NULLSEC
An independent collective operating at the intersection of offensive security research, privacy engineering and digital self-defense. We don't sell your data. We don't collect it. We help you make sure no one else can either.
Privacy first. Everything else is secondary.
Every decision we make — from how we build tools to how we run this site — starts with one question: does this expose anyone? If the answer isn't a hard no, we don't ship it.
Minimal by default
We collect nothing we don't strictly need, and we don't need much. No analytics pixels, no third-party scripts, no fingerprinting.
Encrypted end to end
Every channel we operate — comms, storage, transfer — is encrypted at rest and in transit. No exceptions, no backdoors.
Audited, not assumed
We red-team our own infrastructure the same way we'd red-team a client's. Trust is earned through verification, not branding.
What we actually do.
Research-driven security work, aimed at reducing exposure — yours or your organization's.
Adversarial Security Audits
Authorized penetration testing and red-team engagements that map real attack paths before someone else finds them first.
Privacy Architecture Review
We audit data flows end to end and strip out every unnecessary collection point, log, and third-party leak.
OSINT & Exposure Mapping
We show you exactly what's publicly discoverable about your org or your identity — and how to shut it down.
Secure Comms Deployment
Hardened, encrypted communication and infrastructure setups built for people who can't afford to be wrong about this.
Privacy is not something we protect after the fact. It's the first line we draw before a single byte moves.— NULLSEC Founding Charter
Recent intel.
A sample of the anonymized write-ups we publish once an engagement closes. The full archive lives on the intel page.
What people say once the engagement is over.
"They found things two prior audits missed, then explained exactly why those audits missed them."
"No dashboards, no upsell calls. Just a report, a fix list, and silence afterward. Exactly what we wanted."
"We asked for a privacy review. We got a full map of every place our own team had forgotten data was flowing."