Helsinki · Boston · Dubai

We find the weaknesses before someone else does.

Varihunt is a Finnish cybersecurity firm doing penetration testing, AI security testing, and compliance advisory for companies across Europe, the US, and the Gulf. We test what you've built, tell you plainly what we found, and help you fix it.

varihunt — findings.vh

$ cat VH-2026-014.txt

[FINDING VH-2026-014] Severity: HIGH

IDOR in /api/v1/invoices — cross-tenant data access

Reported → Fix verified in 48h

# redacted — full report under NDA

# methodology: OWASP WSTG · PTES

OSCP · CISSP

Certified senior testers on every engagement

OWASP · PTES

Methodology-driven, not scanner dumps

Helsinki · Boston · Dubai

EU, US, and Gulf coverage

NIS2 · ISO 27001 · SOC 2

Frameworks we test against

CERTIFIED & TRUSTED

OSCPCISSPCISAISO 27001 Lead Auditor·OWASPPTESNIS2ISO 27001SOC 2
Web App Pen Testing ·Mobile Security ·API Penetration Testing ·AI / LLM Security Testing ·ISO 27001 Support ·NIS2 Compliance Advisory ·SOC 1 Readiness ·SOC 2 Readiness ·Cloud Security Review ·GDPR Compliance ·Red Team Exercises ·Tabletop Simulations ·IT Security Audits ·PCI-DSS Advisory ·Web App Pen Testing ·Mobile Security ·API Penetration Testing ·AI / LLM Security Testing ·ISO 27001 Support ·NIS2 Compliance Advisory ·SOC 1 Readiness ·SOC 2 Readiness ·Cloud Security Review ·GDPR Compliance ·Red Team Exercises ·Tabletop Simulations ·IT Security Audits ·PCI-DSS Advisory ·

THE REALITY

Security gaps don't wait for your audit cycle.

Mid-market companies face the same threats as large enterprises, usually with fewer people to catch them. That gap is where most problems start.

01

Compliance isn't the same as security

Passing an ISO 27001 audit or ticking GDPR boxes says your paperwork is in order. It doesn't say your application will hold up against someone actually trying to break it. The two gaps are different, and both matter.

02

AI added new ways in

LLM integrations and GenAI features introduce attack patterns that didn't exist two years ago — prompt injection, indirect data leakage, model supply chain issues. Most testing teams haven't caught up. We have.

03

Modern architecture means more surface

Every API endpoint, container, and third-party integration is a door. Microservices and cloud-native setups multiply them. They need someone who understands the architecture to assess them properly.

04

Slow detection is what actually costs you

Attackers sit inside networks for months on average before anyone notices. Proactive testing finds the problems while they're still cheap to fix — not after the incident review.

varihunt — scope.vh

$ varihunt scope --engagement VH-2026-021

[+] target: acme-bank.example.com

[+] surfaces: web · api · mobile

[+] rules: OWASP WSTG · PTES

# scoping call → threat model → test plan

[✓] senior tester assigned: OSCP · CISSP

[✓] no handoff — same engineer end-to-end

$

HOW WE WORK

Engineers doing the work, not handing it off.

The people who scope your engagement are the ones who run it. No sales-to-delivery handoff where context gets lost, and no junior team running the testing while a senior signs the report.

You get the same people through scoping, testing, reporting, and re-test — so the work stays consistent and the findings stay contextual to your environment.

WHAT WE DO

Ten services, covering the surfaces that matter.

From application testing to compliance advisory, each engagement combines automated tooling with manual expertise — and is delivered with clear, prioritised output.

WAPT

Web Application Pen Testing

Manual-first testing against OWASP, business logic flaws, and authentication weaknesses — not just an automated scan with a report on top.

Mobile

Mobile Application Testing

iOS and Android assessments covering reverse engineering, insecure storage, certificate pinning, and runtime manipulation, mapped to OWASP MASVS.

API

API Security Testing

REST, GraphQL, and SOAP APIs — BOLA, mass assignment, rate limiting gaps, and broken authorisation across your full API surface.

AI/LLM

AI / LLM Security Testing

Hands-on testing for products built on large language models — prompt injection, jailbreaks, RAG pipeline weaknesses, and supply chain risks.

Audit

IT Security and Audit Services

Audits mapped to ISO 27001, GDPR, NIS2, DORA, SOC 1 and SOC 2 — gap analyses and roadmaps your CISO and board can actually act on.

TTX

Tabletop and Desktop Exercises

Facilitated incident response simulations for security and leadership teams. We pressure-test your playbooks before a real event does.

WHY VARIHUNT

A partner, not a scanner with a logo.

The difference between a tool-generated report and real security improvement is the depth of the people doing the work.

01

Manual work, not just scanners

Automation finds the obvious things quickly. Our engineers go further — chaining findings, testing business logic, and checking the things tools are structurally blind to. Both, every time.

02

Reports your engineers will actually read

Each finding gets severity, proof of concept, business context, and prioritised fixes. No wall of CVEs with no idea what to do next.

03

Re-test included, not extra

After your team remediates, we re-test and verify the fixes hold — then issue an attestation letter. We don't consider the engagement done until that's confirmed.

04

Real AI security experience

We've tested GenAI products in production, not just read the OWASP LLM Top 10 slides. That difference shows up in what we find.

05

People who've done this work before

Our consultants are certified, but more importantly they're actively testing — across financial services, healthcare, SaaS, public sector, and critical infrastructure.

06

Three offices, one team

Helsinki, Westford (MA), and Dubai. We work in your timezone and within your regulatory context — EU, US, or Gulf — without handing you off to a remote subcontractor.

FRAMEWORKS AND STANDARDS

We follow the established standards, then go further where they end.

  • OWASP Testing Guide (Web + Mobile)
  • OWASP LLM Top 10
  • PTES — Penetration Testing Execution Standard
  • NIST Cybersecurity Framework
  • MITRE ATT&CK
  • ISO/IEC 27001 + 27002
  • CVSS v3.1 scoring
  • GDPR / NIS2 alignment

AN ENGAGEMENT, START TO FINISH

What working with us actually looks like.

Structured and collaborative from kick-off to sign-off. Clear scope, regular updates, and a re-test built in — not an optional extra.

01

Scoping call

We agree on targets, rules of engagement, timelines, and success criteria together. Nothing starts without a clear, shared scope.

02

Threat modelling

We map your attack surface, identify high-value targets, and build a test plan specific to your environment — not a generic checklist.

03

Active testing

Sprint-based execution with regular progress visibility. You're not waiting until the end for a report to know what's happening.

04

Findings report

An executive summary for leadership and a full technical report for engineering. Every finding includes severity, PoC, and remediation guidance.

05

Re-test and sign-off

Complimentary re-test once you've remediated. Verified fixes confirmed, attestation letter issued, engagement closed.

SECTORS WE WORK IN

Sector context that finds business-logic flaws.

Testing without industry understanding misses the flaws that matter most. Our team brings experience from the sectors below to every engagement.

Financial services and fintech

PCI-DSS testing, open banking API security, transaction logic, and regulatory audit support.

Healthcare and medtech

HL7/FHIR API security, patient data protection, HIPAA-aligned testing, connected device reviews.

E-commerce and retail

Payment gateway security, checkout logic testing, loyalty fraud, customer data protection.

SaaS and technology

Multi-tenant architecture security, API hardening, CI/CD review, cloud-native assessments.

Manufacturing and OT

IT/OT convergence, industrial control systems, SCADA assessments, supply chain risk.

Public sector and government

NIS2 advisory, critical infrastructure protection, secure digital services across the EU and Gulf.

Education and edtech

Student data privacy, LMS security, identity and access management reviews.

Startups and scale-ups

Security-by-design reviews, pre-funding posture assessments, investor-ready audit reports.

COMPLIANCE ALIGNMENT

Findings mapped to the frameworks you answer to.

We structure engagements to support your compliance programme directly — speaking the language of your auditors, your board, and your customers.

GDPR

EU data protection

ISO 27001

ISMS implementation and audit support

NIS2

EU cyber resilience directive

SOC 1

Financial controls assurance

SOC 2

Trust services criteria

PCI-DSS

Payment card industry standard

EU AI Act

AI risk compliance

DORA

Digital operational resilience

WHERE WE ARE

Local teams, three regions.

We deliver engagements in your timezone and within your regulatory context — EU, US, or Gulf.

🇫🇮

Helsinki, Finland

European headquarters

Our Nordic base, serving European mid-market and enterprise clients across GDPR, ISO 27001, NIS2, and DORA work.

Metsänvartijantie 2, 02720 Espoo, Finland
info@varihunt.com+358 445420212
🇺🇸

Westford, Massachusetts

North America

Our US office serves American technology companies and enterprises needing SOC 1, SOC 2, HIPAA, and NIST-aligned assessments.

12 Dempsey Way, Westford, MA 01886, USA
info@varihunt.com+1 339 927 7250
🇦🇪

Dubai, UAE

Middle East and Gulf

Our Gulf hub covers the region's fast-growing enterprise sector — fintech, government, and critical infrastructure.

PO BOX 99058, Dubai, UAE
info@varihunt.com+971 50 557 7970

CORE TEAM

The people behind the work.

Varihunt brings together experienced cybersecurity, governance, cloud infrastructure and technology leadership professionals to support customers that need practical execution, clear accountability and trusted delivery.

BS

Bhaskar Sukumar

IT Security Audit & Cyber Risk Lead

Bhaskar brings 16+ years of IT, cybersecurity and audit experience from the banking sector. His expertise covers cybersecurity audits, regulatory audits, disaster recovery, business continuity, cloud security, identity and access management, vulnerability assessment and IT risk remediation.

CREDENTIALS

CISA | ISO 27001:2022 Lead Auditor | VMware Certified Professional | Microsoft Certified System Administrator

FOCUS AREAS

IT AuditCybersecurity AuditCloud SecurityIAMDR/BCPRegulatory Compliance
D

Danvanthini

GRC & Information Security Consultant

Danvanthini is a GRC and information security professional with experience across ISO 27001, SOC 2 Type II, GDPR and DPDPA compliance. She supports organizations with gap assessments, risk assessments, control evaluations, audit readiness and compliance documentation.

CREDENTIALS

ISO 27001:2022 Lead Auditor

FOCUS AREAS

GRCISO 27001SOC 2GDPRDPDPARisk AssessmentAudit Readiness
KN

Kousalya N

Chief Technology Officer

Kousalya is a technology leader with 11 years of experience in cloud infrastructure, product engineering, system architecture and engineering team leadership. She has built scalable technology platforms, led digital transformation initiatives and managed engineering teams across multiple product lines.

FOCUS AREAS

Cloud ArchitectureDevOpsProduct EngineeringMicroservicesTeam ScalingSystem Design
Meet the team who'll test your systems →

Find your weaknesses before someone else does.

Book a no-obligation scoping call. We'll assess your attack surface and recommend the right engagement — without overselling a package you don't need.

Request a security assessment

We respond within one business day. All enquiries handled in confidence.