Synthetic adversaries. Real findings.
Syntetisk Tech Limited is a Hong Kong security-research outfit. We build AI agents that act like attackers — autonomous recon, multi-round exploit attempts, operator-validated PoCs — and run them continuously against your surface. We sit on the defender's side of the table: operators, not vendors.
How the loop runs. End to end.
FLOW // PIPELINETwo ways we work.
One adversary loop, pointed two ways: continuous penetration testing across your live surfaces, and bespoke private research when you need depth.
Continuous emulation across your surfaces.
Scoped engagements that run on your cadence — weekly, monthly, per-deploy. Agents enumerate, map, and chain exploit attempts the way an attacker would; findings land in your issue tracker with reproduction steps and a working PoC, not a 60-page annual report.
Depth a scan can't reach.
When the threat is bespoke, so is the work. Multi-week engagements that go after the hard problems in your stack — a novel vulnerability class, the internals of a critical dependency, the primitives a real attacker would build. Red-team creativity with academic rigor.
You get threat models, novel disclosures, working proof-of-concept exploits, and any custom tooling we build along the way — delivered as code, yours to keep.
Contact us.
Tell us what you're protecting and what's worrying you — surface, scope, timeline, or just a question. It routes straight to the operators, and we reply within one business day.
Frequently asked.
Scope, data, deliverables — the things you'd ask in a discovery call, answered up front.
Q_01 How do you scope a private research engagement?
We start with a scoping call to agree on targets, threat model, timeline, and deliverables. Private research engagements are multi-week, operator-led, and produce custom tooling delivered as code — yours to keep.
Q_02 What does a private research engagement deliver?
Threat models, novel vulnerability disclosures, and working proof-of-concept exploits — plus any custom tooling we build along the way (recon probes, harnesses, analysis scripts), delivered as code and yours to keep.
Q_03 What kinds of research do you take on?
Zero-day discovery, reverse engineering, protocol and primitive research, and threat intelligence tailored to your stack and adversary profile. We live at the intersection of red-team creativity and academic rigor — the hard problems a scan never reaches.
Q_04 Do you exploit vulnerabilities you find?
We do our best to exploit findings to prove impact — that's how a PoC report differs from a vulnerability scan.
We also respect customer scoping: if you'd rather we surface recommendations and possible misconfigurations without active exploitation, we lock that in during the scoping call. We never act outside the agreed scope, and we never perform destructive or denial-of-service actions.
Q_05 How do you handle the data you collect?
Per-engagement encrypted storage. Tokens, sessions, and any sensitive captured data are deleted after the contractual retention period unless you ask us to retain them for follow-up runs. We never sell, share, or aggregate customer data.
Q_06 Who owns the findings and the tooling?
Findings and reports are yours — to keep, share internally, and act on however you need.
Tooling we build to deliver the engagement (recon pipelines, custom probes, harness integrations, the knowledge base) stays with us. That's our IP, and how we get sharper for every customer over time. We never share your data or your findings across customers.
Q_07 Can you redact a report for third parties?
What we deliver is final — we don't modify reports after delivery.
If you need a redacted version for auditors, partners, or customers, you're free to edit your copy. Just note that once it's been changed it's no longer the report we delivered, and we can't stand behind those edits.
Q_08 What is adversary emulation?
Adversary emulation is a security assessment that reproduces the tactics, techniques, and procedures of a real attacker against your systems. Rather than checking a control list, an operator — or an autonomous agent acting like one — performs reconnaissance, attempts exploitation, and chains steps the way an attacker would.
The deliverable is proof of impact: a working proof of concept, not a theoretical risk rating.
Q_09 What is continuous pentesting?
Continuous pentesting is penetration testing that runs on a recurring cadence — weekly, monthly, or on every release — instead of as a single annual engagement. Each cycle re-tests your live attack surface so new vulnerabilities are caught shortly after they ship.
Findings land in your issue tracker with reproduction steps, not in a once-a-year PDF.