Skip to content
Services
How it works Scope & safety Findings Review desk Blog Write to us
Security testing services

Security testing,
built around your scope.

Security testing for the systems your business depends on. Our AI agent model investigates across your agreed scope. Our researchers validate the findings before they reach your team.

INSIDE THE ASSESSMENT
One engagement. Connected surfaces.Web and API, cloud and Web3 are distinct assessment surfaces connected through an agreed engagement scope.Web & APIApplication boundariesCloudService relationshipsAgreed scopeAI + researcher reviewWeb3Contracts and wallets
One engagement. Connected surfaces.
Web & APICloudWeb3
01 / Find your service

Different surfaces.
One clear scope.

UserAPITenantAPPLICATION BOUNDARIES
WEB & API

Test the boundaries
your product depends on.

For authenticated applications, multi-tenant products and connected workflows.

Start here when
You are changing roles, introducing an integration or preparing a sensitive release.
What we discuss
Applications, API operations, relevant roles and designated test accounts.
Explore the service
Web & API assessment ↗
AppIdentityCloudSERVICE RELATIONSHIPS
CLOUD & SERVICES

Understand what connects.
Review what it can reach.

For selected resources, service identities and application-to-cloud relationships.

Start here when
A service connection, permission model or cloud resource boundary is changing.
What we discuss
Provider fit, named resources, available access and permitted review actions.
Explore the service
Cloud assessment ↗
IntentWalletContractTRANSACTION BOUNDARIES
WEB3

Follow intent
through execution.

For agreed contracts, wallet interactions and relevant offchain dependencies.

Start here when
You need to assess a specific version, contract change or wallet workflow.
What we discuss
Components, environments, source versions and any permitted transactions.
Explore the service
Web3 assessment ↗
02 / Define the need

Start with your question.
Not a package assumption.

Choosing an assessment starting point
Your situationA useful starting scopeWhat to clarify
A product or integration launchA useful starting scopeThe changed workflow and the boundaries it depends on.What to clarifyRelease timeline, test access and the decision the assessment should support.
A permissions or architecture changeA useful starting scopeSelected roles, identities and connected resources.What to clarifyIntended authority and the environments available for review.
A customer security requestA useful starting scopeA scope aligned with the customer’s actual requirements.What to clarifyAssessor qualifications, coverage and report expectations; acceptance is not guaranteed.
A remediation cycleA useful starting scopeSelected findings and the changes intended to address them.What to clarifyRetest scope and conditions, rather than assumed whole-system coverage.
03 / From research to action

AI-supported investigation.
Human-approved delivery.

Our AI agent model supports scoped research. Our team owns the final technical validation, impact judgment and approval of what reaches the customer.

  1. 01

    Agree the scope

    Define systems, accounts, permitted actions and exclusions.

    CUSTOMER + ZAAF
  2. 02

    Investigate & validate

    Collect evidence and review the mechanism and observed impact.

    RESEARCH + HUMAN REVIEW
  3. 03

    Deliver & follow up

    Explain findings, limitations and remediation guidance, with retesting where agreed.

    ACTIONABLE HANDOFF

Bug bounty research informs our experience; the service is scoped security testing for customer systems, not only bug bounty hunting.

04 / Today & what comes next

Be clear about availability.
Be honest about development.

SCOPE DISCUSSION AVAILABLE

Web/API · Cloud · Web3

We discuss technical fit for named systems and components. Listing a service area does not imply support for every technology or unrestricted assessment coverage.

Plan your engagement ↗
IN DEVELOPMENT · NOT AVAILABLE TODAY

Physical-device security

Physical-device testing is a development roadmap item. We are not presenting it as a working customer service or claiming completed device assessments.

05 / Before we start

Practical questions.
Clear expectations.

Bring your technical constraints and buyer requirements to the scoping conversation.

Is Zaaf only for bug bounty research?

No. The service described here is security testing for customer systems under an agreed scope. Research experience informs the approach, while each engagement has its own authorization and deliverables.

Is this an AI-only report?

No. Our AI agent model supports research; our researchers own final technical validation, impact judgment and delivery approval.

Can one engagement cover multiple service areas?

A combined scope can be discussed where the components and access are suitable. Cross-surface coverage should be explicit, not inferred from the service categories.

How do we choose the right scope?

Start with the system, the change or concern, and the decision you need to make. We can then discuss technical fit and the boundaries of a proposed engagement.

Does an assessment guarantee our system is secure?

No. Results are bounded by scope, access, environment and time. Coverage limitations and uncertainties should remain visible.

LET’S DEFINE YOUR ENGAGEMENT

Bring us your scope.
We’ll discuss the next step.

Share your system, priorities and target date.
Please do not include credentials or sensitive findings.