Offensive security meets production engineering. Small team. Ulaanbaatar, Mongolia.
From code to
compromise.
Penetration Testing
OSWE-certified assessments across web, API, and mobile attack surfaces.
Full-Stack Dev
Next.js, React, Go - security-first from line one.
Security Engineering
Source code review, threat modeling, and hands-on remediation.
Infrastructure
Containers, CI/CD, cloud migrations. No shortcuts.
Small crew.
Sharp edges.
Every one of us writes code, breaks code, and ships to production. No managers. No overhead.

Erdene-Och Byambabayar
Tech Lead
Full-stack architect. System design to deployment.

Byambaa Battulga
Software Engineer
Crypto & backend. 5 years deep. CTF competitor.

Uuganbayar Lkhamsuren
Security Engineer
OSWE. 40+ pentests. Finds what scanners can't.
Bugs found.
CVEs published.
Active in bug bounty programs and responsible disclosure - making open-source safer, one CVE at a time.
15+
CVEs Published
$10K+
In Bounties
Yahoo
AWS
Monero
Lambda.global
Агула Даатгал
Татварын Ерөнхий Газар
Vercel
Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
etcd: Nested etcd transactions bypass RBAC authorization checks
NocoDB has Plaintext Storage of Shared View Passwords
NocoDB Vulnerable to User Enumeration via Password Reset Endpoint