Skip to content

ABOUT

Lapsor Cybersecurity, offensive security end to end

A specialist company, not a generalist consultancy. The same team agrees the scope, runs the audit and signs the report. It also reports vulnerabilities to international bug bounty and responsible disclosure programmes.

The team's work on those programmes covers corporate applications and networks at international organisations. Every finding was reported through the programme's own channel.

Everything we can show is published; the rest is under a confidentiality agreement

The confidentiality agreement signed before each engagement prevents us from naming clients or showing their logo. The same agreement sets out how evidence is held, how long it is kept and how it is destroyed.

Lapsor provides references on request, as part of a procurement process and with the client's prior approval.

The technical analyses on this site cover real findings, anonymised: none is published before the fix is closed.

How the team works

01

Bug bounty programmes

The team reports on HackerOne, Bugcrowd and YesWeHack. The same team runs your audit, and no part of the work is subcontracted.

02

Tooling kept current

The team works with the most established tooling in the field and keeps it current as attack techniques change. Tooling speeds the review up, it does not replace it: every finding is exploited and validated by hand before it reaches the report.

03

Certifications

OSCP, CRTO and eWPTX, held by the people who run the audit.

COMPANY

Details on record

Registered name
Lapsor Cybersecurity S.L.
Tax ID
B23984115
Registered address
Madrid, Spain
Business activity
CNAE 6220 · Computer consultancy and computer facilities management
Founders
Miguel Ovejero, CEO, and Miguel Arrabal, CTO
Email
contacto@lapsor.com
Phone
+34 658 360 930
LinkedIn
linkedin.com/company/lapsor

Request scope and terms

Tell us which assets you want tested. We reply within 24 hours.

Request an auditCall