Partnering with organizations on advanced security challenges

Photon Security

Agentic AI & Cybersecurity Leadership

We combine deep technical expertise with strategic thinking to help organizations navigate offensive security, cloud hardening, AI/LLM threats, and emerging attack surfaces. Founded by a security leader with over 2 decades of experience at Commonwealth Bank, VMware, and Apple, with recognized research at GitHub, Microsoft, Atlassian, and Wiz.

Our Research About Us
20+
Years Experience
6+
Security Findings
4
Fortune 500 Clients
20+
Research Publications
Scroll

Expertise

What We Deliver

Leveraging deep technical expertise across the full security spectrum — from hands-on offensive work to strategic consulting.

Offensive Security

Our offensive security services help organizations understand their real-world attack surface. Through penetration testing, red team operations, and API security assessments, we identify critical gaps before attackers do.

PentestingRed TeamResponsible DisclosureWeb App Security

Cloud Security

We design and implement Azure and Microsoft 365 security architectures, including Entra ID hardening, Conditional Access policies, and cloud-native threat detection for enterprise environments.

AzureM365Entra IDZero Trust

Infrastructure Hardening

We establish enterprise security baselines, network segmentation strategies, and endpoint hardening protocols with security automation for large-scale organizational deployments.

HardeningAutomationBaselinesCompliance

AI/LLM Security

Our research program focuses on AI/LLM security assessments, prompt injection vulnerabilities, OWASP LLM Top 10 compliance, and threat modeling for organizations deploying AI-integrated applications.

LLM SecurityPrompt InjectionAI Threat Modelling

Security Tooling

We develop open-source security tools, automation frameworks, and custom security solutions in Python, TypeScript, and PowerShell to enhance organizational security workflows.

PythonTypeScriptOpen SourceAutomation

Consulting & Leadership

We provide security strategy consulting, architecture advisory, technical leadership guidance, and executive-level security counsel for organizations building robust security programs.

StrategyAdvisoryLeadershipArchitecture

Responsible Disclosure

Responsible Disclosure

Vulnerabilities responsibly disclosed to major technology companies.

6+
Vulnerabilities Reported
4
Companies Affected
100%
Responsibly Disclosed
3
High/Critical Severity
High
GitHub · 2024

Data Exposure

Identified a security flaw allowing unauthorised access to sensitive repository data, reported to GitHub Security.

Full write-up in Member Zone
Medium
GitHub · 2024

Access Control Bypass

Discovered a bypass mechanism in GitHub Copilot's access controls, enabling unauthorised feature access.

Full write-up in Member Zone
Medium
GitHub · 2024

Business Logic Flaw

Found a business logic vulnerability allowing bypassing of Copilot subscription pricing controls.

Full write-up in Member Zone

Open Source

Featured Projects

Security tools, AI/LLM tooling, and automation built in the open.

MacOS-MDM-Override
Infrastructure

Scripts and methods to circumvent DNS, Proxy, Route, and PAC file restrictions on MacOS devices managed by MDM profiles. Includes DNS override using dnscrypt-proxy, proxy setting bypass, routing table modifications, and PAC file customizations. Intended for educational and personal use only

HTML
2 1y ago
page-fetcher
Infrastructure

Command-line tool that downloads web pages, bypasses CORS restrictions, removes anti-scraping measures, and opens them locally with all images and resources properly loaded. Uses AllOrigins proxy to fetch content, strips redirects, rewrites URLs for local viewing, and includes progress indicators. For macOS with curl and jq.

Shell
1 2mo ago
VLC-Eavesdropping
Other

Hacking - This document outlines a malicious process that can be used to eavesdrop on conversations using the microphone of a workstation. It also provides recommendations for organizations to prevent such unauthorized activities by blocking VLC Media Player or implementing log and event monitoring as deterrent measures.

1 1y ago
covert-ssh-tunnel
Tools

Hacking - Breach Internal Corporate Network Overview This Bash script is intended for offensive security purposes, specifically to evade corporate network boundaries via a single outbound connection, which can be kept alive using tools like autossh. It evades detection by using port 443, typically allowed as it is commonly used for HTTPS

Shell
1 1y ago
O365-iOS-data-exfiltration
AI/LLM

Hacking - Office 365 Data on iOS - Exfiltration Guide. This guide provides step-by-step instructions for exfiltrating Office 365 data from an iPhone. The process involves jailbreaking the iPhone, setting up an SSH server, bypassing jailbreak detection, and transferring files to a personal computer using SCP.

1 1y ago

Work With Us

Ready to Strengthen Your Security Posture?

Whether you need penetration testing, cloud security architecture, AI/LLM threat assessments, or strategic security guidance — we're here to help you navigate today's complex threat landscape.

Member Zone