Trust

How we work inside your systems

You are giving us access to systems and data that matter. This page sets out how we test, how we handle what we see, how we use AI, and who you are working with.

How we test

Nothing is tested until it is authorised in writing

Every engagement starts with paperwork, not traffic. You know what we will touch, when, and how, before we touch it.

Methodology aligned with

OWASP WSTGOWASP ASVSOWASP API Security Top 10PTESNIST SP 800-115

Red teaming follows MITRE ATT&CK.

  • Written authorisation and an agreed scope before any testing starts.
  • Rules of engagement and testing windows agreed with you in advance.
  • We prefer to test in staging. Where production is in scope, we work to read-only rules.

How we handle your data

Least access, shared only with the people you name

You decide who sees what we find. Your contract sets what happens to it when we finish.

  • Access limited to what the agreed scope requires.
  • Credentials and findings shared only with the contacts you name.
  • Test data and credentials removed at the end of the engagement, as agreed in your contract.

How we use AI

Engineers lead. AI assists.

Senior engineers lead every engagement and AI tools assist them. The judgement, and the sign-off, stay with a person.

  • A person approves every AI verdict and every fix.
  • Our tools never hand your credentials to an AI model.
  • If your policies restrict AI tooling, tell us at scoping and we'll plan the engagement around them.

Built into the products we run

DSO
  • Pentests only hosts you prove you own, by DNS TXT record or file.
  • Deterministic scanners run in containers with no network access, and your code is deleted after each scan.
  • The AI never receives the repository clone credential.
  • Staging recommended; production gets read-only rules.
OpsMaxx
  • AI agents never receive passwords, keys, hostnames or a root shell.
  • Every tool is set to allow, ask or deny, and every action is audited.
  • Secrets are kept in a vault encrypted with AES-256-GCM.

Contracts

Confidentiality from the first conversation

Non-disclosure

We're happy to work under your NDA, or ours, from the first scoping call.

Data processing

For engagements that involve personal data, we put data processing terms in place with you.

Who you work with

A named company, with named people

Cyphlon LLC has been based in Dubai since 2016. The team holds CISSP, CISM, OSCP, CCSP certifications, and an advisory board of practitioners from banking, healthcare and govtech advises on our work in regulated industries.

  • Zeeshan Sultan CEO
  • Navaid Ansari Head of Compliance
  • Martin K Head of Finance and Operations
More about Cyphlon →
Legal entity
Cyphlon LLC
Headquarters
Dubai, United Arab Emirates
Founded
2016
Team certifications
CISSP, CISM, OSCP, CCSP
Advisory board
Banking, healthcare, govtech

Report a vulnerability

Found an issue in our products or this site?

Email [email protected] with what you found and how to reproduce it.

Book a call

Book a 30-minute call

Pick a time that suits you. We'll talk through what you're building and where your security stands, then suggest where to start.

Logo

Cyphlon

1:1 Consultation Call

30 min Google Meet

An introductory call with our engineers about any engagement: a pentest, continuous testing, managed AppSec, security engineering, agentic AI security or a fractional CISO. We'll ask about your stack, your deadlines and what your customers or auditors expect, and tell you plainly if we're not the right fit.

Logo Cyphlon

Research and tool releases by email

Unsubscribe any time. Privacy Policy

About Us

Cyphlon is a security engineering company. We implement DevSecOps, application security, Zero Trust and supply-chain security, build the products we deploy, and publish our research.

[email protected]

© 2026 Cyphlon LLC · Dubai, United Arab Emirates · Founded 2016

Privacy Policy Terms of Use