NOX//SEC --:--:--Z
live · accepting 2 retainers · Q3 '26

We attack first.
So they don't.

NOX//SEC is a 12-person offensive security shop. We break into your stack on a schedule, find what your blue team didn't, and write the patch ourselves.

142engagements
41pre-breach saves
0regrettable incidents
NODE 04 / SF
● ACTIVE
SCAN 41%
R‑T‑T 0.42ms
CLEARANCE
3 / 4 / 5
// 01 — what we run

Four sharp blades. No consulting.

Time-boxed adversarial engagements, always-on recon, disclosed zero-days and a 4-hour incident response line. Every retainer has receipts.

explore services
// 02 — operations

Four sharp blades. No consulting.

Every retainer starts with a 25-minute intake and ends with a written engagement contract. We say no more often than yes — but we say it within 48 hours.

SVC / 01ACTIVE

Red team

Full-spectrum, time-boxed adversarial engagements. 2–6 weeks. Goal-oriented (your call). Initial access, lateral movement, exfil, dwell — the works.

Scope · Internet → crown jewels
SVC / 02ACTIVE

Continuous recon

Always-on attack surface monitoring. We watch your perimeter the way an attacker would — assets, certs, exposed creds, leaked tokens.

Retainer · $8k / month
SVC / 03ACTIVE

Zero-day research

We find unpatched bugs in software you ship. We disclose them properly. We don't sell them to anyone except you.

Output · 3 advisories · 2026
SVC / 04ON CALL

Incident response

When the worst day arrives, we are on a plane within four hours. Forensics, containment, eradication, and a written-down version of what happened.

SLA · 4h on call · retainer only
SVC / 05ACTIVE

Code audits

Deep-read of a single critical codebase (auth, crypto, payments). Two engineers, two weeks, one report. No bug-bounty re-runs.

Engagement · 2 wk · fixed fee
SVC / 06QUIET

Tabletop exercises

Sit down with your executives and walk through the day your worst breach goes public. We play journalist, regulator, attacker, lawyer.

Workshop · 1 day · on site
// 03 — public ledger

Things we found, before they were found.

Every disclosure follows a coordinated 90-day window. When the patch ships, the advisory ships. No exceptions.

CVE Target Vector Severity Disclosed Status
NX-2026-014Major payments SaaSAuth bypass via JWT replayCRITICAL · 9.82026-05-22PATCHED
NX-2026-013EU bank · core ledgerSSRF → internal servicesCRITICAL · 9.42026-05-11PATCHED
NX-2026-012Identity providerSAML signature wrapHIGH · 8.62026-04-30PATCHED
NX-2026-011Major HRIS · uploadRCE via crafted PDFCRITICAL · 9.12026-04-12PATCHED
NX-2026-010Hardware wallet firmwareMemory disclosureHIGH · 8.22026-03-28LIVE 90D
NX-2026-009Web framework · v8.xPrototype pollution → RCEHIGH · 8.02026-03-14PATCHED
NX-2026-008EDR product · agentPrivilege escalationMEDIUM · 7.42026-02-21CONTAINED
// 04 — by the numbers · '26

Eight years quiet.
Forty-one breaches not yours.

NOX//SEC has been running since November 2018. In that time, no client of ours has had a credential-stuffed account compromise, no client has paid a ransom, and exactly one client has had a public breach — which they reported, with our incident report, in the same press release.

We don't sell fear. We sell a small, quiet number: zero regrettable incidents on retainer.

142Engagements · 2018–26
41Pre-breach saves
03Zero-days shipped · 2026
01Public breach (handled)
// 05 — intake

If you're reading this on a Wednesday,
we have until Friday to start.

Two retainer slots open for Q3 '26. Intake is a 25-minute call. NDA mutual. We say no more often than yes — but we say it within 48 hours.

open the dialogue