Skip to main content

Client accounts

What teams said once the report landed.

Client names and reports are withheld under non-disclosure agreement, so these accounts are attributed by role and sector. Named references are available on request once an engagement reaches scoping.

  • They chained three findings we had each rated low into a full account takeover, then showed us the exact request that did it. Our previous supplier had reported two of those same issues and closed them as informational. The report went straight into our sprint board without translation.

    VP Engineering

    Series B payments platform

    Web application and API penetration test

  • The value was not the initial access, it was the timeline. Seeing exactly which of our alerts fired, which ones nobody looked at for eleven hours, and which stages produced no telemetry at all changed how we spend our detection budget.

    Head of Information Security

    UK insurance group

    Red team engagement and purple team replay

  • We were four weeks from a customer security review and needed evidence we could actually stand behind. They scoped it in two days, tested for three weeks, and gave us a report that answered the questionnaire almost line by line. The retest after our fixes was included, which we had not expected.

    Chief Technology Officer

    Healthtech scale-up

    Cloud infrastructure and application assessment

  • Most consultancies hand you a document and disappear. Their team sat with my analysts and rebuilt the attack step by step until we could write detections for it. We closed six genuine gaps in our alerting off the back of that one session.

    Security Operations Manager

    European logistics operator

    Detection review and purple team workshop

  • Our engineering team disputed the severity of a deserialisation issue for months. Nullpath built a working proof-of-concept against our own firmware build, documented the trigger path, and the fix was approved the same week. They then validated the patch properly rather than taking our word for it.

    Director of Product Security

    Industrial hardware manufacturer

    Exploit development and patch validation

  • The workshop used vulnerabilities pulled from our own codebase, which made it impossible for anyone in the room to dismiss as theoretical. Three months on, our reviewers are still catching authorisation mistakes at pull request stage that would previously have reached production.

    Engineering Manager

    B2B software provider

    Secure code review workshop

On confidentiality

We do not publish client logos, report extracts or engagement details without written permission, and we do not ask for permission as a condition of working together. If you want to speak to a reference before committing, tell us the sector and engagement type you care about and we will arrange an introduction.

Start here

Ask a reference what we were like to work with.

Tell us the sector and the engagement type that matter to you. We will introduce you to a client who ran something comparable, before you commit to anything.

Expires in

Limited time offer

We rebuilt your site for you. Claim it and we handle everything transfer, hosting, and your domain. Then update it anytime, just by asking AI.

Host for only$8 per monthBilled yearly
Claim limited offer now