About us
An independent security company in Lisbon
Built by practitioners who preferred building defences to selling fear. We test, audit and advise.
Who we are
Practitioners, not a call centre
VillainStrike is a small, senior team of offensive-security specialists and auditors working out of Lisbon. It was put together by people who had spent years inside engineering and security teams and had grown tired of assessment reports that read well and changed nothing. Everything we sell is delivered by the people you meet during scoping — there is no junior bench, no handover to a third party and no reseller in the middle.
Engagements are deliberately limited in number, so each one gets manual attention rather than a tool run with a cover page attached. Most of our clients are organisations between ten and three hundred people — fintech, SaaS, e-commerce, logistics and professional services — in Portugal and across the wider European Union.
- Hands-on testers and auditors, not account managers
- Web, cloud, network and application experience
- A defender's mindset — every finding has a fix
- Plain talk for engineers and leadership
- Long-term relationships over transactions
Competencies
What the team brings
Application security
Web apps, APIs and the business logic where breaches begin.
Cloud & infrastructure
Cloud posture, identity and network design.
Offensive testing
Methodology-driven testing that mirrors real attackers.
Security awareness
Turning staff into a working line of defence.
Audit & evidence
The clear technical evidence auditors need to see.
Response & hardening
Containing incidents and hardening against a repeat.
Method & standards
The frameworks our work is built on
We do not invent methodology per project. Testing and audit work follows published, peer-reviewed standards, so findings are reproducible and your auditors recognise the format.
| Standard | Where we apply it |
|---|---|
| OWASP WSTG | Web application testing — the structure of every application assessment we run. |
| OWASP ASVS | Verification level agreed with you up front, so "tested" has a defined meaning. |
| OWASP API Top 10 | API and SaaS back-end testing, including object-level authorisation. |
| PTES | Overall engagement phases: scoping, intelligence gathering, analysis, reporting. |
| NIST SP 800-115 | Technical assessment planning and evidence handling. |
| CIS Benchmarks | Cloud and infrastructure configuration review baselines. |
| CVSS v3.1 | Severity scoring, so ratings are comparable across reports and vendors. |
Assessors assigned to an engagement hold recognised offensive-security certifications; the specific credentials of the people on your project are named in the proposal before you sign, not claimed in the abstract here.
Our approach
Honest, useful, confidential
We would rather tell you what you need to hear than what is easy to sell. Every engagement is authorised and contract-based.
- Fixed scope and pricing up front
- No scare tactics or manufactured urgency
- Confidential by default — no names, no logos
- Every engagement authorised
- Free retest to prove issues are closed
Company details
Who you are contracting with
Security testing only works when both sides know exactly who is on the other end of the agreement. We publish our operating address, a monitored email address and a working phone number so you can check us before any commercial conversation starts.
Full company registration and tax identification details, along with our banking information, are set out in the statement of work and on every invoice we issue. They are also provided on request during scoping — before you commit to anything and before any testing takes place.
- All work performed under Portuguese and EU law
- Written statement of work before any engagement
- Mutual NDA available at the first conversation
- Findings and client identities kept confidential indefinitely
We do not publish client names, logos or testimonials anywhere on this site. Any reference to work performed is anonymised, and nothing is published without written permission — see our rules of engagement.
Next step
Let's build your defences
Start with a conversation. We listen first and scope second.