OpenHat Security · draft

Pay us to break it — before someone else does.

Flat $1,000: we hunt every hole we can on systems you authorize, and hand you logs of what we touched — so you pay us to break it before someone malicious does. Refund if no Critical in scope (SOW is binding).

  • — Permission + domain + founder LinkedIn + one app URL
  • — Full authorized test + logs of everything we touched
  • — Stack & extra URLs optional — they only make us faster
OpenHat Security
OpenHat operator
root@your-company-server — authorized session
root@your-company-server:~# ohqs engage --authorized

What you get

Operator-grade, not brochure-ware.

Full authorized test

We hunt for every hole we can find in the business systems you authorize — not a light scan for show.

Logs of everything we touched

You get evidence and logs showing what we accessed and what we tried, so you see the work — not just a summary slide.

Flat $1,000 package

One price to break it on purpose before a malicious actor does. Start intake on this site; SOW is binding. Mock payment until a provider is chosen.

Money-back if no Critical in scope

Full refund when no Critical (as defined) is found in scope — subject to exclusions and the signed contract.

Critical — honest definition

Refund hinges on Critical in scope. Here is what that means.

Draft marketing copy. Severity labels and refund mechanics are finalized only in a signed SOW.

Bulk PII exposure (validated read)

Confirmed read access to bulk personally identifiable information outside intended authorization.

Remote code execution / pre-auth RCE

Ability to execute attacker-controlled code on an in-scope system, including pre-authentication paths.

Full session takeover

Account or session compromise that yields durable control of an authenticated identity in scope.

Unauthenticated DoS at scale

Practical denial-of-service against an in-scope service without credentials, at operationally meaningful scale.

Refund exclusions (draft)

  • You revoke permission or block testing mid-engagement without a written change.
  • Legal or infrastructure blocks make testing impossible after kickoff.
  • Phishing / social-engineering work (priced separately unless explicitly in SOW).

Authorization & ethics

Authorized testing only.

We only need your permission to start. Domain, founder LinkedIn, one app URL, and threats you already fear are enough. Stack and extra URLs help us go faster — optional. You get findings and logs of everything we touched. Not a warranty that every vulnerability will be found.

Next step

Start the $1,000 intake.

Business questions first, mock payment at the end. Binding terms only appear in a signed SOW.

Start intake