Pentests · AI & agent security · Compliance

Pass every security review.
For your software and your AI.

A big customer wants evidence or a pentest, NIS2 and the EU AI Act anyway. We test your systems with real pentests, fix the findings and deliver the proof your customer and the regulator accept. Including the layer almost no one tests: the AI agents and MCP servers you run in your company. Without a security team of your own.

// For companies shipping software or running AI agents · SMEs, startups, scale-ups
3 in 1
Test, secure and prove it, from one team
Fixed price
Fixed scope, fixed price, no army of consultants
Weeks
Results in weeks, not quarters
Security is no longer a once-a-year audit. Customers and regulators want it proven continuously.
Why CyberSec42 exists
How we work
·Fixed scope, fixed price.
·Experienced hands, not an army of juniors.
·A result you can hand over, not billed hours.
·Weeks, not quarters.
The problem

Suddenly you have to prove security. And no one on the team knows how.

A big customer sends a security questionnaire before signing, or asks for a pentest. Or NIS2 and the EU AI Act hit you, with deadlines and liability for management. Without a security team of your own, both quickly become deal-blockers. And an automated scan report is not enough: it prints a number, but neither your customer's procurement nor a regulator accepts it as proof.

28 flagged "critical" by the tool0 actually real, on review100% false positive
Automated scan · "critical" findings28 flagged
real problems, after expert review0 real
≠ proofa tool number full of false positives convinces neither customers nor auditors
What we take off your plate

Three things that belong together. From one team.

So you don't have to build a security team: we test your software and AI with real pentests, secure the gaps and get you through compliance. One contact, one fixed price, clear results.

Test

A real penetration test by experienced experts, not just an automated scan. We find the gaps in your software, cloud and AI/MCP systems and show them as clear findings your developers can fix.

Secure

We sort the findings by real risk and help you close the gaps, explained plainly, without jargon. So your software becomes provably safer, not just on paper.

Compliance

NIS2, ISO 27001 and the EU AI Act, step by step. The evidence comes out of the real security work, not a checklist, and we guide you up to the assessing body.

Our specialty

The most dangerous layer is the one almost no one tests.

Your company wires AI agents, copilots and MCP servers into your systems: into data, inboxes, files, payments, internal tools. Every one of those connections is a new way in. A poisoned tool call or an over-broad permission, and the agent does what the attacker wants.

Classic pentests and ISO audits don't touch this layer. We do, as one of the few.

Prompt injection & tool poisoning Over-broad agent permissions MCP servers & connections Data exfiltration via tools
Data Email Payments MCP server Internal tools Files AI agent !
97%of companies use AI
but only
37%have ever checked it for security
The proof gap

This is exactly the gap where the breach happens.

AI is rolled out faster than anyone checks its security. The same curve as cloud back then, only faster. We close the gap before someone exploits it.

Source: Tenable, State of Cloud & AI Security 2025
What sets us apart

Experienced people, a fixed price, evidence that counts.

01 / people

Reviewed by experts, not just by a tool.

A scanner reports hundreds of false positives. We review every finding by hand, sort by real risk and explain it so your developers can fix it.

every finding reviewed by handsorted by real risk
02 / predictable

Fixed scope, fixed price, results in weeks.

No open-ended consulting contract, no surprise on the invoice. You know up front what you get and what it costs, and you have it in weeks, not quarters.

fixed priceweeks, not quartersone point of contact
03 / evidence

Results your customer and your auditor accept.

You don't get the adjective "secure", you get evidenced findings, ready-made answers for security questionnaires and proof per requirement. And whatever is still open, we say so clearly.

finding → evidence → retestready-made questionnaire answers
What you get in the end

Not a vague opinion. A proof pack you can pass on.

After the review you have everything in hand to show your customer, your investor or a regulator that you are secure, instead of just claiming it.

Test report with all findings, sorted by risk and explained clearly.
A report to pass on that your customer's procurement or your investor accepts directly.
Ready-made answers for security questionnaires, so your next deal doesn't stall on them.
Evidence per requirement for NIS2, ISO 27001 or the EU AI Act.
A concrete action plan and a retest confirming the gaps are closed.
PROOF PACK
Security assessment · result
AI agents & MCPfixed
Web & APIfixed
Access & permissionsfixed
Secrets & dataverified
Delivers evidence for requirements from:NIS2ISO 27001EU AI Act
Verified · evidence attached
The operating model

Not a PDF. A system you run.

Software plus a fixed point of contact. Findings don't die in a report, they become evidence, developer tickets and decisions, and they stay current. This is how a team gets enterprise-grade security without building a whole internal security department.

01

Findings

Breadth and depth, in one calibrated ledger.

02

Evidence

Every claim mapped to the artifact that backs it.

03

Tickets

A prioritized backlog your developers can act on.

04

Decisions

Risk accepted, fixed or retested, on the record.

05

Continuous trust

A monthly cadence so posture never goes stale.

How we work with you

Clear outcomes. Not vague consulting.

Clearly defined services, from a first quick check to ongoing support. Each is scoped to your product and priced individually. Pick the entry point, the path to more is built in.

AI & MCP security

For teams shipping AI agents or MCP servers with real permissions. We check what your tools are allowed to do and where the trust boundaries are, the path from prompt injection to tool abuse, how credentials are handled and the runtime guardrails.

To the service page →

Deep review of critical functions

Some functions simply must not fail, such as encryption, access separation or billing. We review these with special care, every finding backed by traceable evidence rather than a mere claim.

Scoped individually · on request

Ready for your first major customer

The fast way to become credible for a big customer. Security check, trust-page draft, prepared questionnaire answers, evidence register, action plan and a 30/60/90-day roadmap.

To the service page →

Ongoing security support

Security goes stale the moment the first review is over. A monthly cadence of risk checks, evidence and retests keeps your security posture current, with clear reporting for management.

Scoped individually · on request

Consulting & compliance

Preparation for NIS2, ISO 27001, ISO 42001 and the EU AI Act. We find the gaps, build the controls and evidence and guide you up to the hand-off to the assessing body.

To the service page →

Manage external assessments

When you need an outside pentest or a formal audit, we define the scope, manage the delivery and fold the findings back into your ongoing support.

Scoped individually · on request
Who it's for

For SMEs, startups and scale-ups without a security team of their own.

SaaS & software vendorsAI agents & copilotsLegalTech & HealthTech FinTechFirst major-customer questionnaireInvestor reviewNIS2 / EU AI ActSensitive customer data
The first step

A free 30-minute call

No slides. We look at your real situation, tell you where you stand on security and compliance and what the most sensible next step is. Honestly, even if it is: you don't need us right now.

Step 1
Intro call, understand your situation, define the scope.
Step 2
We test, secure and prepare the evidence.
Step 3
Retest until clean, proof pack, hand-off to you.
Individual quote
Every engagement is scoped to your product and architecture. No packages, no list price, no surprises.
Book a free call
Straight answers

The questions companies ask us most.

Do I need my own security team for this?

No, that's exactly why we exist. We take on securing, testing and compliance and deliver results your developers can act on directly. You need no department of your own and no expensive individual consultants.

Do you also test our AI agents and MCP servers?

Yes, that's our specialty. We test exactly the layer classic pentests and ISO audits don't touch: what your agents are allowed to do, where prompt injection and tool poisoning strike, and whether a permission is scoped too broadly.

Is this a penetration test?

A pentest is part of it. We test your systems like an attacker, but go further: we secure, prepare the compliance evidence and keep supporting you, instead of dropping a report and disappearing.

What does it cost?

Every project has a fixed scope and a fixed price you know up front. We scope it to your product instead of billing open consulting hours. You get an individual quote after the free intro call.

Do you issue a certificate?

No, and we don't pretend to. We are your security and compliance partner and prepare everything so the official certification, such as ISO 27001, goes smoothly through the accredited body. Whatever is still open, we say clearly.

Secure and provable,
without your own security team.

In a free intro call we tell you where you stand and what the best next step is. Honestly, even if you don't need us right now.