Skip to content
Offensive security · Monterrey, MX

We break your applications and AI before attackers do.

Shura Labs is a specialist offensive-security consultancy focused on application and AI/LLM security testing — senior specialists, deep manual work, findings you can actually act on.

Freeor run our automated API security diagnostic in ~2 minutes — no strings.

report.pdf · Shura LabsConfidential
  • CriticalIndirect prompt injection → cross-tenant data exfiltration
  • HighBroken object-level authorization (IDOR)
  • MediumWeak session handling on the SSO callback
1 critical · 2 high · verified by hand

Focused disciplines

WebAI · LLMMobileAPICloud App LayerPTaaSDevSecOps

// Services

Assessments across the full application & AI attack surface

Every engagement is senior-led and manual-first. Select a discipline to see what it covers — or ask the assistant in the corner which one fits what you're building.

Focused on the application, AI & identity layer — the software and models you build and ship.

Hands-on, authenticated testing of modern web applications — SPAs, dashboards, portals, and SaaS platforms. We go far past automated scanners: chaining weaknesses, abusing business logic, and thinking through the workflows the way a motivated attacker would. Every finding is manually verified and reproduced.

What we test

  • Broken access control, IDOR & privilege escalation
  • Authentication, SSO/OAuth & session management
  • Injection: SQLi, XSS, SSTI, command injection
  • SSRF and server-side request forgery chains
  • Business-logic & multi-step workflow abuse
  • File upload, deserialization & template handling
  • Multi-tenant isolation & data segregation
  • Sensitive data exposure & secret leakage

Example finding

A "read-only" analyst role that, by tampering with a hidden object ID, could edit and export another tenant's records.

Think this is the right fit?

Request this assessment
Our specialty

Adversarial testing of LLM-powered products and agents. We treat the model, its system prompts, its retrieval layer, and every tool it can call as one connected attack surface — because that is exactly how it gets exploited. This is our core specialty and the discipline most pentest firms still cannot deliver.

What we test

  • Direct & indirect prompt injection
  • Jailbreaks & safety-guardrail bypass
  • System-prompt & training-data extraction
  • RAG / retrieval poisoning & context manipulation
  • Tool / function-call abuse & privilege escalation
  • Agent workflow & multi-step / autonomy abuse
  • Excessive agency & unsafe tool permissions
  • Insecure handling of model output (e.g. XSS via responses)
  • Cross-tenant & sensitive-data leakage

Example finding

A support agent that ingests a customer-uploaded document containing hidden instructions, then uses its internal tools to exfiltrate another customer's data.

Think this is the right fit?

Request this assessment

Static and dynamic analysis of iOS and Android apps — plus the APIs behind them, where the real damage usually happens. We reverse-engineer the client, defeat runtime protections, and test the full path from the device to your backend.

What we test

  • Insecure local storage & Keychain/Keystore misuse
  • Certificate pinning & TLS interception bypass
  • Reverse engineering & anti-tampering resilience
  • IPC, deep links & intent/URL-scheme abuse
  • Hardcoded secrets, keys & endpoints
  • Runtime manipulation (Frida / objection)
  • Backend & mobile-API authorization

Example finding

An app that pins TLS but still stores a long-lived session token in plaintext, recoverable from a backup.

Think this is the right fit?

Request this assessment

Focused testing of the REST, GraphQL, and SOAP APIs that power your apps and integrations. APIs fail differently from UIs — the vulnerabilities live in authorization and data exposure, so that is where we concentrate, mapped to the OWASP API Security Top 10.

What we test

  • Broken object-level authorization (BOLA / IDOR)
  • Broken function-level authorization (BFLA)
  • Mass assignment & excessive data exposure
  • Rate-limit, quota & resource-consumption abuse
  • Injection across parameters, headers & bodies
  • GraphQL introspection, batching & depth abuse
  • Token handling: JWT, OAuth scopes & key rotation

Example finding

A GraphQL endpoint whose nested queries let a low-privileged user enumerate every organization in the database.

Think this is the right fit?

Request this assessment

An application- and identity-layer review of how your product uses AWS, Azure, or GCP. We look at the cloud through the lens of your application — how identity, permissions, storage, and serverless components could be abused to reach your data — rather than doing network or infrastructure penetration testing.

What we review

  • IAM roles, policies & privilege escalation paths
  • Identity, federation & SSO misconfiguration
  • Storage exposure (S3 / Blob / GCS)
  • Secrets management & key handling
  • Serverless attack surface (Lambda / Functions)
  • Application data flows & trust boundaries
  • Over-permissioned service accounts & tokens

Example finding

A build role with a wildcard policy that, if a CI token leaked, would hand an attacker the entire production account.

Think this is the right fit?

Request this assessment

Pentest-as-a-Service for teams that ship continuously. Instead of a single annual snapshot that is stale the day after it lands, you get ongoing coverage that keeps pace with your releases, fast retests of fixes, and a live view of your security posture.

What's included

  • Continuous coverage across your release cycle
  • Change-triggered testing on major releases
  • Rapid retesting & verification of fixes
  • A live findings feed with severity & status
  • Periodic senior-led deep-dive assessments
  • Direct line to the testers, not a ticket queue

Example finding

A feature ships on Tuesday, introduces an access-control gap, and is flagged and retested before it reaches most of your users.

Think this is the right fit?

Request this assessment

Security built into the way your team already ships. We harden your pipelines, add the right automated gates, and design guardrails developers will actually keep — so security scales with engineering instead of blocking it.

What we integrate

  • Pipeline & build-runner hardening
  • Secrets scanning & secure secret management
  • SAST / DAST / SCA gating tuned to cut noise
  • IaC review (Terraform / CloudFormation / Bicep)
  • Dependency & software-supply-chain risk
  • Branch protection & least-privilege CI identities
  • Developer-friendly guardrails & paved paths

Example finding

Replacing a noisy scanner that everyone ignored with a tuned gate that blocks only exploitable, reachable issues.

Think this is the right fit?

Request this assessment

// Methodology

Rigorous where it counts, creative where it matters

We pair recognized testing standards with real attacker creativity — structured enough to be thorough, adversarial enough to find what checklists miss.

Manual-first, automation-assisted

Scanners give us breadth; senior humans give us the findings that matter. The vulnerabilities that actually get you breached — broken authorization, business-logic abuse, chained exploits, prompt injection — are found by hand.

Threat-led, not checklist-led

We model your specific attack surface and abuse cases first, then test against them. A checklist tells you what everyone checks; a threat model tells you how you actually get attacked.

Evidence-based & reproducible

Every finding is manually verified, reproduced, and documented with steps and evidence — scored by CVSS and, more importantly, real business impact in your context. No unverified scanner noise.

Safe by default

Testing is non-destructive and authorized, run in coordinated windows with clear rules of engagement. Critical issues are escalated the moment we confirm them — never held back for the report.

Aligned with

OWASP WSTGOWASP ASVSOWASP API Top 10OWASP LLM Top 10OWASP MASTGMITRE ATT&CKMITRE ATLASPTESNIST SP 800-115

// How we work

A clear engagement, from first call to validated fixes

No black boxes. You know what's happening at every stage — and critical issues reach you in real time, not buried in a report weeks later.

  1. 01

    Scope & kickoff

    We align on targets, access, rules of engagement, and timeline — and agree on what "done" looks like before any testing starts.

  2. 02

    Threat model & recon

    We map your attack surface and the abuse cases that actually matter for your app, data, and users — so effort goes where the real risk is.

  3. 03

    Manual assessment

    Senior specialists test and exploit by hand, chaining weaknesses the way an attacker would. Critical findings are reported the moment we confirm them — you never wait for the final document.

  4. 04

    Prioritized reporting

    Every finding comes with a severity rating, real business impact, clear reproduction steps, and concrete remediation guidance — ordered so you know what to fix first.

  5. 05

    Debrief & remediation support

    We walk your engineers through the findings, answer questions, and help shape the fixes — a working session, not a document hand-off.

  6. 06

    Retest & validation

    Once you’ve remediated, we re-test each issue and confirm it’s truly closed — then issue a validation you can share with customers and auditors.

Continuous engagements loop steps 2–6 on every release — same process, always on.

Discuss scope →

// Engagement models

Work with us the way that fits your team

Every model is senior-led and fixed-fee — scoped to your target, with no surprise hourly billing. Not sure which fits? We'll help you decide.

Fixed-scope assessment

A defined, point-in-time pentest of a specific target.

Best for

Compliance, product launches, one-off validation

  • Scoping call + rules of engagement
  • Senior-led manual assessment
  • Prioritized report with remediation
  • One retest of remediated findings
  • Letter of attestation on request
Request an assessment
Most popular

Continuous / PTaaS

Always-on testing that keeps pace with your releases.

Best for

Teams shipping frequently

  • Ongoing coverage across your release cycle
  • Live findings feed with severity & status
  • Rapid retests as you ship fixes
  • Change-triggered testing on major releases
  • Direct line to the testers
Start continuous testing

Security partner / retainer

A standing AppSec & AI-security team you draw on.

Best for

Teams wanting ongoing expertise on tap

  • A block of testing days you allocate as needed
  • Architecture & design reviews
  • DevSecOps & CI/CD guidance
  • On-call support for launches
  • Quarterly posture reviews
Talk about a retainer

Pricing is scoped to your target and shared up front as a fixed fee — request a quote.

// Deliverables

Reports written to be fixed, not filed

You get a report your engineers will actually use and your leadership can actually read. Here's what's in every one — and a sample of the depth you can expect.

  1. 1

    Executive summary

    A plain-language overview for leadership: overall risk posture, key themes, and what to prioritize — no jargon required.

  2. 2

    Risk ratings

    Every finding scored with CVSS and, more importantly, real business impact in your context — not just a scanner severity.

  3. 3

    Detailed findings

    Reproduction steps, evidence, and affected components for each issue, so your engineers can confirm and fix without guesswork.

  4. 4

    Prioritized remediation

    Concrete, actionable guidance ordered by what to fix first — tailored to your stack, not copy-pasted boilerplate.

  5. 5

    Retest attestation

    After you remediate, a validation of what’s closed — a document you can share with customers and auditors.

Sample finding · draft
CriticalCVSS 9.1·SL-2025-014

Indirect prompt injection → cross-tenant data exfiltration

Summary
The support assistant ingests customer-uploaded documents into its RAG context without isolating them from instructions. A crafted document causes the agent to invoke its lookup_account tool against an arbitrary tenant and return the result.
Business impact
Any customer can read another customer's account data by uploading a single file — a direct multi-tenant confidentiality breach with clear regulatory exposure.
Reproduction
  1. Sign in as a standard tenant user.
  2. Upload invoice.pdf containing the embedded instruction shown in Appendix B.
  3. Ask the assistant to "summarize my invoice."
  4. Observe the response includes account data for tenant_id=1002.
Remediation
Treat retrieved content as untrusted data, never instructions. Enforce tenant scoping in the tool layer (server-side), not via the prompt. Add allow-listed tool arguments and log/deny cross-tenant lookups.

Want to see a full sample report?

We'll share a complete, sanitized example so you know exactly what to expect. (Sample content shown is a draft for illustration.)

Request the full sample report

// Why Shura Labs

Small by choice. Specialist by design.

Big firms sell breadth and headcount. We sell depth and the specific expertise that modern application and AI systems actually need.

Request an assessment
  • 01

    Senior specialists only

    No junior hand-offs, no report-generator scans. Every assessment is run by experienced offensive-security engineers who test by hand and think like an attacker.

  • 02

    AI-security depth most firms lack

    Prompt injection, jailbreaks, RAG manipulation, tool and agent-workflow abuse — offensive AI/LLM testing is a first-class discipline here, not a checkbox bolted onto a web pentest.

  • 03

    Direct, hands-on attention

    You get direct access to the people doing the work, engagements scoped to your actual risk, and findings written to be fixed — not padded to fill a page count.

// FAQ

Questions, answered

Don't see yours? Email hello@shuralabs.io or ask the assistant.

How is Shura Labs different from a big pentest firm?

You work directly with senior specialists who test by hand — not a junior running a scanner against a template. We go deep on a focused set of disciplines (application, AI/LLM, mobile, API, cloud app layer) instead of selling breadth and headcount.

Can you test our LLM / AI features specifically?

Yes — it’s our core specialty. We test prompt injection (direct and indirect), jailbreaks, RAG and retrieval manipulation, tool and function-call abuse, and agent-workflow security. Most pentest firms still can’t cover this; we treat the model, its prompts, its retrieval layer, and its tools as one attack surface.

Do you test production or staging?

Either — we agree on it during scoping. Testing is non-destructive and run in coordinated windows. Many clients prefer a production-like staging environment with representative data; where production testing is needed, we scope it carefully with clear rules of engagement.

How do you handle our data and credentials?

We work under a mutual NDA, collect the minimum access required, store credentials in a secrets manager, and use least-privilege test accounts that are revoked when the engagement ends. Client data is deleted after a short retention window. See our Trust & Security page for the full detail.

Is a retest included?

Yes. Fixed-scope assessments include one retest of remediated findings so you can confirm issues are truly closed. Continuous and retainer engagements include ongoing retesting as you ship fixes.

Do you provide a letter of attestation for compliance?

Yes. We provide a letter of attestation suitable for SOC 2, ISO 27001, PCI DSS, and customer security reviews, plus the detailed technical report your engineers need to remediate.

How long does an assessment take?

It depends on scope, but a typical focused assessment runs one to two weeks of testing plus reporting. We confirm the timeline during scoping — and critical findings reach you in real time, not only at the end.

Are you remote? Do you work with teams outside Mexico?

Yes. We’re based in Monterrey, MX and work remotely with teams internationally. Engagements are run over secure channels, and reporting is delivered securely.

// Free · no obligation · ~2 minutes

Curious where your API stands? Find out for free.

Run our automated API security diagnostic against a system you own. It flags the obvious, high-signal issues in minutes — and, just as usefully, shows you exactly what an automated pass can't catch. No jargon, no payloads, no surprises.

  • Non-intrusive — GET/HEAD/OPTIONS only
  • Just your work email + API URL
  • Full report emailed privately
Run the free diagnosticPrefer a senior-led engagement? Talk to us.

// Contact

Request an assessment

Tell us what you're building and what worries you. A specialist will reply within one business day to scope it with you.

Book a free 30-minute intro callGrab a time that works — straight to a specialist, no form to fill.

Or reach us directly

hello@shuralabs.io
  • Reply within one business day
  • Fixed fee, scoped up front — no hourly surprises
  • Everything under a mutual NDA

Attestation for

SOC 2ISO 27001PCI DSS