Cutting-edge consulting by Jason Haddix and crew. No expert bait-and-switch: every engagement is delivered by world-class researchers, handpicked for your project and led by Jason.
A full-spectrum offensive portfolio, each engagement delivered by researchers picked for your scope and led by Jason from start to finish.
Deep, methodology-driven testing of your web apps by hunters from the top of the bug bounty leaderboards.
Real testing, real insights. Your internet-facing perimeter, assessed the way real attackers approach it, recon first.
Simulating real-world internal threats. Start inside: measure blast radius, lateral movement, and detection response from a foothold.
Comprehensive security for AI-enabled systems: LLM apps, agents, and pipelines, tested against prompt injection, jailbreaks, and the OWASP LLM Top 10.
Scale your security program. We help your security org adopt AI: workflow analysis, tooling, and augmentation roadmaps.
Full-scope adversary emulation, phishing to objective. Modern initial access via file and credential-capture phishing, dependency confusion and hijacking, plus dark-web credential harvesting for stuffing.
Collaborative, side-by-side testing that tunes your detection and response across real attack scenarios, elevating both teams at once.
Thorough testing of your airspace for rogue access, misconfigurations, and exploitable weaknesses across your wireless footprint.
Comprehensive mapping of your external attack surface, surfacing unknown assets and hidden exposures before attackers find them.
Deep, methodology-driven testing of your iOS and Android apps and the APIs behind them.
Need a blended scope or something not listed here? Talk to the team about what you need.
Security program and CISO advisory, from a leader who has been breach tested.
"Our advisory services are deeply rooted in a worldview created across my career in security. I've seen it all through my time. I've been the hacker, the defender, and the executive. My advisory services are modern and practical, focusing on building programs and advising leaders to protect what matters most. Every business is different, but adversary motives stay very static. An advisory engagement with Arcanum is heavily focused on the most common risks organizations face today. This means bolstering application security, security engineering, and understanding what parts of corporate security matter most."
Program or executive: one trusted partner, at the altitude you need. Security Program Advisory builds and matures your program: application security, security engineering, frameworks, and metrics. CISO Advisory guides your leaders on strategy, board communication, and risk decisions. Often a single engagement spans both.
Content and community from Jason and the Arcanum crew, across every channel.
Jason and Arcanum run a specialized Discord to support the class communities. In the public channels, you can find useful discussions, links, and more. For class participants or subscribers, you get access to private resources, monthly hunts, recon data, videos, and more!
Jason and Arcanum deliver a newsletter with Jason's personal commentary on the intersection between offensive security and security leadership. Sometimes hacker-ish, sometimes CISO-ish. Very blazer over the t-shirt type of vibe...
Our YouTube is where we post some of our exclusive content after a bit. Be sure to subscribe for some banger hacking tricks, interviews, and more!
Speak with our consulting team about penetration testing, cyber red teaming, purple team, attack surface discovery, security program or CISO advisory, or something custom.