Recon · Exploit · Report

Everything you ship has a blind spot. We find it in the dark.

NYX SEC is an offensive security and AI red-teaming consultancy in Tbilisi. We think like the adversary — probing your applications, infrastructure, and AI systems for the weaknesses real attackers will reach for first.

Request an engagement See what we test
Operational/ Tbilisi, Georgia / Offensive security / AI red teaming

Who we are

Built to think like the attacker.

NYX SEC exists to bring real adversarial testing to the Georgian market — especially to the companies now building AI agents and LLM-powered products, where almost no local testing capability exists.

We don't run a scanner and hand you a PDF. We attack your systems by hand, the way a motivated adversary would, then show you exactly how we got in and how to close the door behind us.


What we do

Four ways we put your defenses under pressure.

Our focus 01

Adversarial AI Testing

Your LLM apps and AI agents, attacked the way a real adversary would — not benchmarked, broken.

  • Prompt injection & jailbreaks
  • RAG poisoning & retrieval hijacking
  • Agent & tool privilege escalation
  • Data exfiltration via model output
  • Mapped to the OWASP LLM Top 10
02

Penetration Testing

Web, network, and infrastructure — tested by hand, end to end.

  • External & internal network
  • Web & API application testing
  • Authentication & access control
  • Post-exploitation & lateral movement
03

Threat Modeling & Advisory

Know where you're exposed before anyone tests it for you.

  • Architecture & attack-surface review
  • AI/agent design risk assessment
  • Secure-by-design guidance
  • Pre-launch readiness checks
04

Security Awareness & Training

The human layer is part of the attack surface. We harden it.

  • Phishing simulation campaigns
  • Staff & developer training
  • Programs for all ages, incl. youth
  • Delivered in Georgian or English

How an engagement runs

Four phases. No surprises.

Phase 01

Scope

We define targets, boundaries, and rules of engagement in writing — so everyone knows what's in scope before we touch anything.

Phase 02

Attack

We map the attack surface, then attempt real exploitation by hand — the same path a motivated adversary would take.

Phase 03

Report

Every finding lands with evidence, business impact, severity, and exact reproduction steps. No filler, no scanner dumps.

Phase 04

Retest

Once you've remediated, we come back and verify the fixes actually hold against the original attack.


Engagement models

Scoped to your risk, not a fixed template.

Every system is different, so every quote is built around your actual targets. The models below are starting points — reach out and we'll scope the real thing.

Focused Assessment
from ₾2,500 / engagement

A single, well-defined target tested in depth — one application, network, or AI system.

  • One scoped target
  • Manual testing & exploitation
  • Full findings report
  • One round of retest
Request a quote
AI Red Team Sprint
from ₾4,500 / sprint

A time-boxed adversarial engagement against your LLM product or agent system.

  • OWASP LLM Top 10 coverage
  • Prompt injection, RAG & agent attacks
  • Exploit chains with proof
  • Remediation walkthrough + retest
Request a quote
Retainer
Custom / ongoing

Continuous testing that moves at the speed you ship — for teams releasing often.

  • Recurring testing cycles
  • Coverage for new features & releases
  • Priority scheduling
  • Quarterly posture review
Let's talk

Get in touch

Find your blind spot before an attacker does.

Tell us what you're building and what you're worried about. We'll come back with a scope, a timeline, and a quote.

[email protected] LinkedIn →
Tbilisi, Georgia/ Response within 1 business day/ NDA on request