Executive Report
Where the company is exposed, what is serious and what can wait. In business language: you take it into the meeting and everyone understands.
GenIA Safe tests applications, APIs, mobile, code and infrastructure. And it tests the AI layer in production, which is where almost no one knows how to look. You get reproducible evidence, risk ranked by severity and a remediation plan with deadlines.
The AI layer is tested by people who build AI every day.
A scoping conversation, no commitment.
We define the assets, the environments, the execution window and the rules of engagement together with you. Nothing starts before that is agreed in writing.
We test applications, APIs, mobile, code, infrastructure and the AI layer, in black box, white box or gray box mode.
Every confirmed finding enters the risk matrix with its severity, reproduction evidence, business impact and remediation deadline. The result is presented to leadership and to engineering, each in the language they decide in.
We work under non disclosure agreements. A client name appears on this page with written authorization, and not before.
Customer facing applications, integration APIs, the mobile app and the AI layer used in analysis and service.
The full case study is in documentation. We publish client names only with written authorization.
See what you receivePolicyholder and broker portals, quotation APIs, reimbursement flows and the AI that reads documents and receipts.
The full case study is in documentation. We publish client names only with written authorization.
See what you receiveOperational systems and ERP integrations, exposed environments, access control and the AI applied to design and engineering.
The full case study is in documentation. We publish client names only with written authorization.
See what you receivePlatforms holding sensitive data, audit trails, role based access control and compliance with applicable data protection law.
The full case study is in documentation. We publish client names only with written authorization.
See what you receiveSystem to system integrations, tracking APIs, field environments and computer vision in operation.
The full case study is in documentation. We publish client names only with written authorization.
See what you receiveOWASP Top 10, injections, authentication, privilege escalation, isolation between users, business logic, exposed services, vulnerable libraries and cryptography. Every finding comes with step by step reproduction, so your team can fix it without depending on us to understand what happened.
Your AI is connected to your systems, your data and your customers. We run controlled prompt injection and jailbreak tests, audit real conversations, measure cost and latency per model, and check whether the system started hallucinating after the provider's last update. Traditional security firms do not do this, because they do not build AI.
We identify the application and integration flaws that would allow improper access to customer, user and internal information, with the impact of each one classified by severity before any fix begins.
It reaches you as three documents, each written for the person who will read it.
Where the company is exposed, what is serious and what can wait. In business language: you take it into the meeting and everyone understands.
Every finding classified by criticality in the risk matrix, with the evidence, the deadline and remediation guidance ready for your IT team or your vendor to execute.
Proof that your company tests its own security. It is what banks, large clients and auditors ask for when they want evidence, not promises.
Your technical team gets more: the full report, with the mapping of every environment, the evidence and the step by step reproduction of each finding. With retesting contracted, confirmation that the fix worked. And if your operation uses AI, the package also includes a vulnerability report for the AI layer with the prompt already hardened, a model fit matrix by task with cost projection, and a regression report with a mitigation plan.
That is Safe Pontual, our one time assessment, the snapshot of where you stand today. When remediation needs to become routine, Safe Jornada, our continuous engagement, takes over the operation, with test and retest sprints, a live risk backlog and a monthly executive committee. And when the remediation plan points to architecture rather than to a fix, there is a path for that too.
In almost all of them, the flaw that was exploited was known, documented and testable before the incident. What was missing was not defensive technology. What was missing was someone to test.
A ransomware attack forced plant shutdowns in the US, Canada and Australia. The company paid US$ 11 million in ransom.
Bloomberg · 2021
The biggest disruption to the US healthcare system in years, affecting pharmacies and hospitals. Costs passed US$ 872 million.
Wall Street Journal · 2024
The British carmaker had intellectual property and source code published on a dark web forum after its systems were breached.
TechCrunch · 2025In this episode we walk through a career in cybersecurity and what it takes to lead application pentesting.
Watch now (in Portuguese) →A discussion on advanced strategies to protect cloud environments and why being proactive is what makes security work.
Watch now (in Portuguese) →How security teams have to adapt their testing and tactics to stay ahead of faster, more sophisticated threats.
Watch now (in Portuguese) →
A conversation to understand your assets, your environments and what makes sense to test first. No proposal before the scope is defined.
Discuss scope A scoping conversation, no commitment.No. Before any test we define the rules of the work with you: what will be assessed, when and how. Every action is controlled and non destructive. Our role is to identify and confirm the findings, not to cause the damage a criminal would cause. Nothing is deleted, altered or taken offline. If you prefer, the tests can run in a staging environment, without touching the system that serves your customers.
It does, and that is why the reports speak two languages. You get a summary in business language, with the risks found and what should be resolved first. Whoever looks after your systems, whether a vendor, a software house or an internal professional, gets the technical step by step for each fix. And if no one is looking after this today, Safe Jornada, our continuous engagement, works as your outsourced security department.
An executive report in business language, a risk matrix with every finding classified by severity, a prioritized remediation plan, a technical report with the evidence and reproduction steps for each vulnerability, and the Test Certificate. It is the document banks, large clients and auditors ask for when they want evidence rather than promises, and it is the kind of testing evidence that ISO 27001 and PCI DSS processes usually require. If your operation uses AI, the package also includes the AI layer report, with the prompt already hardened.
It depends on the size of what will be assessed. One time packages are sized between 40 and 160 hours of technical work, which in practice means a few weeks between the start of testing and the delivery of the reports. It all starts with a scoping conversation, and the proposal comes out with the schedule and the delivery date already set.
All work is covered by a non disclosure agreement and by scope rules defined in the contract. We access only what is needed to confirm the findings, in a controlled way, and report distribution is restricted to the people you authorize. We operate in line with applicable data protection law, and the test itself helps your company demonstrate the diligence the law requires.
They are different things, and both remain necessary. A firewall and antivirus are automated defenses. The Safe test does the opposite: it simulates a human attacker trying to get in, to find out what gets past those defenses. Most successful attacks exploit exactly what those tools cannot see, such as configuration errors, gaps in login screens and systems exposed to the internet for no reason.
Yes, and this is where we stand apart. AI assistants and agents can be manipulated into leaking information, bypassing business rules or answering on behalf of your brand in ways you never approved. We run controlled prompt injection and jailbreak tests, audit real conversations, measure cost and latency per model, and check whether the system started hallucinating after the provider's last update. You receive the prompt already hardened. Traditional security firms do not test this, because they do not build AI. GenIA does.
Safe Pontual is the snapshot: a package of hours with a full assessment, risk matrix, remediation plan and certificate. It fits audits, go lives, compliance requirements, due diligence or periodic reassessment. Safe Jornada is the operation: a monthly subscription in which we act as your security team, with a live risk backlog, test and retest sprints, an executive committee and continuous maturity growth. If you need to prove something now, start with Pontual. If you need to keep it that way, start with Jornada.
It depends on the scope: how many systems will be assessed, in which environments, at what depth, and whether retesting is needed. We define that with you in the first conversation, and the proposal comes out with the price and the timeline already set, with no surprises later. One time packages are sized in hours, from 40 to 160, and continuous engagement is monthly.