PXL Security LTD, Sofia, Bulgaria Offensive security since 2014[email protected]

About PXL Security

Ten years of proving it.

We started in 2014 with one conviction: a penetration test should prove something — real, demonstrated, fixable risk, not a scan with a logo on it. A decade on, that hasn't changed.

PXL Security was founded in Sofia in 2014, at a time when "penetration testing" too often meant running a scanner and reformatting its output.

We'd seen those reports from the receiving end, and we knew they didn't make anyone safer. So we built the opposite: senior engineers testing by hand, chaining real weaknesses into demonstrated impact, and writing findings an engineer could actually act on. Our first clients stayed because the work held up — and in security, word spreads through the engineers who have to read the report.

Over the years the work followed the threats. Classic web and network testing grew into full red team operations, cloud and mobile assessments, and secure-development review. We started putting our name on the public record, with CVEs disclosed in software used around the world. And because we're builders as much as breakers, we turned what we learn on engagements into our own software.

What hasn't changed is the shape of the company. We're deliberately small and senior. You talk to the people doing the testing, from the first scoping call to the retest. And we still include that retest as standard — because a finding isn't closed until it's proven closed.

The road so far

A decade of offensive security, from a Sofia startup to a team trusted across Europe and beyond.

  1. 2014

    PXL Security is founded

    We open in Sofia with a simple pitch: manual-led testing that proves real impact. Our first engagements are web and network assessments for early clients, including a healthcare product team.

  2. 2015–2019

    Building the craft

    We grow on reputation, not advertising — known for hands-on testing, clear severity and reports engineers can work from. The practice broadens across web, network and application security.

  3. 2020–2022

    From testing to adversary simulation

    Engagements deepen into red teaming, cloud and mobile. We start building internal tooling to make our own work faster and more repeatable.

  4. 2023

    Research goes public

    We formalise our vulnerability-research work and publish our first CVE — the start of an ongoing responsible-disclosure track record.

  5. 2024

    A year on the record

    Nine CVEs disclosed across widely-used software and plugins, each coordinated with the vendor. Our internal tools mature into products.

  6. 2025

    Tools in the world

    We ship Blackbar and Airward publicly, and keep disclosing — including a privilege-escalation flaw in OpenMediaVault.

What we hold to

The principles that have stayed constant since 2014.

Prove it, don't claim it

Every finding comes with reproducible evidence and demonstrated impact. If we can't prove it, we don't report it as a risk.

Senior hands only

The engineer on the kickoff call is the one testing your systems. We don't sell senior and staff juniors.

Honest about the limits

Security testing can't prove the absence of bugs. We're precise about what an engagement does and doesn't tell you.

Closed, not just found

The retest is included. We stay until fixes are verified, and we say so in writing.

Builders, not just breakers

We write code. That's why our tooling fits real workflows and our advice is something engineers can actually ship.

Give back to the field

We disclose responsibly, publish our research, and release tools — because a safer ecosystem is the point.

Certified, and still curious

Our engineers hold the industry's most demanding practical certifications — OSCE³, OSWE, OSEP, CRTO, CREST and more — each earned against live targets, not multiple-choice exams. But the certificate is the floor, not the ceiling: the research and the tools are where the real learning happens.

See the team's certifications · Read our published CVEs

Legal name
PXL Security LTD
Founded
2014, in Sofia
Headquarters
12 Vasil Levski Blvd., 1142 Sofia, Bulgaria
VAT number
BG203239331
Working with
Clients across the EU and worldwide

Let's talk about your security.

Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.

Prefer email? Write to [email protected]. We reply within one business day.