NULLSEC

Zero Trace // Zero Trust // Zero Compromise

An independent collective operating at the intersection of offensive security research, privacy engineering and digital self-defense. We don't sell your data. We don't collect it. We help you make sure no one else can either.

PRIVACY IS NOT A SETTING. IT'S AN ARCHITECTURE. NO LOGS. NO TRACKERS. NO TELEMETRY. ZERO KNOWLEDGE BY DESIGN. ENCRYPT EVERYTHING. TRUST NOTHING BY DEFAULT. PRIVACY IS NOT A SETTING. IT'S AN ARCHITECTURE. NO LOGS. NO TRACKERS. NO TELEMETRY. ZERO KNOWLEDGE BY DESIGN. ENCRYPT EVERYTHING. TRUST NOTHING BY DEFAULT.
01 — Doctrine

Privacy first. Everything else is secondary.

Every decision we make — from how we build tools to how we run this site — starts with one question: does this expose anyone? If the answer isn't a hard no, we don't ship it.

/ 01

Minimal by default

We collect nothing we don't strictly need, and we don't need much. No analytics pixels, no third-party scripts, no fingerprinting.

/ 02

Encrypted end to end

Every channel we operate — comms, storage, transfer — is encrypted at rest and in transit. No exceptions, no backdoors.

/ 03

Audited, not assumed

We red-team our own infrastructure the same way we'd red-team a client's. Trust is earned through verification, not branding.

02 — Capabilities

What we actually do.

Research-driven security work, aimed at reducing exposure — yours or your organization's.

SVC / 01

Adversarial Security Audits

Authorized penetration testing and red-team engagements that map real attack paths before someone else finds them first.

SVC / 02

Privacy Architecture Review

We audit data flows end to end and strip out every unnecessary collection point, log, and third-party leak.

SVC / 03

OSINT & Exposure Mapping

We show you exactly what's publicly discoverable about your org or your identity — and how to shut it down.

SVC / 04

Secure Comms Deployment

Hardened, encrypted communication and infrastructure setups built for people who can't afford to be wrong about this.

0
Data brokers we sell to
0
Trackers on this site
256-bit
Minimum encryption standard
24/7
Monitoring on client infra
"
Privacy is not something we protect after the fact. It's the first line we draw before a single byte moves.
— NULLSEC Founding Charter
04 — Field Notes

Recent intel.

A sample of the anonymized write-ups we publish once an engagement closes. The full archive lives on the intel page.

Session tokens surviving password resets
Advisory · reset flows that revoke the password but not the session
2026.07.28
Third-party SDKs quietly widening data collection
Research · scope creep hidden in minor version bumps
2026.07.12
Cache headers leaking authenticated pages to CDNs
Misconfiguration · surfaced during CDN migrations
2026.06.30
05 — Trust

What people say once the engagement is over.

"They found things two prior audits missed, then explained exactly why those audits missed them."

— Security Lead, Fintech (NDA)

"No dashboards, no upsell calls. Just a report, a fix list, and silence afterward. Exactly what we wanted."

— CTO, Healthcare Platform (NDA)

"We asked for a privacy review. We got a full map of every place our own team had forgotten data was flowing."

— Founder, Consumer App (NDA)
06 — FAQ

Before you reach out.

Do you work with individuals, or only companies?
Both. Individual engagements are usually exposure mapping or secure comms setup; organizational work tends to be audits and privacy architecture review.
Will you test something without written authorization?
No. Every test runs against a signed scope of work. We won't touch infrastructure we haven't been explicitly cleared on, regardless of how the request is framed.
How is client data handled during an engagement?
Encrypted in transit and at rest, access limited to the assigned operators, and purged on sign-off unless you request otherwise in writing.
Do you publish full vulnerability details publicly?
Not by default. Public field notes are stripped of anything actionable. Full technical detail goes only to the affected party, under NDA on request.
07 — Status

Live operational feed.

nullsec@core:~
$ status --network
> checking core...
$ policy --check logging
> logging: disabled. retention: none.
$ whoami
> anonymous