Skip to main content
QSearch logomarkQSearch Security ResearchENGINEERED CONTINUOUS ADVERSARIAL INTELLIGENCE
SWISS OFFENSIVE SECURITY · EVERY REPORT CRYPTOGRAPHICALLY SIGNED

Know exactly how you'd be breached. Before anyone else does.

QSearch runs continuous, AI-accelerated offensive security for small and mid-sized companies. Every finding is a real exploit we reproduced on your systems — verified by a researcher through four gates, explained in business terms, and signed.

ONE SIGNED PAGE OF WHAT AN ATTACKER SEES FROM OUTSIDE — IN 48 HOURS · PASSIVE ONLY · NO SALES FOLLOW-UP
CVP Anthropic Cyber Verification Program Swiss-registered FADP · GDPR · EU AI ActLAUNCH OFFER FOR NEW CLIENTS — LAST 8 SLOTS · UNTIL 13 SEP 2026 →
$ qsearch assess --target client.ch
[✓]Phase 1 — Reconnaissance     2,847 endpoints mapped
[✓]Phase 2 — Surface analysis    auth boundary examined
[▸]Phase 3 — Module-bound testing  QS-047-012 → gate 3/4
[ ] Phase 4 — Signed deliverable
HIGHQS-047-012ATT&CK T1190CVSS 8.1
Authorization bypass on invoice export

Any authenticated user can export another tenant's invoices. Reproduced with a low-privilege account against a production mirror.

GATES 4/4 · SIGNED openpgp:4750…A9D6VERIFIED ✓
ACTUAL DELIVERABLE FORMAT — SAMPLE REPORT BELOW
CVE WATCH — LIVE
CVE-2026-21847 · EPMM RCE · covered ✓CVE-2026-20154 · SSO token replay · covered ✓CVE-2026-19983 · K8s privesc · analyzingCVE-2026-22615 · Next.js middleware bypass · covered ✓CVE-2026-21847 · EPMM RCE · covered ✓CVE-2026-20154 · SSO token replay · covered ✓CVE-2026-19983 · K8s privesc · analyzingCVE-2026-22615 · Next.js middleware bypass · covered ✓
crawled from cve.org · updated continuously
THE PROBLEM

Attackers don't test you once a year.

A pentest is a photograph; your attack surface is a movie. New deploys, new SaaS, new people, 100+ new CVEs published every day. The report answers a question that was already three months old when it shipped.

ANNUAL PENTEST — 1 SNAPSHOT / 12 MONTHS
QSEARCH — TESTING RE-RUNS AS YOUR ENVIRONMENT CHANGES
REGULATION × TECHNOLOGY

Audited on yesterday's law. Attacked with tomorrow's tools.

THE LAW — TIGHTENING
2018 · GDPR
EU baseline — extraterritorial, fines up to 4% of turnover.
2023 · SWISS nFADP
Revised — personal liability for responsible persons, up to CHF 250k.
2024 · NIS2
Management personally accountable for cyber duty of care.
2026 · EU AI ACT
Obligations in force — AI systems now carry due-diligence duties.
EVERY REVISION ADDS CHECKPOINTS YOU MUST EVIDENCE AT AUDIT. "WE DIDN'T KNOW" STOPPED BEING A DEFENSE.
YOUR COMPANY
THE SQUEEZE
THE TECHNOLOGY — ACCELERATING
OFFENSE ▲
100+ new CVEs published — every day
Public exploit PoCs within hours of disclosure
AI-generated phishing and recon at scale
DEFENSE ●
Patches & advisories shipping daily
Detection tooling improving weekly
AI-assisted testing — continuous, not annual
BOTH SIDES MOVE EVERY DAY. STANDING STILL IS THE ONLY LOSING MOVE.
Continuous beats annual

Testing that re-runs as your environment changes — not on a procurement calendar.

Proof beats alerts

Scanners flood your IT with unverified alerts. We send only findings we exploited and verified.

Two readers, one report

Your board gets risk in francs and legal duties. Your IT gets traces and fixes. Same signed document.

HOW AN ENGAGEMENT RUNS

One signed engagement. Four steps.

THE 200× CLAIM, UNPACKED
200×
10 consultants × 20 working days ≈ 200 person-days 1 platform day

A traditional engagement staffs ten people for four weeks — mostly mechanical work: enumeration, correlation, re-testing, reporting. Our platform compresses the mechanical hours into a single day. Judgment is never compressed: every finding still crosses four human-controlled verification gates before it reaches you.

Where we sit — honestly.

DIMENSION
Annual pentest
Scanner subscription
QSearch
Cadence
Once a year
Continuous alerts
Continuous testing + quarterly reassessment
False positives
Low, but findings go stale
You triage them yourself
None shipped — every finding exploited & verified
Proof
PoC at test time
None
Reproducible trace, cryptographically signed
Written for
Security teams
Dashboards
Board + engineering, in one dual-track report
After the report
Engagement ends
Alerts keep coming
We retest fixes and watch new CVEs against your stack
Accountability
Firm letterhead
None
PGP-signed reports — verifiable against our published key
THE DELIVERABLE

One report. Two readers.

FOR THE BOARD
Exposure in francs, not CVSS points. What each finding costs if exploited, and what fixing it saves.
Legal duties mapped. FADP, GDPR and NIS2 obligations tied to specific findings.
A 90-day plan you can resource. Prioritized by risk reduction per franc spent.
ESTIMATED ANNUAL LOSS EXPOSURE
CHF 480,000 today
CHF 60,000 after remediation
FOR ENGINEERING
$ curl -s -H "Authorization: Bearer $LOW_PRIV" \
  https://api.client.ch/exports/4471/download
→ 200 OK · invoice_batch_tenant_0412.zip
CVSS 8.1CWE-639ATT&CK T1190RETEST: SCHEDULED

Full request/response traces, reproduction steps, fix guidance — and a retest when you've shipped it.

ACCOUNTABILITY, ENGINEERED

Reports you can cryptographically verify.

Every deliverable is signed with OpenPGP and verifiable against our published key at qsearch.ch/pgp-key.asc. If a single byte changes, verification fails. The signature is not a marketing line — it's a key.

REPORT SIGNATURE — QS-2026-047
sha256  1f8a…c290  (canonical payload)
openpgp 4750 C048 … D3C6 A9D6
signer  QSearch Security Research
SIGNATURE VALID — VERIFIED ✓

Evidence, not testimonials.

Public cases, redacted to protect the client — open each one on the Track record.
SECTORS SIGNED:CRYPTOGRAPHIC MPCPAYMENTS INFRASTRUCTURESCALE-STAGE FINTECHB2B SAASMANUFACTURING
WHAT CLIENTS SAY AFTER THE REPORT LANDSIDENTITIES REDACTED
Five days in, they minted unlimited platform credit and predicted every spin before the bet even landed. Two previous audits had missed it for two years.
CTO · iGAMING PLATFORM
They broke our whole money economy in a day — then told us, plainly, that our token signing and database crypto were genuinely strong. Findings, never theater.
FOUNDER · iGAMING PLATFORM
The only firm that ever told us the site was solid and closed the one real gap with a single config line. No inflated severity to justify an invoice.
OWNER · INDUSTRIAL SME
One overlooked deployment flag was leaking our source-tree layout and a developer username. They caught it and we fixed it the same week.
IT LEAD · INDUSTRIAL SME
A zero-click heap overflow triggered just by receiving a voice message — reported through our program, confirmed, and bounty-awarded. Textbook handling.
SECURITY TEAM · MESSAGING · 900M+ USERS
Reported responsibly, coordinated with our maintainers, fixed before publication, and credited publicly as a GitHub advisory. Exactly how it should go.
MAINTAINER · OPEN-SOURCE PROJECT
Every finding shipped with a working exploit and a PGP signature I could verify myself. I have never trusted a security report more.
CISO · PAYMENTS
The free surface check alone found three staff passwords sitting in public breach dumps. That got the budget approved in a single morning.
HEAD OF IT · PROFESSIONAL SERVICES
They spoofed our CEO to our own finance team in minutes — no DMARC in place. We had it enforced days later. Cheapest fix we ever made.
CFO · LOGISTICS SME
Admin panels reachable from anywhere and an unpatched edge service — the stuff everyone has and nobody checks. They found it before anyone else could.
OPERATIONS DIRECTOR · MANUFACTURING
Five days in, they minted unlimited platform credit and predicted every spin before the bet even landed. Two previous audits had missed it for two years.
CTO · iGAMING PLATFORM
They broke our whole money economy in a day — then told us, plainly, that our token signing and database crypto were genuinely strong. Findings, never theater.
FOUNDER · iGAMING PLATFORM
The only firm that ever told us the site was solid and closed the one real gap with a single config line. No inflated severity to justify an invoice.
OWNER · INDUSTRIAL SME
One overlooked deployment flag was leaking our source-tree layout and a developer username. They caught it and we fixed it the same week.
IT LEAD · INDUSTRIAL SME
A zero-click heap overflow triggered just by receiving a voice message — reported through our program, confirmed, and bounty-awarded. Textbook handling.
SECURITY TEAM · MESSAGING · 900M+ USERS
Reported responsibly, coordinated with our maintainers, fixed before publication, and credited publicly as a GitHub advisory. Exactly how it should go.
MAINTAINER · OPEN-SOURCE PROJECT
Every finding shipped with a working exploit and a PGP signature I could verify myself. I have never trusted a security report more.
CISO · PAYMENTS
The free surface check alone found three staff passwords sitting in public breach dumps. That got the budget approved in a single morning.
HEAD OF IT · PROFESSIONAL SERVICES
They spoofed our CEO to our own finance team in minutes — no DMARC in place. We had it enforced days later. Cheapest fix we ever made.
CFO · LOGISTICS SME
Admin panels reachable from anywhere and an unpatched edge service — the stuff everyone has and nobody checks. They found it before anyone else could.
OPERATIONS DIRECTOR · MANUFACTURING
START SMALL

Not ready for a call? Start here.

Free surface check

We map what an attacker sees from outside — subdomains, exposed services, leaked credentials — and send a one-page summary. No agent, no access needed.

PASSIVE RECONNAISSANCE ONLY — SEE OUR RECON POLICY
Sample report

The exact deliverable — executive summary to proof-of-concept traces. Redacted from a real engagement.

See a redacted sample →
SME security checklist

The 12 questions that actually matter for a 10–200 person company. Written for owners, not auditors.

Get the checklist

One conversation. No funnel, no SDR.

A senior researcher reads your message and replies within one business day. If we're not the right fit for your environment, we'll tell you that too.

— QSEARCH SECURITY RESEARCH · SWITZERLAND