Vilkas Cyber
Offensive security · pentest · red team · AppSec
Specialized in manual penetration testing, red teaming, and application security — focused on real vulnerabilities rather than scanner-only reports.
Web design, web development, and offensive security sit with the same people. Interfaces that hand over cleanly — and assessments with traceable evidence. No anonymous handoff.


Analysis, build, and review stay with the people doing the work.
HTB Academy, CASP, and offensive security — not agency promises.
Website, rights, handover, and security review run through one process.
Collaboration and exchange with vetted security firms — shown with their consent. Not client logos, no name-dropping without permission.
Offensive security · pentest · red team · AppSec
Specialized in manual penetration testing, red teaming, and application security — focused on real vulnerabilities rather than scanner-only reports.
Offensive & defensive security services
Security provider with offensive and defensive services — a practice partner in the cyber ecosystem.
We started this because we were tired of beautiful websites collapsing at the first serious test, and of honest security disappearing behind compliance theatre.
The premise is simple: anyone who builds brands should know how to break them. Anyone who tests systems should understand how they are created. That is why both disciplines run through the same delivery process here.
We work with owners, executives, and IT leaders in mid-market companies who carry responsibility and recognize empty phrases. What we promise goes into the contract. What we find is disclosed clearly.
We are small because we choose to be small. Every project stays with the people who analyze, build, and test it.
Fixed prices where the scope fits. No hidden costs, no hourly guesswork.
Every design decision gets a reason, every security finding a reproducible proof.
Code, designs, content, and reports — yours after final invoice.
Sensitive findings move through a controlled communication path.

In cybersecurity since 2015. Co-founder of HTB Academy (4M+ learners), co-author of CPTS and author of CJCA — both recognized by CISA/NICCS. Over ten years focused on OSINT and information gathering. Today he personally leads every CASP engagement and holds the exclusive DACH license from OSINT-CORE GmbH. Findings researched manually, sources documented, recommendations signed under his own name.

Penetration Tester · Web Exploitation
University of Applied Sciences degree with distinction in translation (EN/DE), then a technical path via Namecheap and AWS Cloud Practitioner. Today offensive security: Windows, Linux, Active Directory, and web applications — vulnerability analysis and privilege escalation. In pentest and audit engagements she is the direct counterpart for engineering and security teams; she writes every report herself.
No anonymous consultant handoff: whoever analyzes your findings also writes the report. Whoever designs your interface also handles the implementation handover.
Valentin starts as a penetration tester and IT security consultant. First engagements in OSINT, pentests, and audits, alongside intensive self-study focused on information gathering as the most critical phase of a cyberattack.
Publication of the penetration-testing course Baseline. Acquired by HackTheBox Ltd. after a few months and used as the foundation of the HTB Academy platform.
Built HTB Academy as co-founder — now more than 4 million learners worldwide. Dozens of training modules, co-author of CPTS and author of CJCA. Both certifications recognized and offered by CISA/NICCS.
Alongside HTB work: penetration tests, IT security audits, forensics, and supporting several SMBs as an external IT security officer. Over ten years of deep OSINT specialization.
Web development, SEO, and cybersecurity under one responsibility. Exclusive DACH license for the CASP methodology (OSINT-CORE GmbH) — every finding researched manually, every recommendation under his own name.
30 minutes are enough to assess whether we can help usefully.