Pentest. Build the tools that were missing.
own2pwn is THE HIVE: the tools I'd have wanted as a pentester.
On the services side: black-box and white-box web pentests, which I run myself. On the product side: an EASM platform for external attack surface, and an AppSec suite that extends a human-led audit between engagements.
Continuous, contextual, actionable pentesting.
In most organisations, pentesting is still a one-shot event: an annual audit, a report that gathers dust in a drawer, and a six-to-twelve-month gap between two offensive perspectives. That gap is exactly where regressions creep in.
My goal: make offensive testing reproducible between two engagements, without rerunning a full audit at every release.
That's what both own2pwn products aim to do. EASM keeps your exposed-asset inventory up to date. SecAI analyses your code continuously, on every commit, and flags regressions between audits. Human engagements stay where they're worth their cost: exploitation, architecture review, contextual judgement.
AI is used to reduce noise (false positives, non-exploitable findings) and to draft reports. The final call, qualifying, prioritising, writing the client-ready version, always goes through a human operator.
The principles behind every product.
Offensive rigor
My personal commitment: test like an attacker, document like an auditor. No cosmetic checklists, no unreproducible findings.
Transparency
Detailed reports with proofs of exploitation, justified CVSS scores, concrete remediation plans. No black boxes, you understand every finding.
Sovereignty
Code, data, and hosting in the EU. Native GDPR compliance. Your pentest results stay strictly confidential.
Useful automation
AI isn't a marketing gimmick: I use it to cut false positives, prioritise by real exploitability, and focus my time on what requires human judgement.
Three pillars, one offensive approach.
EASM
Continuous mapping of your external attack surface. Forgotten-asset discovery, CVE detection, real-time alerts.
AI-Native AppSec
Contextual taint-based SAST, SCA, IaC and secrets, automated reports. A continuous static-analysis platform for application security.
Web Pentesting
Black-box and white-box audits delivered by an OSWE-certified pentester. Actionable reports, retest included.
What exists, and since when.
Genesis
A field-driven realisation: too many false positives, too many non-actionable findings, too much overlooked attack surface. own2pwn starts here, with the first lines of the site and tooling written for my own use.
The pentest offering
Black-box and white-box web pentesting becomes a formalised offering: scope agreed in writing, methodology, two-level report with PoC and CVSS, retest included, and published day rates on a market where nobody shows a figure.
Building EASM
Writing the EASM engine: multi-source discovery from a single root domain, detection catalogue, CVE correlation and CISA KEV / EPSS prioritisation.
EASM in production, SecAI in pre-launch
EASM runs in production on easm.own2pwn.fr. SecAI, the AppSec suite (taint-tracking SAST, SCA, IaC, secrets), is in pre-launch: static analysis only, no DAST and no replay against a live target.
Author
THE HIVE, one offensive operator, founder of own2pwn.
Pentester by trade, OSWE-certified. I founded own2pwn to bring defensive tooling closer to real-world offensive practice: you don't build a strong security product without having broken systems yourself.
own2pwn is published by THE HIVE, a French single-shareholder company. A deliberately minimal structure, and that is the point of the offering: every engagement, every line of code, every report goes through the same person, the one who signs it.
Test your defences, continuously.
Discover EASM or talk to us directly about your pentest needs.