About us

An independent security company in Lisbon

Built by practitioners who preferred building defences to selling fear. We test, audit and advise.

IndependentLisbon, PortugalEU coverage

Who we are

Practitioners, not a call centre

VillainStrike is a small, senior team of offensive-security specialists and auditors working out of Lisbon. It was put together by people who had spent years inside engineering and security teams and had grown tired of assessment reports that read well and changed nothing. Everything we sell is delivered by the people you meet during scoping — there is no junior bench, no handover to a third party and no reseller in the middle.

Engagements are deliberately limited in number, so each one gets manual attention rather than a tool run with a cover page attached. Most of our clients are organisations between ten and three hundred people — fintech, SaaS, e-commerce, logistics and professional services — in Portugal and across the wider European Union.

  • Hands-on testers and auditors, not account managers
  • Web, cloud, network and application experience
  • A defender's mindset — every finding has a fix
  • Plain talk for engineers and leadership
  • Long-term relationships over transactions
ModelIndependent, contract-based
HeadquartersLisbon, Portugal
CoveragePortugal & the EU
FocusOffensive security & audits
TeamSenior assessors only
EngagementsPoint-in-time & ongoing
ReportingTechnical detail & board summary
First replyWithin one business day
LanguagesEnglish & Portuguese

Competencies

What the team brings

01

Application security

Web apps, APIs and the business logic where breaches begin.

02

Cloud & infrastructure

Cloud posture, identity and network design.

03

Offensive testing

Methodology-driven testing that mirrors real attackers.

04

Security awareness

Turning staff into a working line of defence.

05

Audit & evidence

The clear technical evidence auditors need to see.

06

Response & hardening

Containing incidents and hardening against a repeat.

Method & standards

The frameworks our work is built on

We do not invent methodology per project. Testing and audit work follows published, peer-reviewed standards, so findings are reproducible and your auditors recognise the format.

StandardWhere we apply it
OWASP WSTGWeb application testing — the structure of every application assessment we run.
OWASP ASVSVerification level agreed with you up front, so "tested" has a defined meaning.
OWASP API Top 10API and SaaS back-end testing, including object-level authorisation.
PTESOverall engagement phases: scoping, intelligence gathering, analysis, reporting.
NIST SP 800-115Technical assessment planning and evidence handling.
CIS BenchmarksCloud and infrastructure configuration review baselines.
CVSS v3.1Severity scoring, so ratings are comparable across reports and vendors.

Assessors assigned to an engagement hold recognised offensive-security certifications; the specific credentials of the people on your project are named in the proposal before you sign, not claimed in the abstract here.

Our approach

Honest, useful, confidential

We would rather tell you what you need to hear than what is easy to sell. Every engagement is authorised and contract-based.

  • Fixed scope and pricing up front
  • No scare tactics or manufactured urgency
  • Confidential by default — no names, no logos
  • Every engagement authorised
  • Free retest to prove issues are closed
principles.md
1. test only what we are authorised to2. every finding ships with a fix3. no fear, no 100% guarantees4. client work is confidential

Company details

Who you are contracting with

Security testing only works when both sides know exactly who is on the other end of the agreement. We publish our operating address, a monitored email address and a working phone number so you can check us before any commercial conversation starts.

Full company registration and tax identification details, along with our banking information, are set out in the statement of work and on every invoice we issue. They are also provided on request during scoping — before you commit to anything and before any testing takes place.

  • All work performed under Portuguese and EU law
  • Written statement of work before any engagement
  • Mutual NDA available at the first conversation
  • Findings and client identities kept confidential indefinitely
Trading nameVillainStrike
Operating addressAvenida da Liberdade 110, 1250-146 Lisboa, Portugal
Governing lawPortugal · courts of Lisbon
Data protectionGDPR · supervisory authority CNPD
Registration detailsProvided in the statement of work, on invoices and on request

We do not publish client names, logos or testimonials anywhere on this site. Any reference to work performed is anonymised, and nothing is published without written permission — see our rules of engagement.

Next step

Let's build your defences

Start with a conversation. We listen first and scope second.