Security research, run like an engineering discipline.
QSearch is a Swiss offensive-security firm for companies of 10–200 people. One continuous partnership, a platform that compounds with every engagement — and researchers who sign what they ship.

The attackers went automated. Most defenses didn't.
The people trying to breach you don't book appointments. They run automated campaigns against thousands of companies a night — no scruples, no office hours — and with every wave of new technology they get faster, cheaper and a step ahead.
QSearch exists to end that asymmetry. The same AI, turned into a shield: in the hands of accountable Swiss researchers, with guardrails, on your side. Attacker speed, working for you — at a fraction of the old cost, in days instead of weeks. Because every week of waiting is a week of exposure.
Four weeks of senior time, once a year. By the next audit, the findings describe a system that no longer exists.
A thousand findings, no judgment, nobody's name on any of them. Nobody signs a scanner's output.
The platform automates what doesn't require judgment and concentrates researchers on what does. The deliverable of a four-week consultancy engagement — in days, with the same proof discipline, signed.
What runs behind every engagement.
Not a SaaS you log into — internal tooling we engineer so every engagement starts sharper than the last.
working your engagement in parallel
from web apps to adversarial ML
every finding passes all of them
green before anything ships
75 vetted open-source tools, hardened and isolated before they touch an engagement — orchestrated, not improvised.
Every finding is classified in the frameworks your auditors already speak — CWE, CAPEC and MITRE ATT&CK. No unclassified claims, ever.
30 attack patterns that work, 84 documented dead-endsthat don't — so no engagement ever pays for the same mistake twice.
Member of the Anthropic Cyber Verification Program
Membership is granted after review — who we are, how we operate, and the controls around our offensive tooling. Verifiable on request.
We run frontier AI modelsfor reconnaissance and exploit development — inside the program's responsible-use safeguards, against authorized targets only.
Attacker-grade speed, no gray-area tooling. AI accelerates the search; a senior researcher verifies every finding through four gates — and signs it.
No names on the page. You'll know them by their work.
Working under a handle is the norm of this trade — so we lean into it. What's never anonymous is the output: every deliverable is signed with OpenPGP, verifiable against our published key, and identities are disclosed confidentially on engagement.
Sees the whole board — strategy, research, and what your business actually risks.
Too many white hairs, every one earned in the field. Has probably seen your bug before.
Freezes you with one look. Convinces you with evidence.
Enchants you with words — then puts every single promise in writing.
From the middle lands: fluent in executive, start-up and engineer. Nothing gets lost in translation.
Proof-of-concepts at 2 a.m., enthusiasm at all hours.
Asks the naive question that breaks the assumption. That’s the job.
From lab to partnership.
Independent research and coordinated disclosure. The habits formed here — reproduce, document, verify — became the gates.
Agents, skills and gates engineered into one pipeline. Dead-ends become a database instead of tribal memory.
Approved under Anthropic's Cyber Verification Program — frontier tooling, with guardrails.
Continuous engagements for Swiss SMEs. Run from Zürich, under FADP · GDPR · EU AI Act.
The model is the pitch. One call settles the fit.
A discovery call costs nothing and commits to nothing. A senior researcher answers.
