← All posts

How to vet an offensive security startup when the story shifts

A troubling headline is only the start. For security buyers, the real work is checking whether a high-trust vendor’s identity, infrastructure, claims, and operating process line up under ordinary scrutiny.

Krebs reports on a company pitching offensive security services while several people tied to it carry disputed or troubling public histories. The headline detail is enough to make this worth a practitioner’s time, but the useful work starts after the headline. When a security startup sells access, testing, or intelligence, you are not buying a logo. You are handing someone technical reach into your environment, your staff, and often your vendors.

That changes the due-diligence bar. A slick site, a few conference photos, and a founder story are not the things that matter first. What matters is whether the public footprint lines up across identity, infrastructure, claims, and operating maturity. The problem is not that every mismatch proves bad intent. The problem is that security buyers often skip the slow, boring checks because the category itself sounds credible.

I keep seeing the same pattern in these cases. The vendor sells a high-trust service, but the strongest signals are not in their marketing copy. They are in domain history, certificate logs, filing dates, reused bios, thin technical controls, and the small contradictions between who says they operate the business and who actually appears in the records. Those are the notes worth keeping.

Start with identity, not branding

The first question is not whether the company sounds impressive. It is whether the people presenting themselves as operators can be tied, consistently and publicly, to the business they claim to run.

Look for a stable chain across four places: company registration, domain ownership history if available through public records, professional profiles, and prior appearances in conference schedules, podcasts, guest posts, or litigation records. You are not trying to prove a negative. You are checking whether the same names, dates, roles, and locations recur without constant reinvention.

This is where things commonly go wrong. A founder bio may use broad titles like “advisor,” “operator,” or “former intelligence specialist” that are hard to pin down. A team page may appear complete, but profile photos, job histories, and company formation dates do not line up. Sometimes the company account talks in the plural about years of work before the domain or corporate entity existed. Sometimes a supposedly senior operator has almost no attributable technical work, no public talks, and no trace of prior team affiliations beyond recycled self-descriptions.

Signals worth checking:

  • Whether officer names in business filings match the public-facing leadership
  • Whether claimed tenure predates the company’s actual formation or web presence
  • Whether key staff have a consistent professional footprint over time
  • Whether profile images or biographies appear reused across unrelated sites

If you need a fast first pass, TraceCheck can help map a person or entity’s public footprint from live search signals. The point is not to score anyone as good or bad. It is to identify where the story changes depending on where you look.

Inspect the domain like infrastructure, not a brochure

Security vendors often expect to be judged on expertise, but their own domain can reveal how much operational discipline exists behind the pitch.

Start with age and timing. A freshly registered domain is not inherently a problem, but it should fit the claimed stage of the business. If the company says it has spent years building a reputation and the domain was only recently registered, that is a gap to explain. Then look at certificate-transparency logs, current TLS setup, redirects, subdomains, mail exchange records, and security headers. A company selling high-trust security services does not need a perfect external posture, but a thin or chaotic setup is still a signal.

A few things I look for right away: whether the mail domain actually enforces SPF, DKIM, and DMARC; whether the site redirects cleanly; whether staging or admin subdomains leak in public certificate logs; and whether the certificate history suggests frequent pivots in hosting or naming. None of these proves much alone. Together, they tell you whether the operation feels established or improvised.

Where this goes wrong is over-reading any single artifact. Startups change providers. Small teams launch lean. That is normal. What deserves attention is the accumulation of weak controls paired with ambitious claims. If a firm promises mature offensive work but cannot maintain basic email-authentication hygiene, that mismatch matters because your procurement, legal, and security contacts may all be communicating with them over that same domain.

Useful checks here include Domain Recon, DNS Email-Security Check, SSL/TLS Certificate Checker, and Certificate-Transparency Subdomain Finder. These are not verdict tools. They are ways to ask whether the public-facing infrastructure supports the level of trust the service requires.

Read the offer language for authority without evidence

Offensive security firms trade heavily on exclusivity. They mention elite backgrounds, proprietary methods, private threat access, or unusual legal positioning. That does not make the claim false. It does mean you should separate what is verifiable from what is merely dramatic.

I read sales copy and founder interviews for three kinds of inflation. First, references to unnamed agencies, unnamed clients, or unnamed incidents used as a substitute for case studies. Second, legalistic phrasing that seems built to create distance from uncomfortable facts. Third, repeated use of insider language without adjacent technical substance.

A useful exercise is to make two columns. In one, write every concrete claim that could in principle be verified: years operating, certifications, prior employers, customer sectors, published research, legal entity names, office locations. In the other, put the prestige language: “trusted by,” “elite,” “former special,” “exclusive access,” “government-grade,” and similar constructions. If the second column is doing most of the work, you probably need more evidence before granting network access, sharing sample data, or signing a retainer.

This also applies to references and testimonials. Verify whether quoted customers are real organizations, whether the people named actually work there, and whether the testimonial appears anywhere else online. I have seen glowing quotes attached to people whose public role had no obvious connection to procurement or security. Again, that is not a conclusion. It is a reason to ask for named references you can independently reach.

Check whether the company can survive contact with normal vendor process

One of the fastest ways to test a high-risk vendor is to put them through ordinary controls and watch the quality of the response.

Ask for the legal entity name on the contract, proof of insurance, standard security documentation, a point of contact for incident reporting, data-handling language, subcontractor disclosure, and a clean explanation of where logs, findings, and customer data are stored. If they conduct testing, ask how access is scoped, how secrets are handled, how evidence is retained, and what happens if they discover third-party data during an engagement.

What you are measuring is not whether every answer is polished. Small firms can still answer clearly. You are looking for evasiveness, constant role switching, and documents that seem assembled from templates without understanding. Does the person selling the work also appear as legal, support, and finance? Are invoice details different from the website entity? Does the statement of work name tools, methods, and deliverables in concrete terms, or is it mostly atmosphere?

This is where “offensive” vendors often get a free pass because buyers assume secrecy is part of the package. Some discretion is normal. But if a vendor cannot explain how they handle authorization, evidence, retention, and notification, that is not sophistication. That is a missing process. In this category, missing process can become your incident.

For documents you receive, especially PDFs with amended pages or odd timestamps, Document Authenticity Check is useful for spotting structural anomalies worth a follow-up question.

Follow the money and the communication paths

A lot of avoidable damage happens after the technical evaluation. The contract gets signed, then payment instructions, urgent changes, or side-channel communications begin arriving from addresses and domains nobody scrutinized.

Map every domain and address involved in the relationship: website, signing email, invoicing email, support portal, calendaring links, file-sharing links, and any “temporary” addresses used by founders or contractors. Then verify whether those all belong to the same operational footprint. If invoice messages come from a different domain than negotiation messages, that should be explained. If the company relies on consumer mail for sensitive exchanges, ask why. If email authentication is weak, your accounts-payable and legal teams need to know before someone acts on a forged message.

The failure mode here is treating business-email risk as separate from vendor diligence. It is not separate. A vendor with poor email-domain controls can become a conduit for impersonation, payment redirection, or unauthorized document exchange even if the underlying company is real. That is especially relevant for boutique security firms, where a small number of people often handle every function.

Email Header Analyzer or Phishing & BEC Email Analyzer can help if a message in the thread looks off or if payment details suddenly change. The key is to treat communications security as part of the same investigation, not a later help-desk problem.

What to watch next

The practical lesson from the Krebs item is not about one startup. It is about category risk. Any firm selling penetration testing, threat intelligence, covert collection, or “offensive” capability is asking for unusual trust. That trust should be earned through coherent public records, boring infrastructure competence, and the ability to pass ordinary vendor scrutiny without theatrics.

Watch for mismatches that persist across identity, infrastructure, process, and payment paths. One inconsistency is a question. Several, spread across those layers, usually means you need more evidence before expanding access or moving money. That is the part worth institutionalizing in your procurement playbook.