NULLSEC
An independent collective operating at the intersection of offensive security research, privacy engineering and digital self-defense. We don't sell your data. We don't collect it. Honestly, we don't need to — we're already better than whoever's trying to get it. We just make sure no one else can either.
Privacy first. Everything else is secondary.
Every decision we make — from how we build tools to how we run this site — starts with one question: does this expose anyone? If the answer isn't a hard no, it doesn't ship. We've walked away from paying clients over this. We'll walk away from you too, if it comes to that.
Minimal by default
We collect nothing we don't strictly need, and we don't need much. No analytics pixels, no third-party scripts, no fingerprinting. If you can't find a tracker on this site, that's because there isn't one — not because we hid it well.
Encrypted end to end
Every channel we operate — comms, storage, transfer — is encrypted at rest and in transit. No exceptions, no backdoors, no matter who asks. People have asked.
Audited, not assumed
We red-team our own infrastructure the same way we'd red-team a client's. We'd rather find our own mistakes than let someone else announce them first — it hasn't come to that yet.
What we actually do.
Research-driven security work for people who'd rather hear the bad news from us, on our terms, than from a breach notification later.
Adversarial Security Audits
Authorized penetration testing and red-team engagements that map real attack paths before someone else finds them first.
Privacy Architecture Review
We audit data flows end to end and strip out every unnecessary collection point, log, and third-party leak.
OSINT & Exposure Mapping
We show you exactly what's publicly discoverable about your org or your identity — and how to shut it down.
Secure Comms Deployment
Hardened, encrypted communication and infrastructure setups built for people who can't afford to be wrong about this.
Privacy is not something we protect after the fact. It's the first line we draw before a single byte moves.— NULLSEC Founding Charter
Recent intel.
A sample of the anonymized write-ups we publish once an engagement closes. The full archive lives on the intel page.
What people say once the engagement is over.
"They found things two prior audits missed, then explained exactly why those audits missed them."
"No dashboards, no upsell calls. Just a report, a fix list, and silence afterward. Exactly what we wanted."
"We asked for a privacy review. We got a full map of every place our own team had forgotten data was flowing."