mode redacted sensitive request data but left response data visible. Cookies could end up in automation logs or shared reports.

Fix merged · May 14, 2026

Redact sensitive response headers as well, with tests to verify the fix.

View Mercury report and fix ↗
Stripelink-cli

Saving payment credentials could expose them to another user.

On a shared filesystem, a link prepared by another user could redirect the payment credentials file to a location that user could already read.

Fix merged · May 27, 2026

Create the file exclusively with restricted permissions and avoid writing through symbolic links. This protection applies to systems such as Linux and macOS.

View Stripe report and fix ↗

Contributions by @garagon merged into the official repositories. This is public research by the founder, not work commissioned by these companies.

He also reported findings and proposed fixes in gbrain ↗ and gstack ↗, open source projects by Garry Tan, president and CEO of Y Combinator.

What we test

What we put to the test.

We assess your applications, agents and infrastructure to identify risks and define how to fix them.

Pentesting scope, tests and risks assessed
AreaWhat we testWhat we look for
AI agent pentestingAI red teaming for LLM applications, MCP tools and instructions received by agents.Data exposure, task hijacking and actions beyond authorized permissions.
Web application and API pentestingAuthentication, sessions, access controls and business logic.Access to other customers’ information and operations without the required permissions.
Repositories and architectureCode, dependencies, integrations and system design.Vulnerabilities that can be chained to compromise the system.
Infrastructure, credentials and permissionsCloud configuration, secrets management and access permissions.Exposed credentials, accessible resources and excessive permissions.

After the first pentest

Continuous security validation.

An initial pentest followed by assessment cycles as your agents, applications and infrastructure evolve.

Scope a recurring assessment ↓
Periodic testing
We reassess critical systems and workflows on a schedule agreed with your team.
Validation after changes
We test new releases, integrations and permissions. For AI, this includes changes to models, instructions and tools.
Remediation follow-up
We verify fixes and document new findings and unresolved risks in each cycle.

The proposal defines the frequency, systems covered and changes that trigger a new assessment.

Before requesting a proposal

Define your pentest scope.

Choose your systems, size and goal. Then send us your scope to receive a proposal.

Prefer to talk directly?
Tell us what you need

  1. 1Scope
  2. 2Size
  3. 3Goal
  4. 4Contact

1 of 4 · Scope

What would you like to test?

You can choose more than one option.

Systems to assess

What you receive

What your pentest includes.

To address risks and report to leadership, customers and auditors.

Critical finding alerts
We notify you as soon as a critical finding is confirmed, without waiting for the final report, through the channel agreed with your team.
Executive summary
Scope, risks and priorities in plain language so leadership can make decisions and track progress.
Pentest attestation letter
A shareable document with scope and dates for customers, audits and procurement, without sensitive details. It confirms the assessment was performed; it does not certify the absence of vulnerabilities.
Report and remediation plan
Findings prioritized by impact, with specific recommendations for code, architecture, permissions and controls.
Reproducible evidence
Descriptions, steps and controlled proofs of concept to reproduce each finding. For AI, we document the instructions, tools and permissions involved.
One retest included
We verify fixes for the original findings at no extra cost. The proposal defines the scope, environment and request window.

Turn findings into fixes.

Request a pentest

Recent industry cases

Disclosures from August and September 2026

MetabaseAug 6, 2026 · Applications and APIs

From an application flaw to connected databases.

Metabase confirmed an attack that could allow administrator access, theft of connected database credentials and data export. It released patched versions.

Metabase advisory ↗
SnowflakeAug 17, 2026 · Code and integrations

A public issue opened access to internal Jira.

Wiz demonstrated that a GitHub Actions flaw could expose a credential and allow access to internal information. Snowflake fixed the workflow and revoked the credential; the disclosure describes a research test.

Wiz research ↗
GitSpawnSep 1, 2026 · AI agents

Opening a project could run code before approval.

Manifold documented flaws in coding agents when opening folders containing malicious Git configuration, such as folders received in a ZIP. Some executed code before user approval. Fix status varies by agent.

Manifold research ↗

Third-party cases with original sources. Dates refer to public disclosure. These are not Oktsec clients or findings.

How to get started

Three steps to get started.

  1. Scoping conversation

    Tell us which system you want to assess, its integrations and your assessment goals.

  2. Proposal and authorization

    You receive the scope, exclusions, schedule and price. We begin with your authorization.

  3. Testing and findings review

    We run the tests and review findings with your team to prioritize fixes.

Before you start

Frequently asked questions.

Can you conduct testing at our offices?

Yes. We can arrange remote pentesting and assessments, on-site testing at your offices or a hybrid approach. If your policy restricts remote access or information leaving your environment, we agree how to work within it. The proposal confirms location, availability, access and logistics. For on-site or hybrid engagements, the client covers travel, accommodation and per diem expenses. Working and travel days, together with these expenses, are itemized and agreed in the proposal before work begins.

What is pentesting, and what does Oktsec deliver?

Pentesting, or penetration testing, checks whether a vulnerability can lead to data access or unauthorized actions. Oktsec runs controlled tests within the agreed scope and delivers findings, reproducible evidence and remediation priorities.

Can I book a pentest if my company does not use AI agents?

Yes. We test web applications, APIs, code, architecture and permissions. If your company also uses AI agents, we can include their workflows and tools in the scope.

Do you offer pentesting for startups and enterprises?

Yes. We work with enterprises and startups in Argentina and Latin America, both before a launch and on systems already in operation.

How much does a pentest cost, and how long does it take?

Pricing and timing depend on the applications, APIs, repositories, workflows and environments in scope. We agree on scope and deliverables first; testing starts once you authorize the work.

What do we need for an initial conversation?

A description of the system, workflows or repositories to test, their integrations and the reason for the assessment. Access and technical documentation are arranged later; do not send credentials through the form.

Is remediation verification included?

Yes. One retest of the original findings is included at no extra cost. The proposal defines which findings will be verified, the environment and the request window. New systems or changes outside the original scope are assessed separately.

Do you need production access?

Not necessarily. We can start in staging or a bounded environment. Code and system access are agreed for each assessment. Production testing requires explicit authorization.

Is continuous validation the same as a retest?

No. A retest verifies fixes for the original findings. Continuous validation adds assessment cycles covering the agreed scope and its changes, to identify new risks and track unresolved findings. Frequency and terms are defined in the proposal.

What happens after the assessment?

Your team implements the fixes and we coordinate the retest. If you use AI agents, we can also assess runtime controls with Signal and Control.

Let’s talk about your environment

What do you need
to test?

Tell us what you want to protect or which requirement you need to meet.

Request a pentesting proposal.

A brief description is enough to get started.

Do not include credentials, private code or customer data.

A platform beyond the pentest

We also protect your agents at runtime.

Control acts on requests routed through configured integrations. The assessment does not require purchasing other products.