Human-led penetration testing for web, API, network, cloud, mobile, source code and AI systems. EU based. Findings appear in Outer Core while the test is still running.
We are an Estonia-based offensive security collective. We choose the testers, set the standard, and deliver each engagement through Outer Core, the platform where confirmed findings show up as they are found rather than in a document weeks later. You work directly with the tester doing the work, drive each finding to closed, and retest fixes for a year.
The operating entity is Outer Core OÜ, registered in Estonia.
| Surface | What it covers |
|---|---|
| Web application | Auth, access control and business logic |
| API | REST, GraphQL and SOAP |
| Network | External and internal |
| Cloud | IAM and configuration across AWS, Azure and GCP |
| Mobile | Android and iOS, against OWASP MASVS |
| Source code | White-box review that finds the flaw behind the bug |
| AI and LLM | Testing of AI and LLM systems |
| Red teaming | Objective-led adversary simulation |
| Social engineering | Human-layer testing |
Found something in our own systems? Email security@outer-heaven.com. The same address, and what we consider in and out of scope, is published at outer-heaven.com/.well-known/security.txt.
- outer-heaven.com
- How it works: scope and approval through to a reviewed report
- Sample report: built from fictional systems and findings, so nothing in it describes a real customer
- Work with us: experienced testers can apply to the bench
- Contact: tell us what needs testing and we scope it