Built to the standard the region deserves.
Katiti Security is an offensive-security practice based in Victoria, Mahé. We test the systems that banks, fintechs, government bodies, and offshore-services firms across the Indian Ocean depend on, and we test them to the same standard a firm in London or Singapore would expect.
01Who we are
Katiti Security is a specialist offensive-security firm. Our work is simple to describe and hard to do well. We attack the systems our clients rely on, with their permission, the way a real adversary would, and then we hand back a report that closes the gaps we found. Nothing theoretical, nothing padded, and nothing left half-open.
The firm exists because the Indian Ocean deserves better than an afterthought. The region runs on offshore finance, digital banking, tourism, and public infrastructure, and those platforms hold the same sensitive data and face the same adversaries as their counterparts anywhere else. Too often they are tested to a lighter standard, or not at all, simply because of where they sit on the map. We built Katiti to close that gap.
02The name
Katiti is the Creole name for the Seychelles kestrel, an endemic falcon and the only bird of prey native to these islands. It hunts from a still, watchful perch, reads the ground below in complete detail, and strikes with precision only when the moment is right. That is the posture we hold ourselves to. Patience, total situational awareness, and a precise, deliberate strike rather than noise for its own sake.
It is also a deliberate statement of origin. We are of these islands, not visiting them, and the standard we bring is meant to raise the bar for the whole region rather than extract from it.
03How we work
Four principles shape every engagement, and none of them is negotiable.
Authorization first, always
We test only what we are contracted and permitted to test, inside a scope agreed in writing before any packet is sent. Authorization is not a formality to us. It is the line that separates a security firm from the threat it defends against, and it is the foundation of everything we sell.
Evidence over noise
Every finding we report is real, reproduced, and proven. We do not hand a client a wall of raw scanner output and call it a test. A scanner is one instrument among many, and on its own it produces as many false alarms as real issues. Our reports contain findings a human confirmed and could demonstrate on demand.
Non-destructive by default
Our default mode of testing does not damage data or disrupt a live service. Where a specific test carries any risk to a production system, we flag it, schedule it, and get explicit sign-off before we proceed. A test that takes your business offline has failed at its job, whatever it found.
Two audiences, one document
A finding nobody acts on is a wasted finding. Our reports carry deep technical detail for the engineers who will fix the issue and a clear, plain-language summary for the board that has to fund the work. One document does both jobs, so the fix actually gets made.
04The standards we hold
We do not invent our own yardstick. Your assessment is measured against the frameworks your auditors, your regulator, and your peers already recognise.
- OWASP testing guidance for web applications and APIs, the most widely used body of practice for application security.
- PTES, the Penetration Testing Execution Standard, for the shape and rigour of the engagement itself.
- NIST SP 800-115, the United States technical guide to information-security testing, for assessment method and documentation.
- CVSS v4.0, the Common Vulnerability Scoring System, so every finding carries a severity a third party can verify rather than a label we made up.
- MITRE ATT&CK to describe adversary behaviour in a shared language your defenders already use.
05Why a local firm matters
Distance is not free. A security partner in your own time zone answers when an incident cannot wait. A partner who understands the region reads your threat landscape correctly, from the offshore-finance sector that makes local firms a high-value target to the handful of undersea cables the whole economy depends on. And a partner you can meet is a partner who builds real context over time rather than starting cold on every engagement.
There is a data question too. Sensitive findings about a bank or a government system should be handled by people who understand the local regulatory and confidentiality expectations, not routed through a call queue in another hemisphere. We keep that relationship close on purpose.
06What we will not do
The constraint is the product. We will not test a system without written authorization from someone empowered to give it. We will not strip our own safety rails to manufacture a more dramatic result. We will not pad a report to justify a fee. And we will not share what we learn about your systems with anyone outside the engagement. Discretion is written into every contract, during the work and long after it ends.
If that sounds like a high bar, it is meant to. It is the same bar we would want held to the systems that hold our own money and our own data.
The short version.
Based in Seychelles
Victoria, Mahé. In the region, in your time zone, reachable directly.
Offensive security only
Testing, vulnerability assessment, hardening, and advisory. A focused practice, not a reseller.
Standards-aligned
OWASP, PTES, NIST SP 800-115, and CVSS v4.0 on every engagement.
Confidential by contract
An NDA before any technical detail, and strict discretion after.