EU-based offensive security consultancy

Adversary-grade testing. Reports for your board and engineers.

Principal-led offensive security, from Sofia, across the EU. Penetration testing, red teaming and AI security assessment — manual-first, exploit-validated, aligned to PTES and OWASP.


Held by Simeon Georgiev OSCE³ OSWE CRTO CRTL

Why principal-led

No bait-and-switch.

The person who scopes your engagement is the person on the keyboard. No handoff to a junior after signature.

Manual-first.

Findings are exploited and validated before they reach the report.

Limited concurrency.

We take on a limited number of engagements at a time. Work gets turned away before a report gets rushed.

How an engagement runs

Scoping

A one-page scope you sign off. Fixed price, held for the duration.

Execution

Manual-first testing to PTES and OWASP, weekly status, and confirmed criticals reported the moment they are validated.

Report and retest

Executive summary in plain language; technical findings with CVSS v3.1, evidence, repro steps and fixes. Retests by agreement.

Proof, instead of logos

Checkable: a sample report walkthrough, certification scans with current expiry dates under NDA for procurement, and a named principal you can look up before you let anyone near production.

The practice

Covert Binary Ltd is incorporated in Bulgaria and operates from Sofia. Named associates are brought in when scope requires it, under NDA and named to you in the SoW.

Based
Sofia, Bulgaria
Entity
Covert Binary Ltd · VAT BG207577711
Markets
EU · selectively beyond
Languages
English · Bulgarian
White-label
Available to agencies and consultancies

Ready to test something?

Send one line describing what you want tested. A scoping-call slot comes back inside one business day.