SECURIX is a cybersecurity consultancy — advisory first, with audit and offensive testing, compliance across ISO 27001, SOC 2, GDPR, the EU AI Act and DORA, and incident response. We also build the tools we run for our own clients: Nightprill and Scrytide. Everything we report is measured, and we say plainly what we couldn't test.
Consulting work, scoped to your perimeter and your regulator — carried out by the same team that writes the engines behind our products.
Our core work: security strategy, risk and defensive architecture — where to invest, what to fix first, how to build and operate so you stay secure. An ongoing security partnership, not a one-off report.
Security assessments, penetration testing, red-team and social-engineering — scoped and authorised in writing. We prove access where it exists, and stop at the line where a third party would be harmed.
Preparation and evidence for ISO 27001, SOC 2, GDPR, the EU AI Act and DORA. We build the evidence your auditors accept — we don't sell the certificate.
When something is already wrong: containment, evidence, and a written account your team and auditors can rely on — plus ongoing security support between engagements.
We didn't buy our stack; we built it, and we use it in our own engagements every day. Two are in production today, priced in the open on their own sites.
Others monitor your addresses; Nightprill monitors your brand, everywhere it appears — and sorts before it alerts you, so you receive what's real, not thousands of raw signals to triage.
Visit nightprill.com →A scanner that does the analyst's work: it scans behind the login, verifies whether a vulnerability actually applies, names the public exploit, and tells you plainly what it couldn't test. Read-only.
Visit scrytide.com →The rule that governs our products governs our engagements: a test that didn't happen is not a negative result.
Every finding carries its evidence and a way to reproduce it. If we couldn't test something, the report says so — we don't dress a gap as a clean result.
No tool and no team sees everything. We tell you what our scope covered and where its edges are, so you can decide what to do about the rest.
Processing runs in the EU, on named sub-processors, never sent to a consumer AI service — with a GDPR Article 27 representative in the EU.
We go far enough to be sure, and stop before harm. Anything beyond a proof of access happens only under written authorisation, scoped per perimeter.
Your data is processed within the EU or Switzerland, each provider bound by a data-processing agreement and named to you on request. Nothing is sent to a consumer AI service.
For frameworks like ISO 27001, SOC 2, GDPR, the EU AI Act and DORA, we produce the technical evidence and help you prepare — we don't issue the certification. For the GDPR itself, we act as your processor under contract during engagements, and as controller only for our own products, described in our privacy policy.
An engagement, a product trial, or a question about scope — we'll tell you what we can prove, and what we can't, before anything is signed.
hello@securix.hk