# PENTECTON > A senior security architect working inside engineering teams on the security of what they ship: architecture reviews before a feature is built, threat models before release, and concrete fixes. Also covers AI/LLM feature security. ## About PENTECTON works inside engineering teams on the security of what they're shipping: reviewing architecture before a feature is built, threat-modeling it before release, and turning risks into concrete fixes. Founded by Radoslaw Karpowicz, a security architect with experience at Auth0, Okta and Snowflake. OSCP certified, published security researcher and 0-day discoverer. ## Services - [SaaS Security Readiness Review](https://pentecton.com/services/security-architecture-review/): You receive an architecture-level risk map, prioritized systemic findings, and a 30-60-90 day remediation plan focused on the risks that can affect enterprise sales, audits, and long-term product security. Typical engagement: 5-10 days. - [Product Security Assessment](https://pentecton.com/services/product-security-assessment/): You receive a prioritized product security report, buyer readiness notes, and a remediation backlog to help your team fix key issues before enterprise customers, auditors, or security reviewers ask difficult questions. Typical engagement: 5-7 days. - [AI Security Architecture Review](https://pentecton.com/services/ai-security-review/): You receive a focused AI security review covering data flows, prompt injection, model access control, tenant isolation, provider risks, and practical recommendations before AI features reach customers at scale. Typical engagement: 5-8 days. ## Guides - [Security Architecture Review Guide for SaaS Platforms](https://pentecton.com/guides/security-architecture-review-guide/): A practical guide to security architecture reviews for CTOs and engineering leaders building or scaling SaaS platforms. - [OAuth/OIDC Pre-Launch Checklist](https://pentecton.com/guides/oauth-checklist/): 60+ product security checks for teams shipping SSO, OAuth 2.0/2.1, or OpenID Connect - aligned with the OAuth 2.1 draft. Free checklist from Pentecton. ## Research - [How I discovered a vulnerability in hundreds of Mac OS X applications](https://vulnsec.com/2016/osx-apps-vulnerabilities/): Identified a critical vulnerability in the Sparkle Updater framework that allowed remote code execution through man-in-the-middle attacks on applications using unencrypted HTTP connections. Hundreds of macOS apps were affected, including VLC, iTerm and Adium. - [How to detect the Sparkle Updater vulnerability](https://vulnsec.com/2016/detecting-osx-apps-rce/): Detection techniques and proof-of-concept exploitation of the Sparkle update framework vulnerability using mitmproxy. Demonstrates automated identification of vulnerable applications through network traffic analysis. - [How attackers exploit routers remotely](https://vulnsec.com/2016/how-routers-are-exploited-remotely/): Research into a remote code execution vulnerability in Netgear routers allowing unauthenticated command execution as root. Demonstrates browser-based exploitation through DNS rebinding techniques to compromise home networks. - [Solving the XSS challenge from Intigriti](https://vulnsec.com/2019/intigriti-xss-challenge/): Demonstrates a race condition vulnerability in a domain whitelist bypass challenge. By dynamically changing an iframe's location hash before a redirect executes, arbitrary JavaScript execution is achieved within the target domain's context. - [picoCTF 2019 - JavaScript Kiddie writeup](https://vulnsec.com/2019/picoctf-2019-js-kiddie/): Technical writeup of two picoCTF web challenges involving PNG file format analysis and cryptographic key recovery. Published in Paged Out! magazine issue #2. - [SANS Holiday Hack Challenge - Honorable Mention](https://vulnsec.com/2017/SANS-Holiday-Hack-Challenge-2016/): Awarded honorable mention in the SANS Holiday Hack Challenge. Covers Android APK reverse engineering, ELF binary analysis, SQL injection, privilege escalation, cryptanalysis and Meteor framework exploitation across interconnected targets. ## More - Full content for AI assistants: https://pentecton.com/llms-full.txt ## Contact - Website: https://pentecton.com/contact/