We ran the same checks back at them. They failed both.
My experience with this company is an unsolicited email exchange. They cold-emailed us two "Security Vulnerability Reports," both rated Critical, signed by a "Cyber Security Researcher" whose name appears nowhere on their own website. We did not buy anything.
We triaged both the way we triage any inbound report. Neither survived first contact.
No scope. No rules of engagement. No authorization. No prior relationship. That isn't research, it's a domain list and a free scanner, and not doing it is the first thing anyone in this field is taught.
The findings are passive DNS lookups. No active testing was performed, and they didn't conceal it: Report 02 lists our "Vulnerable Location" as a URL on somebody else's scanning website. They screenshotted a third-party tool and invoiced it as an assessment.
The technical content is worse than the methodology.
Report 01 asserts that a missing MTA-STS record allows spoofed mail from our domain. It does not. MTA-STS is transport security between mail servers. Sender authentication is SPF, DKIM and DMARC, all three of which we publish, all three of which were in the same DNS response they screenshotted. They inverted the threat model while looking at the evidence that contradicted them.
Report 02, on CAA records, is copy-pasted from 2017 press coverage and unedited. Still in the future tense: the requirement "goes into effect on September 8." That was September 8, 2017. It cites Symantec certificates being distrusted "until October 2018." Nine years stale, and nobody read it before sending.
Out of professional courtesy we ran the same checks back at them. Passive only, ninety seconds:
No CAA record. No MTA-STS. No DNSSEC. No Content-Security-Policy. PHP 8.0.30, which reached end of life in November 2023, so 32 months without security patches, serving a live storefront checkout. Registrant hidden behind a privacy proxy.
Both "Critical" findings they billed us for are absent from their own zone.
Their public website matches the standard of the reports. Every team bio on their published team page is lorem ipsum filler. Every testimonial on their site is attributed to the same name, listed as CEO of a company called "Company." Their published team page lists two well-known real figures from the security industry as staff, with the WordPress theme's stock demo images beside their names, one of which is reused four times for four different entries. Their credentials page is beginner course-completion screenshots with no verification links, including a blockchain mock exam presented as a certification.
They advertise $800 to $3,000 per issue and $10,000+ per audit.
Fundamentals: they cannot describe what a mail security protocol does, cannot read a DNS response they screenshotted themselves, and cannot patch a four-year-old runtime on their own storefront. The only tradecraft on display was the fake name in the signature block, and even that failed. If you get one of these, you are not being audited. You are being billed for a command someone else ran.








