bitter pill
02

services

bitter pill also works on what already exists. the network you inherited, the code you shipped, the model you just wired in, the footprint you didn’t know you had. we assess it as an adversary, find where it’s weak, prove it, and help you close the gap.

the real state of things, and what to do about it.

you don’t have to know the name of what you need. you just have to contact us.

quick list of work we don’t do: regulatory certification, compliance review, GRC, policy authoring, forensics, malware analysis.

consulting

you don’t always need a deliverable. sometimes you need someone who has seen how this goes wrong, in the room, before you commit to action.

our offer is our experience, at whatever shape fits. an afternoon pressure-testing a plan. a few days for an incident-response tiger team. a few weeks alongside a build, catching the decisions that get expensive to unmake later. an open line for when something comes up.

you set the scope and the clock. we bring the part you can’t hire in a hurry.

AI security

a model in your stack is a new attack surface, and an odd one. it can be persuaded, poisoned, or used as a bridge to whatever you connected it to, none of which classic defenses were built to notice.

before you build, we threat-model the integration: where the model can reach, what it’s trusted to do, what happens when it’s wrong, and what defenses you’ll need. on what you’ve already shipped, we review the controls and point out the gaps: input filtering that isn’t there, the model with more access than it needs, implicitly trusted output. and we’ll attack it live, probing for prompt injection, forcing leaked context, talking our way past its guardrails the way a real user eventually will.

new tech is tricky to implement safely. make sure your AI integration doesn’t let someone in.

network security review

you give us your network diagram, or you tell us there isn’t one. either way we go find what’s actually there, and lay the two side by side.

we map what you actually expose, not what the inventory says you expose — then we walk the difference with you. the host nobody remembered. the segmentation that’s flatter than the drawing. the service that was supposed to be internal. where your picture and the real thing disagree is usually where the trouble is already waiting.

you get the discrepancies, the outright problems, the spots that will hurt later if left alone, and a plain list of what to harden first.

OSINT hunt

before anyone comes after you, they read up on you. the open internet holds more about your organization than you’d guess, and none of it takes touching your systems to find.

we run that same pass. we find out what there is to know using only what’s already publicly available. the result is the picture an attacker would build before making a move. you get all of it laid out, what chains into what, and how to turn the information to your advantage.

code & configuration review

two services, one discipline: reading what you built for the flaws that don’t show at runtime.

secure code review covers your source and your infrastructure-as-code. we look for the missing check, the unsafe default, the logic that does more than intended, the accidental exposure.

secure configuration review covers the things that decide how everything talks: firewall rules, network appliance configs, the settings on critical applications. what’s open that shouldn’t be, what’s trusted that shouldn’t be, what’s a typo away from a bad day.

either review comes back with findings, severity, and clear remediation guidance.

vulnerability research

we take a target you care about and methodically find ways to break it. reverse engineering, fuzzing, picking apart how the thing actually behaves. more invasive than a scan or review. we’re mining for flaws deep beneath the surface.

you get each proof, how we reached it, what it lets an attacker do, fix recommendations, and disclosure coordination.

offensive testing

we agree on who would come after you and why, then we do that. the scope follows the motive, so what you learn is about your actual risk. adversary emulation is a point-in-time, few-holds-barred, open-ended attempt to reach something that matters, by whatever path presents itself.

if you’d rather have something more constrained, like a scoped penetration test, we’ll run that too. approach is scoped to the question; we’ll help you define what you wish to learn.

you get the full report complete with chain of events, non-technical descriptions, per-discovery technical writeups plus remediation guidance, and where your defenses held. post-engagement assistance is offered by default, but you tell us whether you need it.

private clients

everything on this page, reoriented for the person. the same assessment, review, and hardening; sized for your home network, your devices, your accounts, and whoever shares them with you.

before anything’s wrong, we build it right: private network, private cloud, secure remote access, and one-on-one teaching for anyone who’d rather understand it than outsource it.

for living out in the open, we fit the work to how exposed you are. quiet privacy for someone who wants a smaller footprint, or a hardened setup for someone whose whole living is being findable.

and when something has already happened, we handle remediation: eject whoever’s there, close the way they came in, and wipe what they touched.

private work for your private life, discreet and quiet.

05

contact

no forms, no discovery calls, no sales sequence.

tell us the problem in a paragraph. we'll answer quickly with fit and shape, or a pointer somewhere better.

contact@bitterpill.io openPGP D183..655A signal on request