unsafe.ltd

unsafe.

Building Asera and Evor. Design partners welcome.

Nothing interesting is safe.

unsafe is an independent security product company. We build AI agents that attack software the way an adversary would, and a platform that takes every finding, from every tool, all the way to a fix.

Become a design partner See the products

asera

Agentic security testing for your code and your running systems.

Asera puts a team of AI agents on your application. One reads the source and traces untrusted input to dangerous sinks. Another maps the live attack surface and tries to prove what the first one suspects. You get findings with evidence, not a wall of maybes.

See Asera in detail

Static analysis, in the code

  • Reads whole repositories and follows data flow across files, services and frameworks.
  • Finds injection, broken access control, exposed secrets, vulnerable dependencies and business-logic flaws.
  • Explains why a line is exploitable and drafts the patch.

Dynamic testing, against the running system

  • Maps endpoints, roles and authentication flows of web apps and APIs.
  • Runs scoped pentest tasks: authentication bypass, IDOR, injection, SSRF, misconfiguration.
  • Confirms each finding with safe, reproducible proof and chains small issues into the attack paths that matter.

How a run works

  1. Scope You set the targets, test accounts and limits. Nothing outside the scope is touched.
  2. Map Agents read the code and crawl the application.
  3. Suspect Static analysis proposes candidate weaknesses with the code path behind each one.
  4. Prove Dynamic agents try to confirm every candidate within the agreed limits.
  5. Report Evidence, impact, CWE and OWASP mapping, and a fix, ready for Evor or your tracker.

Intrusive actions wait for human approval. Every agent step is logged and can be replayed.

evor

Vulnerability operations, from first finding to closed audit item.

Evor connects to the security tools you already run through their APIs, pulls every finding into one place, and moves each one to an owner, a fix and proof that it is fixed. AI agents handle the repetitive part: deduplicating, enriching, routing and writing the ticket.

See Evor in detail

One inventory

Findings from code scanners, pentests, cloud and container tools, and Asera, deduplicated against the assets they affect.

Prioritised by real risk

Severity weighed against exploitability, internet exposure and how critical the asset is to the business.

Automated handoff

LLM agents triage new findings, assign the owning team, open the ticket with context and fix guidance, and follow up on SLAs.

Database security

Imports reports from IBM Guardium and other database activity monitoring tools, and surfaces excessive privileges, unmonitored sensitive data and policy violations.

Ready before the auditor is

Evor maps findings and controls to compliance requirements and tells you what is failing, which evidence is missing and what to fix before the assessment.

  • PCI DSS v4.0.1
  • ISO 27001
  • SOC 2
  • KVKK
  • GDPR

Bring your own model.

Asera and Evor run on the model you choose, and you can mix them: a frontier model for deep reasoning, a local model for code that cannot leave the building.

Enterprise models

Through your own enterprise agreement and keys.

  • Anthropic Claude
  • OpenAI GPT and Codex
  • Google Vertex AI

Local models

Open-weight models on your own hardware, through vLLM, Ollama or any OpenAI-compatible endpoint. Source code and findings stay inside your network.

  • GLM
  • Qwen
  • DeepSeek

Principles

Permission first
Asera only tests what you own or are authorised to test, inside a scope you sign off.
Proof over noise
A finding without evidence is a question, not a result.
People decide
Agents propose. Humans approve anything intrusive or irreversible.
Your data, your boundary
Deploy in your cloud or on your hardware. Your code and findings are never used to train models.

Work with us early.

We are building Asera and Evor with a small group of security teams. If you run application security, penetration testing or compliance and want early access, write to us.