office@safebyte.io București, România ISO 27001:2023 · ISO 9001:2023
About us

Complete cybersecurity, built on offensive experience

SafeByte Consulting is a cybersecurity firm — offensive testing, audit and compliance, incident response, consulting and governance — with a single mission: to find real risks and address them concretely, not on paper.

With over 19 years of experience, we work with organisations across sectors — financial services, energy, technology, healthcare, public administration and critical infrastructure — in Romania, Moldova and the European Union.

Perspective

We understand your business

Whatever your field, we know you’re proud of what you’ve built. You want to keep it safe and you want it to grow. We don’t just bring technical expertise — we shape security around your business.

What sets us apart

What you’ll feel in every report

Manual testing by experts

Automated tools give us coverage; the real value comes from manual exploitation by specialists. Every vulnerability is validated by a person, demonstrated with a concrete proof-of-concept and explained in business context — not a list of false positives from a tool.

Depth, not surface

We know what a core banking system, an industrial SCADA network, a cloud Kubernetes environment or an enterprise ERP looks like from the inside — and how an attacker targeting them thinks. This isn’t generic experience: it’s built system by system, engagement by engagement, across sectors.

A team with top certifications

OSCP, OSWP, CREST, LPT Master, CEH, CISA, CISM, CRISC, CISSP — and DNSC-attested cybersecurity auditors. Certifications are not decoration: they are the guarantee that whoever tests your systems knows exactly what they’re doing.

Rigorous methodology, international standards

We work according to OWASP, NIST SP 800-115, PTES and OSSTMM for testing; ISO 27001, NIST CSF and COBIT for audit and governance. Clear reports, CVSS-classified, with prioritised recommendations and retesting included — because a good report ends with remediation, not with findings.

Discreet, non-destructive, trustworthy

We work in coordination, without disrupting production, under NDA and with professional liability insurance. Client data stays the client’s — and is securely destroyed at the end of the engagement.

Not just reports — direction

From CISO-as-a-Service to risk assessments and governance, we provide strategic direction, not just technical findings. Security doesn’t end at the pentest report; it continues with updated policies, corrected architecture and day-to-day support.

Our expertise

What we cover

Offensive testing

Web, API, mobile, infrastructure, thick-client, cloud, OT/SCADA, IoT, Active Directory, red teaming and TIBER-EU.

Audit and compliance

ISO 27001, NIST CSF, PCI-DSS, NIS2, DORA, SWIFT CSP, GDPR — including sector-specific requirements from central banks and supervisory authorities.

Detection and response

Incident response, threat hunting, continuous monitoring.

Consulting and governance

CISO-as-a-Service, policy and risk management, security architecture, security integrated into IT projects, on-site support.

In-house solutions

Developed by our specialists: the Vigilum platform for continuous monitoring and the SafeByte Atlas vulnerability scanner.

Specialised assessments

AI/LLM security, eKYC and anti-deepfake, ICS/SCADA/OT, hardware and embedded — niche domains that require direct experience, not just generic methodology.

Earned trust

Reputation is built one honest report at a time

We’ve been chosen by organisations in sectors with high security requirements — financial services, energy, technology, healthcare, public administration — in Romania, Moldova and the European Union. Every engagement is a proof of trust; every report, a reputation to uphold.

Our mission

Organisations that are genuinely harder to break into

To make organisations harder to break into — not on paper, but in reality. No inflated severities and no alarmism: the technical truth, stated clearly, and a concrete path to remediation.

We assess your defences like an attacker. We secure them like a partner.

Tell us what needs to be assessed. We’ll respond within two business days.

Request an assessment