Built by operators
PentStark was founded in Bangalore by three offensive-security practitioners.
PentStark was founded by operators to replace the one-shot audit with an always-on offensive practice — built for teams that ship daily and still need to pass the audit.
Every engagement is led by practitioners, not a practice-area sales engineer. You talk to the people finding the bugs.
Reports are PoC-driven. Every finding reproduces, every remediation is engineering-specific.
Scope units and flat retainers — no per-consultant-day billing games.
Modern engineering ships daily. Security should match that cadence, not fight it.
We publish the frameworks, the tools, and the evidence format. Nothing is black-box vendor magic.
Operators who can't explain a bug to an engineer don't get to find them for our customers.
We started PentStark after a decade of watching engagement reports go untouched in a SharePoint drive. Engineers wanted fix guidance. Auditors wanted structured evidence. Leaders wanted a number they could trust. The one-shot annual pentest couldn't serve any of them.
So we built the practice we wished existed: a continuous engagement model, findings delivered the moment we discover them, unlimited retests within the window, and a report format a developer will actually read.
Three years in, PentStark is a distributed team of operators with delivery heritage from Fortune 500 consultancies, FAANG red teams, and independent research.
PentStark was founded in Bangalore by three offensive-security practitioners.
Delivered our first 50 engagements and published the first batch of CVE disclosures.
Standardized evidence handling and engagement controls as our operator team expanded across continents.
Launched the PTaaS platform and crossed the 100-customer milestone.
Expanded AI/LLM red teaming into a dedicated, fast-growing practice.
Our engineers hold OSCP, OSCE³, OSWE, CRTO, CISSP, and CCSP among other credentials. We publish CVEs, speak at conferences, and maintain open-source security tooling.
Public write-ups, conference talks, and disclosures from our research team.
Thirty minutes with a real operator tells us what you need and what we can deliver. No BDR handoff, no sales engineer theater — the person you talk to is the person who scopes the work.