Request Engagement

We break what others assume is safe.

A Saudi practice for offensive security and secure software engineering. Every engagement starts with a written scope and ends with a report your team can act on.

Offensive Security

We don't sell a vague "security assessment." Every engagement has a written scope, an agreed methodology, and one output: a report your team can execute against. Our practice is built on certifications including OSWE, OSCE3, OSEP, and others held within our network.

OSWE · eWPTX

Web Applications & APIs

Authentication, authorization, and business-logic testing, up to remote code execution. No automated scans.

OSEP · CRTP · CRTO

Internal Networks & Active Directory

Adversary simulation from a single foothold to full domain compromise, with every step documented.

eMAPT

Mobile Applications

Static and dynamic analysis of iOS and Android apps, including their server-side communication channels.

OSED · OSCE3

Exploit Development

Binary analysis and custom exploit writing when off-the-shelf tooling isn't enough.

move your cursor over the skyline

Design

We design and build the interface your client will see, with the same rigor as the report we deliver. This section is the sample.

Riyadh —:—

Software Engineering

We build what we can test. Web platforms, mobile apps, and infrastructure reviewed against the same standard we hold client systems to.

Web Platforms

Applications and dashboards built for long-term operation, not a demo.

Mobile Applications

End-to-end apps, from design to store release.

Masarif

Personal expense & budget tracker

A consumer app for personal expense and budget tracking, live on the App Store.

masarif Available on the App Store ↗
Shipped

Mirsad

In progress

Not yet public.

mirsad
In Progress

Faiz

AI employee for Salla & Shopify merchants

In progress.

In Progress

How We Work

Written Scope

Exactly what will be tested, what won't, and when.

Agreed Methodology

Black-box, grey-box, or white-box — chosen before work starts, not during.

Immediate Escalation

Anything that threatens production doesn't wait for the final report.

Two-Tier Report

An executive summary for decision-makers, a technical breakdown for implementers.

Retest

We verify remediation and document closure.

Broken Verification on Password Reset

One finding, as it appears in the report we hand over.

SeverityCritical
ImpactFull account takeover without user interaction.
EvidenceFull request/response pair, with screen recording.
ReproductionFour numbered steps on the test environment.
RemediationBind the reset token to the session and invalidate after use.

The Standards We Build On

These certifications are held within our practice. They belong to their issuing bodies; showing them here does not imply endorsement by, or affiliation with, those bodies.

OSCP+
OSWE
OSCE3
eWPTX
OSED
OSEP
CRTP
CRTO
OSWP
eMAPT
eCPPT
eJPT

Request Engagement

We'll come back with a written scope, timeline, and price — not a general offer. Tell us three things.

What do you want tested or built?
Roughly how big: how many apps, users, domains?
When do you need the result?
Start the Conversation
Email
info@aql-tech.com
Location
Riyadh, Saudi Arabia