About Packet33

Security made simple for SaaS and Healthcare.

We are a boutique collective of senior security practitioners helping startups from pre-seed through Series A build secure, compliant, and audit-ready products.
100% senior-led testing, never handed off to junior staff
Book a free consultation

Expertise and certifications

Senior practitioners, respected credentials.

Our senior practitioners each bring over a decade of hands-on offensive security experience across Fortune 100 companies, government environments, and enterprise SaaS platforms. Every practitioner holds industry certifications including OSCP, CRTP, and CARTP. Their backgrounds span large-scale infrastructure security, Active Directory attack paths, cloud security architecture, and web application penetration testing. Every engagement is scoped by our team, tested and documented by these senior practitioners directly, and quality-reviewed before it reaches you.
Never handed off. It is common in this industry for a firm to quote senior rates but staff the actual testing with junior analysts. Every Packet33 engagement is tested by the senior practitioner assigned to it, from start to finish.
OSCP certification
OSCP
CRTP certification
CRTP
CARTP certification
CARTP

Our team
The people behind every engagement.

Senior Pentester

OSCP, CRTP, CARTP10+ years of experience
Focused on cloud environments, web applications, and APIs, with recent work assessing LLM-integrated features as AI capabilities become standard in SaaS products. Testing experience also extends to network infrastructure.

Senior Pentester

OSCP, INE Mobile Application Security10+ years of experience
Experience spanning web, API, mobile, desktop, network, and cloud environments. Mobile and desktop application testing is a particular area of depth, alongside standard web and API work, with recent experience assessing LLM-integrated features as AI adoption grows across SaaS platforms.

Founder

Compliance & Cloud Security Focus
Brings hands-on experience across compliance program development, cloud security, and security operations. Leads Packet33 end to end, working directly with clients on engagement scoping and project management, translating audit and procurement requirements into testing engagements that actually move deals forward.

How we test
A methodology built for real attack paths.
๐Ÿงช

Manual first

Automated scanners find what is already known. Our engagements are built around manual testing performed by senior practitioners, with automation used to support coverage, not replace judgment.

๐Ÿ“

Standards based

Testing is structured against recognized frameworks, including the OWASP Top 10, OWASP API Security Top 10, the OWASP Web Security Testing Guide (OWSTG), and PTES, depending on engagement type and scope.

๐Ÿ”

Authorization and access control

We specifically test for broken object level authorization (BOLA), insecure direct object references (IDOR), and tenant isolation failures, the class of vulnerability that matters most for multi-tenant SaaS platforms.

๐Ÿง 

Business logic testing

Beyond technical vulnerabilities, we test for workflow abuse, meaning ways your application’s intended functionality can be manipulated to produce unintended outcomes that a scanner cannot detect.

โ˜

Cloud and IAM review

For engagements that include cloud infrastructure, we review configurations and identity and access management policies against security best practices to identify misconfigurations and excessive permissions.

โœ…

Compliance mapped reporting

Where relevant to an engagement, findings can be mapped to SOC 2, HIPAA, or ISO 27001 controls, giving your team and your auditor a direct line from finding to framework.


Transparency first

See the quality of our work before you commit.

Before you book a call, see the quality of our work for yourself. Download a sample Packet33 pentest report to see how we document findings and provide clear remediation paths for your team.

This report has been sanitized for public release. A real report includes full technical evidence including PoC captures and logs, and optional compliance mapping for SOC 2, NIST, ISO, and other frameworks.


Our partners
Working with the platforms your compliance team trusts.

Packet33 works with leading compliance and security platforms to help our clients build a complete security program, from penetration testing and audit readiness through certification and ongoing compliance management.

Thoropass

Thoropass is a compliance automation platform helping companies achieve and maintain SOC 2, HIPAA, ISO 27001, and other certifications. We partner with Thoropass to help clients who need audit readiness services before engaging their audit team, and to refer clients who need a trusted compliance platform to manage their ongoing program.

Who we serve
Built for the teams that move fast and need trust.
๐Ÿ’ป

SaaS founders and engineering teams

You are moving fast and need to unblock sales deals. We provide the penetration testing reports required by enterprise procurement teams and the technical evidence needed for SOC 2 and ISO 27001 certifications.

๐Ÿฅ

HealthTech and MedTech platforms

You build software that touches ePHI or clinical workflows. We help you validate your technical safeguards to ensure HIPAA compliance and build trust with the hospitals, payers, and clinical partners you sell into.

Does Packet33 only work with pre-seed through Series A companies?

Pre-seed through Series A is our primary focus and where most of our clients are, but we also work with more established startups who want the same senior-led, fixed-scope approach.

Do you only work with SaaS and HealthTech companies?

SaaS and HealthTech are where we specialize, and it shows in how we test and report. We’re open to conversations with other tech companies too, but our depth is strongest for teams in those two spaces.


Our approach

Built for the modern security landscape.

We operate as a boutique collective of senior practitioners. By combining specialized automation with manual testing, we help teams identify vulnerabilities and validate their cloud security posture. Every engagement is finalized with a focus on technical integrity and actionable reporting.

Let’s talk

Ready to strengthen your security program?

We will meet you where you are and help you build lasting trust with customers, patients, partners, and auditors.