We help early teams solve the security problems that actually threaten the company: the ones scanners miss and generalist firms won't touch.
Prefer a free start? Get the AI security playbook.
Offensive security engineers · AI-native attack surface · Critical findings in hours, not weeks
Don't take it from us.
“You showed up and got the job done in a couple of days, and you offered to come onsite, which not a lot of people do.”
“You were fast and thorough. The findings are extremely well documented and hard to dispute.”
“What you're especially good at is reframing individual issues and showing how they chain together, a higher order of reasoning I don't see when you just run security scans via Claude Code.”
Auth boundaries. AI features nobody's attacked yet. Pre-enterprise diligence. Post-incident cleanup.
Penetration testing
Real web app and API offensive work: tenant auth, business logic, payments, with engineer-ready findings.
AI & agent attack surface
Prompt injection, tool abuse, forged channels (SMS, email, voice), and the paths scanners never see.
When something's already on fire
High-stakes reviews, customer security questionnaires, and help when a finding or incident can’t wait.
Real exploit paths. Impact. What to fix first.
Lower commitment. Still useful before you email us or book a pentest.
Also covered in the playbook
Testing the API, ignoring SMS, voice, and tools
Attackers do not stop at your REST endpoints. If your agent reads email, takes phone calls, or calls tools, each channel is an entry point.
Treating prompt injection as a content filter problem
Sanitizing user text is not enough. Image payloads, forged webhooks, and chained tool calls bypass filters. Test full exploit paths, not single inputs.
Shipping agents on the same auth model as your dashboard
Agents often run with broad credentials. One missing check on a tool endpoint can expose customer data or trigger actions as the agent.
Email hello@pigeonlabs.ai. Tell us what's hard. We'll tell you if we can help.