SUSPECTED A BREACH?  INCIDENT RESPONSE  contact@katitisecurity.com
VICTORIA +04 MAHÉ · SEYCHELLES
Offensive security · Seychelles

Offensive
Security.
Indian Ocean.

We test the region's most critical systems the way a real adversary would, then hand you a report your board and your engineers can both act on.

OWASP · PTESAligned methodology
CVSS v4.0Every finding scored
Evidence-ledNothing theoretical
// 01

Most breaches do not begin with genius. They begin with a default password nobody changed, an endpoint left open, a secret hiding in plain sight.

We find those first, before someone with worse intentions does. Then we make sure they stay closed.

// 03   What we test

The weaknesses that quietly open the front door.

Individually these look minor. Chained together, they are how a breach actually happens. Every engagement hunts all six.

Authentication & access

Default or unchanged credentials, weak session handling, and privilege boundaries that can be crossed.

API security

Exposed endpoints, data returned without login, and API blueprints that hand an attacker your whole map.

Secrets & exposure

Hardcoded keys, passwords, and tokens sitting in client-side code where anyone can read them.

Transport & configuration

Weak TLS, permissive CORS, and development settings left switched on in production.

Sessions & business logic

CSRF gaps, token abuse, and logic flaws that no automated scanner will ever catch.

Platform & infrastructure

Application servers, cloud posture, and the fingerprints that tell an attacker exactly what you run.

// 04   From the field

Real findings. Real severity. Names withheld.

A sample of what we have surfaced during authorised assessments. Every detail that could identify a client has been removed.

CriticalCVSS 9.8

Factory credentials on the authentication service

A highest-privilege account still using the vendor's out-of-the-box password, reachable from the public internet. The single key to the entire platform, never changed after install.

// authorised assessment · financial services
HighCVSS 7.5

Entire API surface exposed without login

The application's complete endpoint blueprint, well over a thousand routes covering accounts, payments, and administration, downloadable by anyone before authenticating.

// authorised assessment · digital banking
HighCVSS 7.5

Secrets hardcoded in public JavaScript

Service credentials and an API key embedded directly in client-side code, readable by any visitor who opened the browser console. No breach required, just curiosity.

// authorised assessment · public web platform

Illustrative findings from authorised engagements. Client identities, hosts, and specifics withheld under confidentiality.

// 05   Methodology

A clear path from scope to a fix that holds.

No black boxes. You always know what we are testing, what we found, and that it is genuinely closed.

PH·01

Scope

Targets, rules of engagement, and timing agreed in writing before anything begins.

PH·02

Reconnaissance

We map your attack surface the way an adversary would, from the outside in.

PH·03

Exploitation

Manual, adversarial testing backed by tooling, going far deeper than any scanner alone.

PH·04

Reporting

One document your board and your engineers can both read, act on, and fund.

PH·05

Re-test

We return, confirm every fix landed, and sign it off. Not before.

// 06   Industries

Built for the systems that cannot fail.

The Indian Ocean runs on offshore finance, tourism, and public infrastructure. We test the platforms those depend on.

Banking & Fintech

Digital banking, payment platforms, and the APIs behind them.

Government & Public Sector

Citizen services and critical national infrastructure.

Offshore & Corporate Services

Registries, trust and fund platforms, compliance systems.

Enterprise & SaaS

Customer-facing products, cloud estates, and internal tooling.

// 07   Why Katiti

The kestrel watches, then strikes with precision.

Katiti is the Seychelles kestrel, an endemic falcon that misses nothing in its field of view. It is the only bird of prey native to these islands, and it is the standard we hold ourselves to. Local by origin, uncompromising by method.

Start a conversation
01

Reports two audiences can read

Deep technical detail for your engineers, and a plain-language summary a non-technical board can understand and fund. One document, both jobs done.

02

Evidence over noise

We never pad a report with low-value scanner output. Every finding is real, reproduced, and scored by its actual impact on your business.

03

Local presence, global standards

Based in Seychelles, fluent in the region, working to OWASP, PTES, and NIST. Close enough to care, rigorous enough to trust.

04

Discretion by default

What we learn about your systems stays between us. Confidentiality is written into every engagement, never an afterthought.

// Get started

Find out what an attacker already knows.

Tell us what you want tested and we will scope an engagement that fits. Every conversation is confidential from the first message.