Dunicot A cybersecurity consultancy and advisory firm.

Credentials · All independently verifiable

Everything here can be checked.

Certifications listed by issuer. Acknowledgements published by the vendors themselves. Press coverage with original sources. Verify before you buy. That advice applies to every firm you shortlist, including this one.

Certifications

  • Dunicot Private Limited ISO/IEC 27001 certified ISMS badge ISO/IEC 27001 certified ISMS Dunicot Private Limited
  • OffSec Certified Professional (OSCP) badge OffSec Certified Professional (OSCP) OffSec
  • OffSec Web Expert (OSWE) certification badge OffSec Web Expert (OSWE) OffSec
  • CREST certified badge CREST certified CREST
  • EC-Council Licensed Penetration Tester (Master) certification badge Licensed Penetration Tester (Master) EC-Council
  • EC-Council Certified Penetration Testing Professional badge Certified Penetration Testing Professional EC-Council
  • EC-Council Certified Ethical Hacker badge Certified Ethical Hacker EC-Council
  • TCM Security Practical Network Penetration Tester certification badge Practical Network Penetration Tester TCM Security
  • ISACA Certified Information Systems Auditor badge Certified Information Systems Auditor ISACA
  • ISACA Certified Information Security Manager badge Certified Information Security Manager ISACA
  • CompTIA Advanced Security Practitioner certification badge CompTIA Advanced Security Practitioner CompTIA
  • Amazon Web Services AWS Certified Security Specialty badge AWS Certified Security Specialty Amazon Web Services
  • Microsoft Azure Security Engineer Associate certification badge Azure Security Engineer Associate Microsoft
  • Fortinet Certified in Cybersecurity badge Fortinet Certified in Cybersecurity Fortinet
  • Fortinet Certified in Network Security badge Fortinet Certified in Network Security Fortinet
  • Cisco Certified Network Associate badge Cisco Certified Network Associate Cisco

16 active certifications: the firm’s own ISO/IEC 27001 ISMS, and fifteen held by individuals across offensive security, cloud, audit and governance. Each of the individual certifications is verifiable on the issuing authority’s own portal, and the ISO certificate and scope statement are provided on request under NDA.

Practice certification

Organisation
Dunicot Private Limited
Standard
ISO/IEC 27001
Evidence
Certificate and scope statement provided on request under NDA

Research record

Top 100
HackerOne all-time rank reached by our co-founder
$2M+
Earned by our team across global bug bounty programs
HackerOne and other platform profiles
100+
Vendor Hall of Fame acknowledgements earned by our team
Vendor security acknowledgement pages
15
Active security certifications held across the team
Issuer verification portals
200+
Successful projects delivered
Internal engagement log
25+
Certified security experts on the team
Company records

Hall of Fame acknowledgements

Organisations that have publicly credited our team for responsible disclosure. These are acknowledgements of security research, not client engagements and not partnerships. The distinction matters and is stated here deliberately.

  • Microsoft
  • Google
  • GitHub
  • Apple
  • Sony
  • Salesforce
  • BuzzFeed
  • Intel
  • SAP
  • Booking.com
  • Starbucks
  • Docker Hub
  • U.S. Dept. of Defense
  • DoorDash
  • Zomato
  • Malwarebytes
  • AVG
  • Grab
  • ESET
  • New Relic
  • Recorded Future
  • HackerRank
  • Sky TV
  • Blockchain.org
  • Caviar
  • ShowMax
  • Quantopian
  • Freelancer
  • MediaFire
  • Bitcasa
  • Schuberg Philis
  • Issuu
  • Constant Contact
  • Resin.io
  • Balsamiq
  • ABN AMRO Bank
  • Inkmonk
  • Inflectra
  • OpenDrive
  • Panorama9
  • FunCaptcha
  • Transloadit
  • Microsoft
  • Google
  • U.S. Department of Defense
  • GitHub
  • Intel
  • Apple
  • Sony
  • Salesforce
  • SAP
  • Booking.com
  • Starbucks
  • BuzzFeed
  • Docker Hub
  • DoorDash
  • Zomato
  • ESET
  • Malwarebytes
  • AVG
  • ABN AMRO Bank
  • Grab
  • New Relic
  • Recorded Future
  • HackerRank
  • Sky TV
  • Blockchain.org
  • ShowMax
  • Caviar
  • Quantopian
  • Freelancer
  • MediaFire
  • Bitcasa
  • Schuberg Philis
  • Issuu
  • Inflectra
  • Constant Contact
  • Transloadit
  • FunCaptcha
  • OpenDrive
  • Inkmonk
  • Panorama9
  • Resin.io
  • Balsamiq

Press coverage

Questions

Who will perform our penetration test?

Named, certified testers from our team, agreed with you during scoping and held to contractually. Not an anonymous pool, and not juniors working under a senior's byline. You can ask for the CVs and certifications of everyone assigned before you sign, and delivery is reviewed by our Principal Consultant. The certifications held across the team are listed on the credentials page.

What is a HackerOne Top 100 ranking?

HackerOne’s all-time leaderboard ranks researchers by reputation accumulated from valid, triaged vulnerability reports across public bug bounty programs. It is earned from findings that companies validated and paid for, which makes it one of the few security credentials that reflects demonstrated results rather than an examination.

Which companies have publicly acknowledged your vulnerability disclosures?

Public Hall of Fame acknowledgements include Microsoft, the U.S. Department of Defense, GitHub, Intel, SAP, Booking.com, Starbucks, Docker Hub, DoorDash, Grab, ABN AMRO Bank, New Relic, ESET, Malwarebytes and more than eighty others, 100+ documented in total. These are public acknowledgements of responsible disclosure, not client engagements.

Has Dunicot’s security research been covered in the media?

Yes. The best known is the 2018 disclosure that data belonging to 1.4 million Careem drivers was exposed, covered by Khaleej Times, Gulf News, Databreaches.net, MenaBytes and Zawya.

Credentials checked. What next?

Describe the system, the roles and the deadline. Scoping is free and takes about twenty minutes.