Founded in 2019 by Iheb Ennachet (also known as Iheb Nachet) — developer first, penetration tester second. Evosec is a web & mobile development agency with an in-house offensive security team, serving startups and scale-ups in France, the United States and worldwide.
Ship fast. Ship secure. Refuse to choose.
Most agencies treat security as a line item at the end of the project — if at all. We put the people who break software in the same sprint as the people who build it. The result is products that pass the App Store review, the security questionnaire and the RGPD audit on the first try.
We don't resell tools or outsource the work. Senior engineers write the code, our own red team attacks it, and we're the accountable party for both.
Every developer on the team has shipped production software — and every tester has broken some. Nobody at Evosec only sells.
Written scope and fixed-price milestones within 48 hours of the first call. No surprise line items, no phantom advisory fees.
If a client's posture is bad, we say so on the first call. If we're not the right fit, we refer out. Trust compounds.
We measure success by outcomes: products shipped on time, vulnerabilities fixed before launch, audits passed, zero client breaches.
Custom web applications, SaaS platforms, B2B portals and e-commerce on Laravel and Next.js. Fixed-price milestones, weekly demos, penetration test before every release.
iOS and Android apps in React Native, Flutter, Swift and Kotlin. Secure storage, hardened APIs, OWASP MASVS pentest before store submission.
Simulated adversary operations against your organisation. We act like an attacker to find what your defenders will miss. External, internal, physical, and social engineering.
Blend of automated scanning and deep manual testing. Web apps, APIs, mobile, network, wireless. Actionable reports with CVSS scoring and remediation roadmaps.
Tactical threat intel delivered as a newsletter and on-demand briefings. Know what's targeting your sector before it hits. Curated by our team, not a feed.
Ongoing discovery, prioritisation, and tracking of vulnerabilities across your estate. We turn scan output into a remediation programme your team can actually execute.
24/7 monitoring, threat hunting, and incident response. Alert fatigue killed by our triage process. Real humans investigating real threats.
PCI DSS-compliant quarterly external vulnerability scanning by our Approved Scanning Vendor team. Clean reports for your compliance programme.
30-minute call with a senior engineer. Written scope and fixed-price estimate within 48 hours.