Swiss security research lab

What attackers already see about your business.

Every organisation leaks more to the public internet than it realises: forgotten hosts, expired certificates, credentials in old breach dumps, a staging environment nobody switched off. Boty finds that exposure the way an adversary would, tests whether it can actually be used, and keeps watching after the report is delivered.

  • Public sources first. Discovery never touches your systems.
  • Written authorisation. Nothing is probed that you have not scoped.
  • Evidence per finding. No severity without a reproduction path.
domains & subdomainscertificate transparencyexposed servicesTLS postureSPF · DKIM · DMARCbreach corporapublic code & secretscloud storageDNS hygienevendor advisoriesCVE trackingdangling recordsdomains & subdomainscertificate transparencyexposed servicesTLS postureSPF · DKIM · DMARCbreach corporapublic code & secretscloud storageDNS hygienevendor advisoriesCVE trackingdangling records
The problem

Nobody has a complete list of what their company exposes.

Infrastructure accumulates. A marketing site goes up for a campaign and stays up. A developer registers a subdomain for a test and moves on. A supplier gets access to a system and keeps it after the contract ends. An employee reuses a work address on a service that is later breached.

None of this is negligence — it is what happens to any organisation that operates for a few years. The problem is asymmetry: an attacker only has to enumerate your public footprint once, and the tooling to do that is cheap, fast and widely available. Most organisations have never done the same exercise against themselves.

How it works

Reconnaissance, verification, and then the part that matters.

The same sequence an adversary follows, run against you deliberately, with a report at the end instead of an incident.

  1. 1

    Scope

    You tell us which domains, brands and ranges belong to you. It goes in writing, including what is explicitly off limits.

  2. 2

    Discover

    We rebuild your public footprint from open sources — DNS, certificate transparency, registries, breach data, public code. Nothing touches your infrastructure.

  3. 3

    Verify

    Authorised, rate-limited checks establish which assets are live, what they run, and which findings are real rather than artefacts of the data.

  4. 4

    Rank

    Each finding gets a severity, a realistic attack path and evidence — so the list can be worked top to bottom instead of argued about.

  5. 5

    Watch

    Optional: the same discovery runs on a schedule, so you hear about a new exposure when it appears rather than at the next assessment.

What we do

Four things, done properly.

Security work and engineering work, from the same base: extracting reliable signal out of large volumes of messy real-world data.

External attack surface analysis

Everything about your organisation that is reachable from the public internet, enumerated and ranked.

  • Asset inventory: domains, subdomains, hosts, services and owners
  • Findings ranked by exploitability and business impact, each with evidence
  • TLS, DNS and SPF/DKIM/DMARC posture review
How this works

Penetration testing

Adversary simulation against web applications, APIs, infrastructure and cloud — with proof rather than guesswork.

  • Severity-rated findings with reproduction steps and evidence
  • Attack chains, not just isolated issues
  • Remediation guidance written for the engineers who will apply it
How this works

Threat intelligence briefings

A weekly written brief on the advisories, campaigns and regulatory changes that touch your stack and your sector.

  • Weekly written briefing, filtered to your technology stack and sector
  • Every item states what changed, who is affected, and whether action is required
  • CVE, vendor advisory and primary-source references throughout
How this works

Applied Artificial Intelligence

Text, Image and video processing systems assessed or integrated to run in production, not to demo well.

  • Feasibility assessment against your actual data or environment before commitment
  • Text or image-processing pipelines: Chatbots, object/face detection, 3D reconstruction, data-privacy filters
  • Model integration into existing systems and workflows
How this works
Your exposure

The categories that turn up again and again.

These are the finding types that recur across almost every external assessment. Each one is discoverable from outside your network, usually without touching a single one of your systems.

Read how the analysis is scoped
Leaked credentialsEmployee logins sitting in breach corpora
Open servicesRemote access nobody meant to publish
Weak or expired TLSLegacy ciphers, missing HSTS, stale certificates
Secrets in public codeAPI keys and tokens in repositories
Forgotten subdomainsShadow assets and dangling DNS records
Mail spoofing gapsMissing or permissive SPF, DKIM, DMARC
Open cloud storageMisconfigured buckets and shares
Information leakageVersions, banners, metadata, verbose errors
Evidence, not adjectives

What we will not do.

A security vendor that will not say what it does not do is asking you to take quite a lot on faith. So, explicitly:

  • We do not publish client findings, client names or client data. Research on this site is about publicly observable infrastructure in aggregate, or about our own systems.
  • We do not display live counters or fabricated activity feeds. If a number appears on this site, it has a source and a date next to it.
  • We do not touch anything outside written scope, and testing stops when you say stop.
  • We do not report severity without a reproduction path. A finding you cannot verify is a finding you cannot prioritise.
Questions

The things people ask first.

What exactly is Boty?

Boty is a Swiss security research lab. The work splits into three parts: mapping what your organisation exposes to the public internet, simulating how an adversary would attack it, and tracking security advisories continuously so you find out about relevant exposure early. A fourth strand, applied computer vision, comes from the same engineering base.

Who is Boty for?

Small and mid-sized organisations that depend on internet-facing systems but do not have a dedicated security team. If nobody in your company can produce a complete list of your public-facing assets from memory, that is the gap we close.

Do you attack systems without permission?

No. Discovery uses public sources only and never touches your infrastructure. Anything that does touch your systems is authorised in writing beforehand, scoped to named assets, and stops when you say stop.

How is an attack surface analysis different from a vulnerability scan?

A vulnerability scan checks hosts you already know about. An attack surface analysis starts from the outside with no inventory and reconstructs one — which is why it usually finds assets your own documentation does not list.

All questions

Find out what you are exposing.

Send a short description of your environment. You get back a scoped proposal — what would be examined, how long it takes, and what it costs. No obligation and no sales sequence.