office@safebyte.io Bucharest, Romania ISO 27001:2023 · ISO 9001:2023
Offensive testing and compliance for critical systems

Cybersecurity.
Smarter. Better.

Financial · Energy · Critical infrastructure · Public sector

We test applications, infrastructure and critical systems the way a competent adversary would: manually, in context and impact-driven. We don’t deliver alert lists; we demonstrate what can be exploited, how far an attacker can reach and what to fix first.

We support regulated organisations and critical-infrastructure operators. We are a European Union company, ISO 27001 and ISO 9001 certified, with professional liability insurance. Data, evidence and project deliverables stay in the EU.

Smarter

More than automated scanning

We automate the repetitive parts, but validation and decisions stay with the tester. Every relevant finding is manually verified and put in context. A scanner flags a potential issue; we demonstrate whether it can be exploited and what the impact is.

Better

Priorities based on impact, not volume

We don’t inflate severity and we don’t bury real risks in an oversized report. You get well-argued findings, clear priorities and recommendations your team can act on.

Certified

Verifiable rigour, at company and team level

ISO 27001:2023 and ISO 9001:2023 at company level; OSCP, OSWP, CEH, LPT, CISA and GICSP at team level. We deliver technical and executive documentation tailored to your internal team, management and auditors.

Verifiable technical certifications We present and validate them before the project starts.
OSCPOSWPCEHLPTGICSPGRIDCHFICSSAECSACompTIA Security+CISSPCompTIA PenTest+
Penetration testing

Knowing your vulnerabilities isn’t enough. You need to know what an attacker can do with them.

A well-executed penetration test correlates vulnerabilities, configurations and access rights into a realistic attack scenario. The result shows which assets are exposed, which controls work and where intervention is most urgent.

  • Exploitable vulnerabilities, manually validated
  • Attack chains and pivot points
  • Architecture and segmentation flaws
  • Detection and response capability
  • Real exposure of data and systems
  • Evidence for audit and compliance
  • Clear remediation priorities
  • Validation of security investments
SafeByte team during a penetration test
Capabilities

The attack surface no longer stops at web apps and networks

Cloud, industrial systems, digital identity, AI models and software supply chains have radically expanded the attack surface. Our capabilities cover these environments without sacrificing the rigour of traditional testing.

01

ICS / SCADA / OT

We assess industrial control systems in energy, water, district heating and manufacturing. Testing is planned to limit operational risk and uses protocols and scenarios specific to industrial environments.

02

Cloud, Kubernetes and IaC

We assess public, private and government cloud, Kubernetes configurations, containers, IAM policies, pipeline secrets and the gap between infrastructure declared in code and what actually runs in production.

03

Red Team and TIBER-EU

We build offensive scenarios from relevant threats and explicit business objectives. Exercises can be aligned with the TIBER-EU framework, national implementations and DORA operational resilience requirements.

04

AI-assisted pentesting

We pentest with our own AI platform — a frontier or self-hosted LLM, plus a proprietary methodology with iteration loops, strict safety instructions and an interactive-pentester mode. The tools cut dead time; judgement and control stay with the tester.

05

AI and LLM system security

We test prompt injection, data exposure through context, tool-equipped agent abuse, insufficient isolation and escalation through model integrations. The assessment tracks risks introduced when an AI system gets access to real data and processes.

06

Hardware, embedded and firmware

We analyse embedded devices, firmware, hardware interfaces and communication protocols, including black-box scenarios and controlled physical access conditions.

07

eKYC and deepfake resilience

We assess identity verification flows against synthetic presentations: generated images and video, manipulated documents, cloned voice, replay and liveness bypass. Testing is relevant for banking onboarding, fintech and payment institutions.

08

Purple teaming and detection validation

We execute attack techniques alongside the defence team and measure what the SOC, EDR and correlation rules detect, what goes unseen and how long the response takes. The result is a concrete plan for improving detection.

SafeByte team working on a security project
Why SafeByte

Technical expertise, project discipline and business-context awareness

  • Experience in critical environments

    Our team’s expertise was built in complex projects — from financial applications and enterprise infrastructure to ICS/SCADA and systems with strict continuity requirements. We understand both the technology and the operational constraints around it.

  • Continuously updated technical practice

    We keep our methods and labs current through research, testing and ongoing training. We don’t mechanically apply the same checklist: we adapt techniques to the architecture, technology and risk profile of each project.

  • Recommendations you can act on

    A vulnerability doesn’t exist in a vacuum. We evaluate it against the organisation’s processes, data, dependencies and obligations, then formulate proportionate, clear and actionable measures for the teams that need to implement them.

ISO/IEC 27001:2023Information security
ISO 9001:2023Quality management
Sectors

We work where downtime has real consequences

Every sector has different technologies, threats, obligations and risk tolerances. The methodology stays rigorous, but the scenarios and evaluation criteria are adapted to the operational context.

Banking and financial

Commercial banks, credit institutions, fintech, payment institutions and processors, in heavily regulated contexts with strict resilience requirements.

Energy

Generation, transmission and distribution, hydropower, district heating and supply, with interdependent IT and OT infrastructures.

Utilities

Water and sewage operators, where IT infrastructure, communications systems and the SCADA environment must be assessed together.

Nuclear and industrial

Organisations in nuclear, oil and gas and continuous-process manufacturing, where safety and availability take priority.

Healthcare and pharma

Pharmaceutical manufacturers, medical institutes and organisations managing sensitive data, laboratory systems and connected equipment.

Public sector

Central and local authorities, digitalisation agencies and publicly funded projects, with high requirements for transparency, continuity and compliance.

Relevant experience

Projects we can describe without breaching confidentiality

Most projects are protected by non-disclosure agreements. The examples below are anonymised but preserve the type of organisation, the scale and the nature of the work.

Multi-year programme

Multi-year penetration testing and security audit programme for one of the largest banking institutions in Romania.

Central bank

External, internal, interbank and wireless testing, complemented by vulnerability assessments, for a state’s central bank.

Mobile banking

PCI DSS v4.0.1 audit for a payment application, with documentation accepted by the banking regulator.

International programme

Security audits and penetration tests for seven energy and critical-infrastructure companies, within a programme coordinated by an international development organisation.

Government cloud

Security assessment for application migration to a government private cloud, carried out under a framework agreement funded through the NRRP.

Nuclear and oil & gas

Penetration tests for organisations in the nuclear sector and the oil and gas industry.

Early Access · Vigilum by SafeByte

Expose the attacker before the attacker exposes you.

Vigilum deploys credible decoy artefacts across your infrastructure — credentials, sessions, files, services and cloud keys — that no legitimate user or process has a reason to touch.

When one of these artefacts is accessed, you get an early, context-rich signal: the source of the activity, the pivot points and the path taken through the infrastructure.

  • High-confidence signals with no dependency on continuous tuning
  • Visibility into lateral movement and the attack path
  • On-premises or fully air-gapped deployment
  • Complements your EDR and SIEM — doesn’t replace them
attack path visibility Semnal timpuriu origine · pivot · momeală atinsă momeli 06 tipuri ilustrate semnal HIGH încredere ridicată legendă atacator momeli detecție traseu perimetru / dmz rețea internă cloud identity / AD date sensibile internet atacator DMZ stații utilizatori directory services serviciu momeală sesiune momeală credențiale momeală cont momeală chei cloud momeală fișier momeală momeală atinsă alertă timpurie cu context complet
Contact

Tell us what needs to be assessed

Briefly describe the system, objective and estimated timeline. We’ll get back to you within one business day. For sensitive information, you can use our PGP key.

Vulnerability reporting
security.txt · PGP key available
Office
Bucharest, Romania
SafeByte Consulting S.R.L.