02
The record
Clients are never named and never identifiable. What we publish is the sector, the question, and the outcome.
Failure point foundFintech
Saudi Arabia
262KRPS
Peak load reached
A mobile banking API, tested to the point it broke.
What they asked
A regulated investment platform wanted to know how much load their customer-facing API could take before customers noticed — and where, exactly, the failure would happen.
What we found
It broke earlier than expected. Under sustained load the service stopped answering, and the outage was visible worldwide. Customers could not sign in or open an account while it lasted. Every part of that was captured under an authorised, scheduled test rather than discovered during a real attack.
What happened next
We delivered a prioritised remediation roadmap ordered by risk reduced against effort required, with a retest booked to confirm the fixes hold.
Fixed and re-verifiedTechnology platform
Saudi Arabia
5.89MRPS
Peak load absorbed
A critical weakness found and closed inside one engagement.
What they asked
A production platform sitting behind a well-known protection layer wanted confirmation that the protection actually held under pressure, not just that it was switched on.
What we found
It did not, at first. One class of traffic slipped past the defences that were supposed to stop it and took the service down. Their team was notified immediately and applied a fix while the engagement was still running.
What happened next
We retested the same weakness at higher volume and for longer. It held. The finding closed as remediated with evidence, not as patched and assumed.
Held at every levelNetwork operator
Own ASN
644Gbps
Peak traffic absorbed
Network-wide testing that came back clean.
What they asked
A network operator needed independent confirmation that their protection held across their whole address space, not just in front of one service — the kind of evidence a regulator expects on file.
What we found
It held. Every level tested was absorbed and filtered with no downtime, from raw network floods through to attacks aimed at the applications themselves.
What happened next
A clean pass, documented for compliance review, with testing continuing on a semi-annual cadence.
Reports are confidential to the client. Nothing identifying an engagement — names, addresses, infrastructure detail or the techniques used — is published here or anywhere else.