About PXL Security
Ten years of proving it.
We started in 2014 with one conviction: a penetration test should prove something — real, demonstrated, fixable risk, not a scan with a logo on it. A decade on, that hasn't changed.
PXL Security was founded in Sofia in 2014, at a time when "penetration testing" too often meant running a scanner and reformatting its output.
We'd seen those reports from the receiving end, and we knew they didn't make anyone safer. So we built the opposite: senior engineers testing by hand, chaining real weaknesses into demonstrated impact, and writing findings an engineer could actually act on. Our first clients stayed because the work held up — and in security, word spreads through the engineers who have to read the report.
Over the years the work followed the threats. Classic web and network testing grew into full red team operations, cloud and mobile assessments, and secure-development review. We started putting our name on the public record, with CVEs disclosed in software used around the world. And because we're builders as much as breakers, we turned what we learn on engagements into our own software.
What hasn't changed is the shape of the company. We're deliberately small and senior. You talk to the people doing the testing, from the first scoping call to the retest. And we still include that retest as standard — because a finding isn't closed until it's proven closed.
The road so far
A decade of offensive security, from a Sofia startup to a team trusted across Europe and beyond.
- 2014
PXL Security is founded
We open in Sofia with a simple pitch: manual-led testing that proves real impact. Our first engagements are web and network assessments for early clients, including a healthcare product team.
- 2015–2019
Building the craft
We grow on reputation, not advertising — known for hands-on testing, clear severity and reports engineers can work from. The practice broadens across web, network and application security.
- 2020–2022
From testing to adversary simulation
Engagements deepen into red teaming, cloud and mobile. We start building internal tooling to make our own work faster and more repeatable.
- 2023
Research goes public
We formalise our vulnerability-research work and publish our first CVE — the start of an ongoing responsible-disclosure track record.
- 2024
A year on the record
Nine CVEs disclosed across widely-used software and plugins, each coordinated with the vendor. Our internal tools mature into products.
- 2025
What we hold to
The principles that have stayed constant since 2014.
Prove it, don't claim it
Every finding comes with reproducible evidence and demonstrated impact. If we can't prove it, we don't report it as a risk.
Senior hands only
The engineer on the kickoff call is the one testing your systems. We don't sell senior and staff juniors.
Honest about the limits
Security testing can't prove the absence of bugs. We're precise about what an engagement does and doesn't tell you.
Closed, not just found
The retest is included. We stay until fixes are verified, and we say so in writing.
Builders, not just breakers
We write code. That's why our tooling fits real workflows and our advice is something engineers can actually ship.
Give back to the field
We disclose responsibly, publish our research, and release tools — because a safer ecosystem is the point.
Certified, and still curious
Our engineers hold the industry's most demanding practical certifications — OSCE³, OSWE, OSEP, CRTO, CREST and more — each earned against live targets, not multiple-choice exams. But the certificate is the floor, not the ceiling: the research and the tools are where the real learning happens.
- Legal name
- PXL Security LTD
- Founded
- 2014, in Sofia
- Headquarters
- 12 Vasil Levski Blvd., 1142 Sofia, Bulgaria
- VAT number
- BG203239331
- Working with
- Clients across the EU and worldwide
Let's talk about your security.
Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.