About

About and certifications

RRNK Security is a penetration testing team working with organisations in Thailand and with international clients. We prioritise manual testing, demonstrated impact, and reporting that technical teams can genuinely use.

How we work

Every engagement has a named tester who is accountable for it, and every report is peer-reviewed internally before delivery. We do not ship scanner output as a report, and we say so directly when a piece of work falls outside our expertise.

Certifications held by team members

The following certifications are held by members of our team. We present them as text only and do not reproduce issuer logos unless usage rights have been confirmed.

Please note: these are individual practitioner certifications, not company accreditations. RRNK Security is not a CREST-accredited company, is not a certification authority, and is not an official partner of OWASP or of any certification body.

How we hold ourselves to account

  • Authorised testing only

    No testing begins before written authorisation is in place from someone empowered to grant it for the target systems.

  • Prove it before we report it

    We do not report what we cannot demonstrate, and we say clearly when a finding is an observation rather than a confirmed vulnerability.

  • Plain, accurate language

    We avoid overstated claims. We do not promise that a system is fully secure, because no assessment can honestly promise that.

  • Protect client data

    Engagement data is restricted to those who need it, stored encrypted, and destroyed on the agreed schedule.

Contact

Start with a scoping conversation

Tell us roughly what you need tested and we will come back with a proposed scope, duration and testing approach.

We test only with written authorisation and only within the agreed scope.