About / Genaura

Two perspectives.
One clear purpose.

Genaura combines penetration testing with AI security research. We examine where applications, cloud identities and AI-enabled workflows can cross a boundary they should hold.

Test a path under written authority. Show what happened, what remains uncertain and what a defensive change should address.

Two disciplines.Shared technical accountability.

Security decisions need more than a list of alerts.

Code written by people, reused components and configuration have long shaped security risk. AI tools add new questions about what information an agent can read, which actions it can take and whose permissions it uses. In each case, the useful question is which boundary holds under test.

We test security boundaries in authorised assessments and research how AI changes those boundaries and the methods used to examine them. Assessments follow agreed scope and give technical teams an account of what was observed. Our AI-assisted testing research is in progress, not a released product.

The agreed scope, evidence and any retest should make clear what was checked—and what was not.

Offensive depth.
Defensive consequence.

We do not treat the test and the response as separate stories. An attack path is useful when it changes how a team can prevent, detect or contain it.

Red-team lens

Challenge the assumption.

Start with the access an adversary could obtain. Test whether it can cross an application, identity or operational boundary under the agreed conditions.

What can this foothold actually reach?

Blue-team lens

Improve the control.

Connect the observed path to remediation, detection coverage and operational choices. Retesting can then check the original route against the changed system.

What changes would reduce exposure or improve response?

Layered transparent planes representing permissions that must remain distinct.
Identity. Permissions. Execution.Check the conditions at every step.

Make the evidence
testable.

Method is not decoration around a technical result. It makes clear what was authorised, what was tested, and how confidently the observed evidence supports a decision.

  1. 01

    Written authority

    Every engagement starts with an agreed target boundary, permitted actions, escalation route and stop conditions.

  2. 02

    Useful evidence

    A finding should show the conditions that produced it, the path it supports and its practical limits.

  3. 03

    Defensive follow-through

    Remediation and detection work are tied to the observed path, then retesting checks what the change now prevents.

Read the engagement controls

What could
an attacker reach?

Bring the system, boundary or decision that needs a more rigorous answer. We will help define an authorised assessment that produces useful evidence for the people who must act on it.

Explore security research