Product teams need credible security evidence, but traditional scoping often starts with repeated calls, vague boundaries and delivery risk. Pure scanners are faster, but leave the buyer to decide which output is real and what to fix first.
We're Kotav Labs.
An independent security lab serving product teams worldwide through fixed-scope assessments, automation-first delivery and explicit human review.
Leads scope, delivery quality and the Argus platform. Brings senior technology, security and engineering leadership across international product organisations.
Vetted independent security specialists are contracted transparently for defined application, API, cloud or framework work when the agreed scope requires additional capacity.
Make serious security work easier to buy and deliver
Kotav productises the work between those extremes. Structured intake and Argus handle repeatable tasks; the principal and selected specialists review material findings and recommendations. Fixed pricing follows from fixed scope — not from pretending every engagement is identical.
Principal-led. Specialist-backed.
Kotav is a focused lab, not a large consultancy. Core delivery stays with the principal; vetted specialists are reserved for defined scopes that genuinely require additional expertise.
years of leadership
Technology, security and engineering
published service scopes
Discovery, focused, full, continuous, compliance
pentest options
Focused Validation or Full Application
evidence hosted in EU
Hetzner Germany · processor terms disclosed
The operating team
Kotav is a focused lab, not a large consultancy. Core delivery stays with the principal; vetted specialists are reserved for defined scopes that genuinely require additional expertise.
Founder & Principal
Leads scope, delivery quality and the Argus platform. Brings senior technology, security and engineering leadership across international product organisations.
Specialist Network
Vetted independent security specialists are contracted transparently for defined application, API, cloud or framework work when the agreed scope requires additional capacity.
How we work
Company: Kotav International — business and assets, Lda. · Registered in Portugal · NIF available on request · Methodology: OWASP Testing Guide v4.2 · PTES · NIST SP 800-115
Signed before we start
Every engagement starts with a signed Rules of Engagement document. We never probe a target without documented authorisation.
Audit trail on every action
Every HTTP request, finding, and tool call is logged with a timestamp and SHA-256 hash. Tamper-evident and exportable.
EU-hosted evidence
Assessment infrastructure and stored evidence are hosted in Germany. Approved subprocessors and processing locations are disclosed per engagement. You own every artefact delivered.
What we stand for
Automate repetition
Structured intake, evidence mapping and repeatable checks belong in the platform. Human attention stays on ambiguity, impact and remediation.
Own the outcome
Every paid engagement has defined deliverables, a delivery window and explicit exclusions. Current pentest scopes include one defined retest.
You own the evidence
All findings, audit logs, SARIF, and remediation guidance are yours forever. Open standards. No vendor lock-in. Switch providers any time.
Transparent pricing
Published starting rates and scope limits make the commercial boundary visible before authorisation.
Want to work with us? Get in touch.
Whether you have a project in mind or just want to explore what's possible, we'd love to hear from you.
Contact us