Alpha inferno レビュー 

7
TrustScore 5段階評価の3

2.9

レビューはレビュアーの個人的な意見であるため、特定の記載内容を検証することはありません。ただし、ビジネス上の取引が行われたことを確認できた場合、レビューに「確認済み」のラベルを付ける場合があります。詳細はこちら

プラットホームの健全性を維持するため、当社のプラットフォーム上のすべてのレビューは、確認済みか否かにかかわらず、年中無休で稼働する自動ソフトウェアによって審査されています。このテクノロジーは、本当の経験に基づいていないレビューなど、ガイドラインに違反するコンテンツを特定し、削除するよう設計されています。ただし、すべてを検知できるわけではありませんので、お気づきの点がございましたら、どうぞお知らせください。詳細はこちら


連絡先

2.9

まあまあ

TrustScore 5段階評価の3

7件のレビュー

5つ星
4つ星
3つ星
2つ星
1つ星

最近のレビュー依頼の記録はありません

この企業は最近、顧客にレビューを依頼していないため、レビューが全体の意見を反映していない可能性があります。

ネガティブなレビューに回答していません

この企業のTrustpilot 利用方法

レビューや評価の取得方法、スコアリング、モデレーションのプロセスについて確認する。

2.9

すべてのレビュー

(7)

過去12か月のレビュー数: 4

レビューを書く

レビューの確認を行います

Trustpilot に参加している企業は、インセンティブを提供したり、レビューを非表示にするためにお金を払ったりすることは許可されていません。レビューはレビュアーの個人的な意見で、Trustpilot のものではありません。詳細はこちら

5つ星のうち1の評価

We ran the same checks back at them. They failed both.

My experience with this company is an unsolicited email exchange. They cold-emailed us two "Security Vulnerability Reports," both rated Critical, signed by a "Cyber Security Researcher" whose name appears nowhere on their own website. We did not buy anything.

We triaged both the way we triage any inbound report. Neither survived first contact.

No scope. No rules of engagement. No authorization. No prior relationship. That isn't research, it's a domain list and a free scanner, and not doing it is the first thing anyone in this field is taught.

The findings are passive DNS lookups. No active testing was performed, and they didn't conceal it: Report 02 lists our "Vulnerable Location" as a URL on somebody else's scanning website. They screenshotted a third-party tool and invoiced it as an assessment.

The technical content is worse than the methodology.

Report 01 asserts that a missing MTA-STS record allows spoofed mail from our domain. It does not. MTA-STS is transport security between mail servers. Sender authentication is SPF, DKIM and DMARC, all three of which we publish, all three of which were in the same DNS response they screenshotted. They inverted the threat model while looking at the evidence that contradicted them.

Report 02, on CAA records, is copy-pasted from 2017 press coverage and unedited. Still in the future tense: the requirement "goes into effect on September 8." That was September 8, 2017. It cites Symantec certificates being distrusted "until October 2018." Nine years stale, and nobody read it before sending.

Out of professional courtesy we ran the same checks back at them. Passive only, ninety seconds:

No CAA record. No MTA-STS. No DNSSEC. No Content-Security-Policy. PHP 8.0.30, which reached end of life in November 2023, so 32 months without security patches, serving a live storefront checkout. Registrant hidden behind a privacy proxy.

Both "Critical" findings they billed us for are absent from their own zone.

Their public website matches the standard of the reports. Every team bio on their published team page is lorem ipsum filler. Every testimonial on their site is attributed to the same name, listed as CEO of a company called "Company." Their published team page lists two well-known real figures from the security industry as staff, with the WordPress theme's stock demo images beside their names, one of which is reused four times for four different entries. Their credentials page is beginner course-completion screenshots with no verification links, including a blockchain mock exam presented as a certification.

They advertise $800 to $3,000 per issue and $10,000+ per audit.

Fundamentals: they cannot describe what a mail security protocol does, cannot read a DNS response they screenshotted themselves, and cannot patch a four-year-old runtime on their own storefront. The only tradecraft on display was the fake name in the signature block, and even that failed. If you get one of these, you are not being audited. You are being billed for a command someone else ran.

2026年7月31日
自発的なレビュー
5つ星のうち1の評価

Spam

They sent beg-bounty spam to our client support email, raising a ticket and wasting our developer's time, overstating an issue as "critical" despite it being a low severity issue with no credible exploit.

2026年7月7日
自発的なレビュー
5つ星のうち5の評価

A huge thank you to @Husnain Iqbal at…

A huge thank you to @Husnain Iqbal at Alpha Inferno Private Limited for spotting and reporting a critical vulnerability in our code! Your vigilance and expertise helped us strengthen our security, and we’re grateful for your commitment to keeping our product safe for all users.

2024年10月7日
自発的なレビュー

Trustpilot エクスペリエンス

Trsutpilot のレビューは誰でも書くことができます。レビューを書いた人には自分の書いたレビューをいつでも編集したり削除したりする権限があり、それらのレビューはアカウントがアクティブである限り表示されます。

プラットフォーム保護のため、専門チームと高度なテクノロジーを駆使しています。偽レビューとの闘いについての詳細はこちらをご一読ください。

Trustpilot におけるレビュー プロセスの詳細についてはこちらをご覧ください。

よいレビューを書くための8つのヒントをご覧ください。

確認を行うことで、Trustpilot に投稿されるレビューが [LINK-BEGIN-PEOPLE]実在の人物[LINK-END-PEOPLE] によって書かれたものであることの保証につながります。

レビューに対してインセンティブを提供したり、選択的にレビューを依頼したりすることは、TrustScore にバイアスを生む可能性があります。これは 当社のガイドラインに反します

詳細情報