About AFINE

Your permanent, certified team with over 150 CVEs published.

At AFINE, we break Fortune 500 enterprises for a living. Our penetration testing team is OSCP certified - every researcher holds core offensive security certifications, with most holding OSCE, OSWE, OSEP and CRTO. We've published CVEs in SAP, Microsoft, CyberArk, Palo Alto Networks and more.

We are ISO 27001 Certified

AFINE is ISO 27001 certified. Our penetration testing team protects your data with the same rigor we use to break your security. This international standard ensures systematic controls for managing sensitive information throughout our offensive security operations.

AFINE's ISO 27001 certification badge

We carry professional liability insurance

AFINE maintains professional liability insurance covering all offensive security operations. This protects both our clients and us against financial exposure from testing activities or unexpected incidents.

AFINE's Professional Liability Insurance badge

AFINE Developed DASVS

At AFINE we created the Desktop Application Security Verification Standard (DASVS) - It's comprehensive security framework for desktop applications. DASVS provides security teams with actionable requirements for testing Windows, macOS, and Linux applications against real-world threats.

AFINE's Professional Liability Insurance badge

Our Penetration Testing Team

At AFINE, you work with researchers who know what breaks in production. Our penetration testing team has spent 10 years testing banking systems, payment infrastructure, and critical applications. When AFINE reports findings, your developers know what to fix, and your leadership understands the risk.

Artur Byszko
CEO

Leads AFINE with over 20 years in cybersecurity. Artur worked at Big Four firms, co-founded a security consultancy, and led security at one of Europe's largest chemical groups. At AFINE, he drives company strategy and oversees operations. Holds OSCP, OSCE, CISSP, CISA, and CSSA certifications.

Michał Majchrowicz
IoT & Hardware Pentester

Specializes in breaking IoT systems and embedded devices. Michał tests industrial control systems, connected medical devices, and smart infrastructure used in manufacturing and critical facilities. His expertise spans hardware security testing, firmware analysis, and protocols securing industrial environments.

Sławomir Zakrzewski
Web & Cloud Infrastructure Penetration Tester

Specializes in web application and cloud infrastructure security. Slawomir breaks enterprise platforms and APIs, finding vulnerabilities in serverless functions, IAM configurations, and container orchestration. His work secures SaaS platforms and fintech applications in hybrid cloud environments.

Marcin Węgłowski
Mobile Application Pentester

Leads mobile application security testing for Android platforms. Marcin breaks mobile banking apps, healthcare applications, and enterprise mobile solutions. His work has secured applications handling sensitive financial transactions and protected health data for millions of users.

Zbigniew Piotrak
Infrastructure & Active Directory Pentester

Expert in Active Directory security and enterprise network infrastructure. Zbigniew compromises identity management systems, finding privilege escalation paths and access control bypasses in authentication systems protecting major financial institutions and enterprise infrastructure.

Mateusz Wojciechowski
Head of AI

Leads AFINE's AI security research and offensive security methodologies for AI-powered systems. Mateusz specializes in machine learning vulnerabilities, LLM security, and AI application testing. He's developing security frameworks for enterprises deploying AI in production environments handling sensitive data.

Paweł Zdunek
Thick Client Pentester

Focuses on .NET and Java thick client applications. Paweł breaks proprietary enterprise software, financial trading platforms, and business-critical desktop applications. His expertise includes reverse engineering compiled applications and finding logic flaws in systems handling sensitive corporate data.

Piotr Zdunek
Web Application & Active Directory Pentester

Specializes in web application security and Active Directory testing. Piotr breaks modern web applications and enterprise authentication systems, finding vulnerabilities in identity infrastructure and application logic. His work secures financial platforms, healthcare portals, and business-critical applications handling sensitive corporate and customer data.

Marcin Wyczechowski
IoT & Industrial Systems Pentester

Specializes in IoT device security and hardware penetration testing. Marcin tests embedded systems, industrial control equipment, and operational technology. His work secures critical infrastructure, manufacturing systems, and connected devices against both physical and remote exploitation.

Hubert Decyusz
Red Team Operator

Leads external red team operations and phishing campaigns. Hubert conducts full-scope adversary simulations combining technical exploitation with social engineering. He tests organizational security posture beyond technical controls, exposing human and process vulnerabilities in enterprise environments.

Maksymilian Kubiak
Cloud Infrastructure Pentester

Expert in offensive cloud security and infrastructure auditing. Maksymilian breaks AWS, Azure, and GCP environments, finding misconfigurations and architectural vulnerabilities. He conducts penetration testing and comprehensive security reviews of cloud deployments for enterprises migrating critical workloads.

Who tests your systems

At AFINE we assign researchers based on your infrastructure and what you need tested. If you operate banking systems, you work with pentesters who know core banking platforms. If you run healthcare infrastructure, you work with specialists who've tested EHR systems. Whether it's cloud infrastructure, mobile apps, or industrial control systems - we match you with researchers who've broken that technology before.

Our Certifications

Our Values

Quality & Reliability

We deliver security testing at the highest level with 97% client retention. We work around your constraints, but we never compromise on thoroughness or documentation.

Responsibility

Our team has published over 150 CVEs in enterprise software including SAP, Microsoft, CyberArk, and Palo Alto Networks. We help protect enterprises by finding vulnerabilities before attackers exploit them.

Team

Every AFINE researcher is OSCP certified, most holding OSCE, OSWE, OSEP, and CRTO. We invest in continuous training, transparent environment, and a culture built on respect and technical excellence.

Why Organisations Choose AFINE

You get researchers who understand your business context and know what to test. AFINE's penetration testing team manually analyzes your custom applications, proprietary systems, and business logic - finding vulnerabilities that put your operations at risk. Our reports include technical details for security teams, proof-of-concept exploits and fix guidance for developers, and business impact for leadership.

150+

published CVEs

10 years

protecting enterprise clients

Enterprises AFINE Has Compromised

Our team has published 150+ CVEs
in enterprise software

Get your assement today

Call to action background with gradient effect

Why Organizations Trust Us

Svg Vector Icons : http://www.onlinewebfonts.com/icon

AFINE moved from third-choice pentesting supplier to first-choice partner. They keep finding important, and in a few cases even critical issues in places where other pentesters have not found them.

Cedomir Karlicic

Head of Security

,

Isabel Group

Abstract infinity loop symbolizing ongoing security protection

AFINE has been our security testing partner since 2020, consistently delivering exceptional results. Their team identifies advanced vulnerabilities that significantly strengthen our security posture. Reports clearly explain risks with actionable detail for rapid remediation. They consistently meet our aggressive deadlines while maintaining flexibility. Highly recommended as a trusted cybersecurity partner.

Jacek Skorupka

Group Cybersecurity Director

,

Medicover‍

Abstract infinity loop symbolizing ongoing security protection

I am super impressed. This is really thorough. You have uncovered vulnerabilities that our previous pentest failed to detect. Incredible work. Thank you very much!

Kevin Cadman

KingMakers

,

Director of DevOps & Infrastructure

Abstract infinity loop symbolizing ongoing security protection

We've partnered with AFINE for over 5 years, during which they've conducted dozens of security audits for BGK - including penetration tests, security analyses, abuse testing, and source code reviews. Their work consistently meets the highest standards, delivers on time, and provides excellent value. I highly recommend AFINE for their professionalism, flexibility, and collaborative approach.

Krzysztof Murawski

Department of Security

,

Bank Gospodarstwa Krajowego

Abstract infinity loop symbolizing ongoing security protection

The AFINE team performed application analysis and tests of IT environments for us. Provision of services - at the highest level. Information received and knowledge transferred - priceless. I recommend it with a clear conscience, although you have to be prepared for strong impressions.

Marek Krzyżanowski

IT Director

,

Apator Group

Abstract infinity loop symbolizing ongoing security protection

AFINE delivered sharply prioritized, high-impact findings that allowed us to focus our security efforts exactly where they mattered most. There was no wasted time on low-risk noise - only clear, actionable issues with real business relevance. The engagement was efficient, communication was excellent, and the return on investment was immediately evident.

Artur Maliszewski

CIO

,

Tpay

Abstract infinity loop symbolizing ongoing security protection

Find out what people are saying about us

See All Client Stories

Security Assessment Services FAQ

Questions enterprise security teams ask before partnering with AFINE for security assessments.

Is AFINE ISO 27001 certified and what compliance frameworks do you support?

Yes, AFINE is ISO 27001 certified. Beyond certification, we maintain operational security excellence built through 10 years of enterprise work. Our security assessment services support DORA, PCI DSS, SOC 2, ISO 27001, TIBER-EU, NESA, and FCA compliance. We've conducted hundreds of assessments for regulated institutions like PKO BP, ING Bank, and BGK.

What certifications and specialized expertise does AFINE team hold?

Every team member holds minimum OSCP or eWPTX certification. Our researchers average 7-10 years offensive security experience with OSCE, OSWE, OSED, OSEP, CRTO, CSSA, CISSP, CISA, and BSCP certifications. We've published CVEs in SAP, Microsoft, CyberArk, Palo Alto, F5, IBM, and other enterprise software.

What makes AFINE different from other penetration testing vendors?

We've published 150+ CVEs in enterprise software and understand how attackers exploit complex systems beyond automated scanning. Our manual testing finds business logic flaws and attack chains others miss. Isabel Group confirmed we "keep finding critical issues where other pentesters have not found them." Our 10-year exclusive focus on banking, critical infrastructure, and healthcare environments means we understand compliance and production system safety.