You are giving us access to systems and data that matter. This page sets out how we test, how we handle what we see, how we use AI, and who you are working with.
How we test
Every engagement starts with paperwork, not traffic. You know what we will touch, when, and how, before we touch it.
Methodology aligned with
Red teaming follows MITRE ATT&CK.
How we handle your data
You decide who sees what we find. Your contract sets what happens to it when we finish.
How we use AI
Senior engineers lead every engagement and AI tools assist them. The judgement, and the sign-off, stay with a person.
Built into the products we run
Contracts
We're happy to work under your NDA, or ours, from the first scoping call.
For engagements that involve personal data, we put data processing terms in place with you.
Who you work with
Cyphlon LLC has been based in Dubai since 2016. The team holds CISSP, CISM, OSCP, CCSP certifications, and an advisory board of practitioners from banking, healthcare and govtech advises on our work in regulated industries.
Report a vulnerability
Email [email protected] with what you found and how to reproduce it.
Book a call
Pick a time that suits you. We'll talk through what you're building and where your security stands, then suggest where to start.
Cyphlon
An introductory call with our engineers about any engagement: a pentest, continuous testing, managed AppSec, security engineering, agentic AI security or a fractional CISO. We'll ask about your stack, your deadlines and what your customers or auditors expect, and tell you plainly if we're not the right fit.
Cyphlon
About Us
Cyphlon is a security engineering company. We implement DevSecOps, application security, Zero Trust and supply-chain security, build the products we deploy, and publish our research.
© 2026 Cyphlon LLC · Dubai, United Arab Emirates · Founded 2016