Skip to content
v1olet

Find the flaw before an attacker charges you for it.

v1olet runs penetration tests, red team operations, and vulnerability research for teams that ship fast. Every finding comes reproducible, with a working proof of concept and a retest once you have fixed it.

  • Retest included
  • Named operators, no subcontracting
  • Findings as you go, not at the end

Competed at

  • HTB Cyber Apocalypse 2026
  • OmniCTF 2026 Qualifier
  • BroncoCTF
  • Operation Heist CTF 2026
  • THEM?!CTF 2026
  • Guardians Qualifications 2026
Verify on CTFtime ↗

Five ways we get hired.

Engagements are scoped individually. Most clients start with an assessment and move to continuous testing once the release cadence picks up.

01

Penetration testing

Web applications, APIs, and infrastructure, tested by hand against a defined scope and a fixed window.

Findings report · retest

02

Red team operations

Adversary simulation that measures whether you detect and respond — not just whether the perimeter holds on the day of the test.

Attack narrative · detection gaps

03

Vulnerability research

Deep review of software and protocols, down to the primitives, to surface the bug classes an automated scanner has no way to model.

Advisory · coordinated disclosure

04

Continuous testing

Testing that runs alongside your release cycle instead of once a year, so findings land while the code is still fresh in someone’s head.

Rolling findings queue

05

Training and workshops

Hands-on sessions built from real engagements and competition work, run for engineering teams as well as internal security functions.

Live lab · exercise set

06

Not sure which you need?

Most engagements start with a short scoping call. Tell us the stack and the deadline and we will say plainly what is worth testing first.

hello@v1olet.xyz

Four stages, no surprises on the invoice.

The same sequence on every engagement, from a two-week web assessment to a six-week red team operation.

  1. Scope

    Fixed price and a named lead before anything starts.

    We agree the targets, the rules of engagement, the testing window, and the escalation path. You receive a fixed price and the name of the operator who will lead the work before a single request is sent. Scope creep is handled as a written change, not as a surprise on the invoice.

    • Signed scope and rules of engagement
    • Fixed price and testing window
    • Named engagement lead
    • Escalation contacts on both sides
  2. Test

    Findings reach you the hour they are confirmed.

    Testing runs against a shared channel with your team. Anything critical is escalated immediately — the hour we confirm it, not in a report six weeks later. You can watch the engagement progress rather than waiting for a document, and your engineers can start on a fix while the operator is still in the environment to verify it.

    • Shared channel with the operators
    • Immediate escalation of critical findings
    • Running list of confirmed issues
    • Daily progress notes on longer engagements
  3. Report

    Every finding reproducible, with a proof of concept.

    Each finding lands with reproduction steps, a working proof of concept, an assessment of business impact, and remediation your engineers can act on. Severity is argued from impact in your environment, not copied from a scanner. The report carries both an executive summary you can hand to a customer or auditor and the technical detail your developers need.

    • Technical report with reproduction and PoC per finding
    • CVSS v4.0 vector and business-impact rationale
    • Executive summary for non-technical distribution
    • Remediation guidance mapped to your stack
  4. Retest

    Included in the original price.

    Once you have shipped the fixes we verify each one and reissue the report with the resolved findings marked and dated. The reissued report is the artefact you can show a customer, an auditor, or a procurement team. This is included — it is not a second engagement.

    • Verification of each remediated finding
    • Reissued report with resolution status and dates
    • Attestation letter on request
    • Notes on any fix that did not fully close the issue

Our results are a matter of public record.

The operators who run client work compete year-round under the v1olet tag. Placements below are as published by the organisers, and every entry links to its source.

Competitions recorded
rd
Best placement · BroncoCTF
Largest field faced
  1. 28th

    HTB Cyber Apocalypse 2026

    24–29 Jul 2026 · 7000+ teams

  2. 4th

    OmniCTF 2026 Qualifier

    17–19 Jul 2026 · 1k+ teams

    AVERAGE PLACE
  3. 3rd

    BroncoCTF

    11 Jul 2026 · 731 teams · captained by existin

  4. 17th

    Operation Heist CTF 2026

    13–14 Jun 2026 · captained by e1

The people who will be on your engagement.

We do not subcontract. The operators listed here are the ones who do the work — the same bench that competes under the v1olet tag.

Existing!?!

Captain

Web Exploitation

Captain. Web exploitation and misc specialist - captained the 3rd-place BroncoCTF run.

At every point of Existence, meaning lurks
runs_led
3
best_finish
3rd
main_cat
web
  • web
  • misc
  • osint

ctxzero

Captain

Penetration Testing

Captain. Penetration testing and web exploitation.

Sky is the Limit
  • pentesting
  • red teaming
  • web
  • pwn

ra1ncandy

Co-captain

Generalist

Co-captain. True all-rounder - equally comfortable across OSINT, web, reverse engineering, and misc challenges.

A man who has not hit his Claude limit by noon has wasted his morning. -Socrates
  • osint
  • web
  • rev
  • misc
  • ai

ɘluЯɘ

Co-captain

Forensics & Cryptography

Co-captain. Forensics and cryptography specialist, also covering misc and blockchain challenges.

Do I truly have free will?
  • forensics
  • misc
  • crypto
  • blockchain

Bench depth

Operators across 14 disciplines, from web and binary exploitation to cloud, cryptography and OSINT. Engagement teams are assembled from the specialists the scope actually needs.

  • web17
  • osint13
  • rev12
  • misc11
  • pentesting10
  • red teaming9
  • pwn7
  • crypto6
  • forensics5
  • ai3
  • blockchain1
  • teaching1
  • cloud1
  • quantum1

Credentials, standards, and the paperwork procurement asks for.

Engagements run against named methodology standards, under written rules of engagement, by operators who hold industry certifications.

Tell us what you are shipping.

Send the stack, the deadline, and what worries you. We come back with an approach, a timeline, and a fixed price — usually within two working days.

Or write directly: hello@v1olet.xyz