About

Security work at the smallest scale, where it actually breaks

We took our name from Max Planck, the physicist who showed that nature sets its rules at the smallest scale. Security fails the same way. A single stale credential, one permissive firewall rule, one unvalidated parameter. Our job is to find those details before someone else does.

Who We Are

A small firm, on purpose

Planck Defense & Aerospace is a focused team of senior security practitioners. Our work spans three connected disciplines: offensive security, organization-specific threat intelligence, and dedicated VPN infrastructure. Every person on the team carries an operational role. Nobody here only sells, and nobody only manages.

The aerospace in our name reflects where we set the bar. Defense, aerospace, and other high-assurance industries expect precision, documented method, and controlled handling of sensitive material. We apply that standard to every client, including the finance, healthcare, SaaS, energy, manufacturing, and government contracting organizations we work with.

We will not tell you a founding story or quote a headcount. What we can tell you is exactly how an engagement with us runs, what you receive, and who does the work. Those are the claims that matter, and they are the ones you can verify.

What defines our engagements

  • Testers you talk to directly. Questions during an engagement go to the person with their hands on your systems, not through an account layer.
  • Scopes we can deliver in full. We size engagements to the time real testing takes. If a scope cannot be covered properly, we say so before we sign.
  • Findings backed by evidence. Every issue we report ships with reproduction steps, request and response data or equivalent artifacts, and a CVSS v3.1 rating you can defend internally.
  • Advice that survives contact with engineering reality. Remediation guidance is written for the team that has to implement it, with awareness of legacy constraints, release cycles, and what a fix costs in practice.
Principles

Four rules we do not bend

These are not values statements. They are operating constraints that shape how we scope, staff, test, and report.

Evidence over noise

Severity means something in our reports. A critical finding is one we can demonstrate, with a working reproduction path and a clear statement of impact. We do not pad reports with informational filler dressed up as risk, and we do not inflate ratings to make an engagement look productive. Every finding is reproducible by your team from the report alone.

Senior work only

There is no bench of juniors learning on your systems. The practitioners who scope your engagement are the ones who execute it. That keeps teams small and calendars honest, and it means the person reading your architecture diagram has seen a hundred like it and knows where the same mistakes tend to hide.

Straight talk

If something you ask for is out of scope, unsafe to test in production, or simply low risk, we say so. If a finding is a genuine problem but unlikely to be exploited in your environment, the report says that too. You are paying for judgment, not for a longer list, and judgment sometimes means telling you a thing you flagged is fine.

Confidential by default

We sign an NDA before scoping begins, not after. Data handling, retention, and destruction are defined in writing for every engagement. Your findings are never reused as marketing material, never anonymized into case studies without written permission, and never disclosed to anyone you have not authorized.

How We Work

The operating model behind every engagement

Three structural choices, made deliberately, that determine what working with us feels like in practice.

01

Small teams with direct lines

Each engagement is staffed by a small team, and you get direct contact with the people doing the work. When a tester finds something serious mid-engagement, you hear it from the tester, that day, not in the report three weeks later. When your engineers have a question about a finding, they ask the person who wrote it. This removes the translation loss that turns precise technical findings into vague action items.

02

Fixed, honest scopes

A scope is a promise about depth, not just a list of assets. Before we agree to one, we check it against the hours the work demands: authenticated and unauthenticated coverage, the attack classes relevant to the target, and enough room for the unexpected paths that produce the findings that matter. We would rather decline work than dilute it. When a scope and a budget do not fit, we tell you what we would cut and why, and let you make the call with full information.

03

Long relationships over transactions

Most of the value we deliver arrives after the first report: in the retest that confirms your fixes actually closed the hole, in the question your platform team asks six weeks later, in the second engagement that starts from accumulated knowledge of your environment instead of from zero. We include one retest of fixed findings in every assessment and we keep engagement records so continuity is real, not a slide in a sales deck.

Responsible Disclosure

Coordinated disclosure, practiced and supported

We practice coordinated disclosure in our own research and we support it as a norm for the industry. When our work surfaces a vulnerability in third-party software, we report it to the vendor privately, allow reasonable time for a fix, and coordinate publication so users are protected before details are public.

The same standard applies to us. If you believe you have found a security issue in our infrastructure or services, write to [email protected]. That address reaches the team that handles reports about our own systems, not a ticket queue.

  • Acknowledged promptly. Reports to [email protected] receive a human response, and good-faith reports are never met with legal threats.
  • Investigated by engineers. The people who run our infrastructure triage every report and keep you informed of the outcome.
  • Credited when fixed. We credit researchers who report responsibly, unless you prefer to stay anonymous.
Get Started

Talk to the people who will do the work

A short scoping conversation is enough to tell you whether we are the right fit. No account managers, no scripted pitch.