About
About and certifications
RRNK Security is a penetration testing team working with organisations in Thailand and with international clients. We prioritise manual testing, demonstrated impact, and reporting that technical teams can genuinely use.
How we work
Every engagement has a named tester who is accountable for it, and every report is peer-reviewed internally before delivery. We do not ship scanner output as a report, and we say so directly when a piece of work falls outside our expertise.
Certifications held by team members
The following certifications are held by members of our team. We present them as text only and do not reproduce issuer logos unless usage rights have been confirmed.
-
OSCP
Offensive Security Certified Professional
-
eWPT
eLearnSecurity Web Application Penetration Tester
Verification — eLearnSecurity Web Application Penetration Tester
-
eWPTX
eLearnSecurity Web Application Penetration Tester eXtreme
Verification — eLearnSecurity Web Application Penetration Tester eXtreme
-
CPSA
CREST Practitioner Security Analyst
-
CRT
CREST Registered Penetration Tester
Please note: these are individual practitioner certifications, not company accreditations. RRNK Security is not a CREST-accredited company, is not a certification authority, and is not an official partner of OWASP or of any certification body.
How we hold ourselves to account
-
Authorised testing only
No testing begins before written authorisation is in place from someone empowered to grant it for the target systems.
-
Prove it before we report it
We do not report what we cannot demonstrate, and we say clearly when a finding is an observation rather than a confirmed vulnerability.
-
Plain, accurate language
We avoid overstated claims. We do not promise that a system is fully secure, because no assessment can honestly promise that.
-
Protect client data
Engagement data is restricted to those who need it, stored encrypted, and destroyed on the agreed schedule.
Contact
Start with a scoping conversation
Tell us roughly what you need tested and we will come back with a proposed scope, duration and testing approach.
We test only with written authorisation and only within the agreed scope.