Penetration testing and code review for software companies.

Manual testing for SOC 2, ISO 27001, HIPAA, and customer security reviews.

Contact us

Penetration Testing

Twice the manual hours of a typical pentest.

Our testing is rigorous, simulating real-world attacks across applications, APIs, networks, and infrastructure. We focus on vulnerability chaining, business logic, authentication, and authorization.

Coverage
  • Architecture, Design, Threat Modeling
  • Authentication
  • Session Management
  • Access Control
  • Validation, Sanitization and Encoding
  • Stored Cryptography
  • Error Handling and Logging
  • Data Protection
  • Communications
  • Malicious Code
  • Business Logic
  • File and Resources
  • API and Web Service
  • Configuration
How we work
01

Scope

A founder scopes every engagement: targets, roles, goals, and what we need from you.

02

Test

Three weeks of manual testing. We share critical vulnerabilities in real-time.

03

Report

Reproducible findings with severity and fixes, written for the engineer who has to fix them. The report stays current as fixes land, so you can send it to a partner anytime.

04

Retest

Retesting is included, with no expiration.

Testing follows the OWASP ASVS and Testing Guide, NIST SP 800-53A, and OSSTMM.

Work that outlasts the engagement.

We test for three weeks and stay on for the year: a shared Slack channel for remediation, architecture questions, and vendor and package selection. A lightweight outsourced CISO, included in every engagement.

We take on a limited number of engagements, with the boutique service we wanted as founders and CTOs: retesting included, clear findings, and actionable remediation advice.

Pricing is based on scope and the number of hours of skilled human attention against the surface we're testing.

Code Review

Some vulnerabilities can only be found by reading the code.

With source access we cover more in less time and catch the classes of bugs gray-box penetration testing can't reach. We review code in most languages, and pair a review with a penetration test of the same application when you want both.

Contact us

Founders

The people on this page scope, lead, and review every engagement.

William Lovely

William Lovely

Previously Chief Product Officer, Underdog; co-founder and CEO, Federacy (YC S18).

William was Chief Product Officer at Underdog, where he led a 250-person product, engineering, security, design, and data organization in a highly regulated industry, through the company's growth to its $1.3 billion acquisition by IG Group. Before Underdog he co-founded Federacy with James, and before that founded two venture-backed companies, from connected hardware to manufacturing, including AccelGolf (Techstars Boston '09, acquired) and Pistol Lake. He has been building software products for twenty years.

James Sulinski

James Sulinski

Previously VP, Infrastructure, MoPub (acquired by Twitter); co-founder and CTO, Federacy (YC S18).

James has been building software for twenty-five years, much of it as a CTO, and has worked in security for almost two decades, starting with helping build an ISP at age fifteen. He was one of the early engineers at MoPub, then the largest mobile ad exchange, where he led infrastructure through its acquisition by Twitter. MoPub was later sold to AppLovin for $1.05 billion. Before that he was an infrastructure engineer at drop.io, acquired by Facebook. He founded SF DevOps and NYC DevOps, then the two largest DevOps meetups in the world, and was co-founder and CTO of AccelGolf and Pistol Lake. At Federacy he personally triaged thousands of bug bounty reports and led over a hundred penetration tests. He has also contributed code to numerous open source projects, including Kubernetes, Chef, Vuls, and Salus.

An elite team of security researchers

We work in small teams and focus on vulnerability chaining, business logic, authentication, and authorization. Our team holds OSCP, OSCE, CISSP, CREST, and CEH certifications, with backgrounds at MIT, Carnegie Mellon, CERT, Google, Twitter, and many more.

Federacy: Prior to Castine, we founded Federacy as part of Y Combinator in 2018. Federacy was a penetration testing and bug bounty platform built to make rigorous security testing accessible to startups. We ran it for eight years, performing more than 130 penetration tests and over 10,000 hours of security research for fintech, healthtech, and developer-tool companies, including AngelList.

Who we work with

Companies that handle sensitive data.

Startups and technology companies. Fintech, healthtech, developer tools, and infrastructure. From seed stage through growth.

Why they come
  • Care deeply about security
  • A SOC 2 or ISO 27001 audit
  • A customer or partner security review
  • A launch or a new surface
  • Diligence ahead of a raise or acquisition

If what you need is a fast check-the-box test, there are cheaper places to get one. We're happy to make introductions.

Contact us

Want to know what an attacker would find?

Email team@castinesecurity.com. The founders reply within a day, and the first call is scoping, not a sales team.

Contact us

We're always looking for exceptional security researchers. Please reach out at team@castinesecurity.com.