About us / Founder-led

Web and security under one responsibility.

Web design, web development, and offensive security sit with the same people. Interfaces that hand over cleanly — and assessments with traceable evidence. No anonymous handoff.

Direct accountabilityNo anonymous handoff
Valentin Dobrykov
Valentin DobrykovOSINT · CASP · Security
Alina Rak
Alina RakPentest · Web exploitation
Founder-ledDirect accountability

Analysis, build, and review stay with the people doing the work.

Security depthReal assessment experience

HTB Academy, CASP, and offensive security — not agency promises.

One processBuild, handover, review

Website, rights, handover, and security review run through one process.

Position

Why we exist.

We started this because we were tired of beautiful websites collapsing at the first serious test, and of honest security disappearing behind compliance theatre.

The premise is simple: anyone who builds brands should know how to break them. Anyone who tests systems should understand how they are created. That is why both disciplines run through the same delivery process here.

We work with owners, executives, and IT leaders in mid-market companies who carry responsibility and recognize empty phrases. What we promise goes into the contract. What we find is disclosed clearly.

We are small because we choose to be small. Every project stays with the people who analyze, build, and test it.

Principles / 04

What you can expect from us.

/ 01

Transparent price, clear milestones.

Fixed prices where the scope fits. No hidden costs, no hourly guesswork.

/ 02

Evidence over opinion.

Every design decision gets a reason, every security finding a reproducible proof.

/ 03

You keep the rights.

Code, designs, content, and reports — yours after final invoice.

/ 04

Confidential & NDA-ready.

Sensitive findings move through a controlled communication path.

Team / 05

You speak directly with the people leading the project.

Valentin Dobrykov

Valentin Dobrykov

Founder · OSINT & CASP methodology

In cybersecurity since 2015. Co-founder of HTB Academy (4M+ learners), co-author of CPTS and author of CJCA — both recognized by CISA/NICCS. Over ten years focused on OSINT and information gathering. Today he personally leads every CASP engagement and holds the exclusive DACH license from OSINT-CORE GmbH. Findings researched manually, sources documented, recommendations signed under his own name.

OSCPCASP-LeadOSINTPentest
Alina Rak

Alina Rak

Penetration Tester · Web Exploitation

University of Applied Sciences degree with distinction in translation (EN/DE), then a technical path via Namecheap and AWS Cloud Practitioner. Today offensive security: Windows, Linux, Active Directory, and web applications — vulnerability analysis and privilege escalation. In pentest and audit engagements she is the direct counterpart for engineering and security teams; she writes every report herself.

CPTSCWESPentestOSINTOWASP

No anonymous consultant handoff: whoever analyzes your findings also writes the report. Whoever designs your interface also handles the implementation handover.

History / 06

How we got here.

2015

First steps in cybersecurity.

Valentin starts as a penetration tester and IT security consultant. First engagements in OSINT, pentests, and audits, alongside intensive self-study focused on information gathering as the most critical phase of a cyberattack.

OSINTPentestAudit
2019

Independent work & Baseline course.

Publication of the penetration-testing course Baseline. Acquired by HackTheBox Ltd. after a few months and used as the foundation of the HTB Academy platform.

BaselineHTBTraining
2020

Co-founder of HTB Academy.

Built HTB Academy as co-founder — now more than 4 million learners worldwide. Dozens of training modules, co-author of CPTS and author of CJCA. Both certifications recognized and offered by CISA/NICCS.

HTB AcademyCPTS / CJCANICCS / CISA
Since then

Pentests, audits, forensics & CISO support.

Alongside HTB work: penetration tests, IT security audits, forensics, and supporting several SMBs as an external IT security officer. Over ten years of deep OSINT specialization.

ForensikAuditOSINT
2024

SHELL-AFFECT & CASP DACH license.

Web development, SEO, and cybersecurity under one responsibility. Exclusive DACH license for the CASP methodology (OSINT-CORE GmbH) — every finding researched manually, every recommendation under his own name.

CASPOSINT-CORESHELL-AFFECT
Experience fromOSINTPenetration TestingWeb developmentSEO
Next step

Let's talk about your digital risk or your next web project.

30 minutes are enough to assess whether we can help usefully.

Speak directly with accountable peopleNext step
Request a conversation