Security work, done in the open

SySecurity is the offensive security practice of SysAlbania. We test systems the way an attacker would, then hand you everything needed to fix what we found.

SysAlbania has published security research, tooling write-ups and a live CVE tracker since its first article. SySecurity is where that work becomes an engagement: a scoped test, a written report, and a retest once the fixes land.

How we work

Every engagement starts with written authorisation and a rules-of-engagement document. We agree what is in scope, what is explicitly out of scope, and the window in which testing happens. Nothing is touched before that is signed.

Testing is manual first. Tooling is used to widen coverage, not to generate the report. A scanner output with a cover page is not a penetration test, and we do not sell one.

What we will not do

We do not test systems without the owner's written authorisation, we do not publish client names without permission, and we do not sell findings to anyone but the client who commissioned the work.