---
title: "Security · Marxen"
url: "https://marxen.in/security"
description: "Authorised penetration testing that produces a working exploit and a reproduction path."
---

# A report that ends in an exploit, not a warning.

Most security reports hand you findings ranked by a scanner's opinion. Ours hand you the request that got through, the data it reached, and the fix.

## § 01 · What we run

**Bastion**
does penetration testing. Agents read your source, plan attack paths, and execute real exploitation against injection, cross-site scripting, server-side request forgery and authorisation flaws through browser automation. You get proof by exploitation, with a reproduction path your engineers can follow.

**Perimeter**
does exposure assessment. Which of your credentials already sit in breach corpora. Which employee accounts are enumerable across public platforms. What an attacker can assemble about your organisation before touching anything you own.

## § 02 · How it engages

A scoped contract, written authorisation naming the systems in scope, a named client contact and a defined test window. We do not run this self-serve and we do not run it without that paperwork. The authorisation letter is what separates a penetration test from a crime.

- [Scope an engagement ↗](mailto:info@marxen.in?subject=Security%20engagement)
