Penetration testing
Web applications, APIs, and infrastructure, tested by hand against a defined scope and a fixed window.
Findings report · retest


v1olet runs penetration tests, red team operations, and vulnerability research for teams that ship fast. Every finding comes reproducible, with a working proof of concept and a retest once you have fixed it.
Competed at
Engagements are scoped individually. Most clients start with an assessment and move to continuous testing once the release cadence picks up.
Web applications, APIs, and infrastructure, tested by hand against a defined scope and a fixed window.
Findings report · retest
Adversary simulation that measures whether you detect and respond — not just whether the perimeter holds on the day of the test.
Attack narrative · detection gaps
Deep review of software and protocols, down to the primitives, to surface the bug classes an automated scanner has no way to model.
Advisory · coordinated disclosure
Testing that runs alongside your release cycle instead of once a year, so findings land while the code is still fresh in someone’s head.
Rolling findings queue
Hands-on sessions built from real engagements and competition work, run for engineering teams as well as internal security functions.
Live lab · exercise set
Most engagements start with a short scoping call. Tell us the stack and the deadline and we will say plainly what is worth testing first.
hello@v1olet.xyz ↗The same sequence on every engagement, from a two-week web assessment to a six-week red team operation.
Fixed price and a named lead before anything starts.
We agree the targets, the rules of engagement, the testing window, and the escalation path. You receive a fixed price and the name of the operator who will lead the work before a single request is sent. Scope creep is handled as a written change, not as a surprise on the invoice.
Findings reach you the hour they are confirmed.
Testing runs against a shared channel with your team. Anything critical is escalated immediately — the hour we confirm it, not in a report six weeks later. You can watch the engagement progress rather than waiting for a document, and your engineers can start on a fix while the operator is still in the environment to verify it.
Every finding reproducible, with a proof of concept.
Each finding lands with reproduction steps, a working proof of concept, an assessment of business impact, and remediation your engineers can act on. Severity is argued from impact in your environment, not copied from a scanner. The report carries both an executive summary you can hand to a customer or auditor and the technical detail your developers need.
Included in the original price.
Once you have shipped the fixes we verify each one and reissue the report with the resolved findings marked and dated. The reissued report is the artefact you can show a customer, an auditor, or a procurement team. This is included — it is not a second engagement.
The operators who run client work compete year-round under the v1olet tag. Placements below are as published by the organisers, and every entry links to its source.
24–29 Jul 2026 · 7000+ teams
11 Jul 2026 · 731 teams · captained by existin
13–14 Jun 2026 · captained by e1
We do not subcontract. The operators listed here are the ones who do the work — the same bench that competes under the v1olet tag.
Captain
Web Exploitation
Captain. Web exploitation and misc specialist - captained the 3rd-place BroncoCTF run.
“At every point of Existence, meaning lurks”
Captain
Penetration Testing
Captain. Penetration testing and web exploitation.
“Sky is the Limit”
Co-captain
Generalist
Co-captain. True all-rounder - equally comfortable across OSINT, web, reverse engineering, and misc challenges.
“A man who has not hit his Claude limit by noon has wasted his morning. -Socrates”
Co-captain
Forensics & Cryptography
Co-captain. Forensics and cryptography specialist, also covering misc and blockchain challenges.
“Do I truly have free will?”
Bench depth
Operators across 14 disciplines, from web and binary exploitation to cloud, cryptography and OSINT. Engagement teams are assembled from the specialists the scope actually needs.
Engagements run against named methodology standards, under written rules of engagement, by operators who hold industry certifications.
PlaceholderOperators on this team hold industry certifications including OSCP, CPTS and CRTO, and several have long professional practice outside competition. Exact figures are pending confirmation and are deliberately left blank rather than estimated.
Send the stack, the deadline, and what worries you. We come back with an approach, a timeline, and a fixed price — usually within two working days.
Or write directly: hello@v1olet.xyz