WE BUILD IT.
WE BREAK IT FIRST.

Founded in 2019 by Iheb Ennachet (also known as Iheb Nachet) — developer first, penetration tester second. Evosec is a web & mobile development agency with an in-house offensive security team, serving startups and scale-ups in France, the United States and worldwide.

Doctrine

WHAT WE BELIEVE.

These principles guide every engagement we take on, every report we write, and every client conversation we have.

Ship fast. Ship secure. Refuse to choose.

Most agencies treat security as a line item at the end of the project — if at all. We put the people who break software in the same sprint as the people who build it. The result is products that pass the App Store review, the security questionnaire and the RGPD audit on the first try.

We don't resell tools or outsource the work. Senior engineers write the code, our own red team attacks it, and we're the accountable party for both.

01 · Engineers who attack.

Every developer on the team has shipped production software — and every tester has broken some. Nobody at Evosec only sells.

02 · Fixed price, plain SOWs.

Written scope and fixed-price milestones within 48 hours of the first call. No surprise line items, no phantom advisory fees.

03 · Tell the truth, early.

If a client's posture is bad, we say so on the first call. If we're not the right fit, we refer out. Trust compounds.

04 · Results over theatrics.

We measure success by outcomes: products shipped on time, vulnerabilities fixed before launch, audits passed, zero client breaches.

By The Numbers

THE SCOREBOARD.

Building and securing software since 2019 — for France, the USA and beyond.
20+
Years collective XP
▲ combined team
50+
Products & engagements
▲ web · mobile · security
0
Client breaches to date
▌ our only metric
<4m
Avg. incident response
▌ 24/7 availability
3
Core markets
▌ FRANCE · USA · TUNISIA
3
Languages spoken
▌ EN · AR · FR
100%
Products pentested pre-launch
▲ no exceptions
24/7
Emergency availability
▌ WhatsApp + phone
Capabilities

WHAT WE DELIVER.

Two things we build, six ways we secure them — all under one roof.
01

Web Development

Custom web applications, SaaS platforms, B2B portals and e-commerce on Laravel and Next.js. Fixed-price milestones, weekly demos, penetration test before every release.

▌ LARAVEL · NEXT.JS · SAAS · E-COMMERCE · APIS
02

Mobile App Development

iOS and Android apps in React Native, Flutter, Swift and Kotlin. Secure storage, hardened APIs, OWASP MASVS pentest before store submission.

▌ REACT NATIVE · FLUTTER · SWIFT · KOTLIN
03

Red Team as a Service (RTaaS)

Simulated adversary operations against your organisation. We act like an attacker to find what your defenders will miss. External, internal, physical, and social engineering.

▌ ADVANCED THREAT SIMULATION · OSCP-LEVEL OPERATORS
04

Vulnerability Assessment & Penetration Testing (VAPT)

Blend of automated scanning and deep manual testing. Web apps, APIs, mobile, network, wireless. Actionable reports with CVSS scoring and remediation roadmaps.

▌ OWASP · PTES · DAST/SAST · MANUAL TESTING
05

Threat Intelligence

Tactical threat intel delivered as a newsletter and on-demand briefings. Know what's targeting your sector before it hits. Curated by our team, not a feed.

▌ SECTOR-SPECIFIC · IOC FEEDS · APT TRACKING
06

Vulnerability Management

Ongoing discovery, prioritisation, and tracking of vulnerabilities across your estate. We turn scan output into a remediation programme your team can actually execute.

▌ CVSS PRIORITISATION · REMEDIATION TRACKING · SLA REPORTING
07

Threat Detection & Response

24/7 monitoring, threat hunting, and incident response. Alert fatigue killed by our triage process. Real humans investigating real threats.

▌ SIEM · EDR · MDR · IR RETAINER
08

ASV Approved Scans

PCI DSS-compliant quarterly external vulnerability scanning by our Approved Scanning Vendor team. Clean reports for your compliance programme.

▌ PCI DSS · QUARTERLY SCANS · COMPLIANCE REPORTS
Command Staff

THE BENCH.

Engineers and operators, not salespeople. Every team member has shipped or broken real software.
▌ CEO · Founder

Iheb Ennachet (Iheb Nachet)

Full-stack engineer, mobile & web developer, penetration tester and founder. Laravel · Next.js · React Native. Known as 0xdeadbeef & 0xslayer. Read full profile →
EN
▌ Engineering

Product Engineering Team

Senior Laravel, Next.js, React Native and Flutter engineers. Every feature ships with tests, a staging demo and a security gate.
RO
▌ Red Team Lead

Red Team Ops

Adversary simulation and exploitation. OSCP-level operators. Pentests every product before launch; physical, digital and social engineering engagements.
Base of Operations

WHERE WE OPERATE.

Nearshore for France, remote for the USA. Headquartered in Sousse, Tunisia — Europe's leading nearshore engineering hub.
▌ HQ · PRIMARY BASE

Sousse, Tunisia

Avenue Habib Bourguiba S.B.A
4040 Sousse, Tunisia
+216 55 737 390
REMOTE ENGAGEMENTS GLOBALLY
▌ CORE MARKETS

🇫🇷 France · 🇺🇸 USA · 🇹🇳 Tunisia

Paris time zone (CET) · daily US East Coast overlap
French & English contracts · EUR / USD invoicing
RGPD · NIS2 · SOC 2 · HIPAA aware
iheb.ennachet@devsolve-agency.com
LANGUAGES: EN · AR · FR

TELL US WHAT YOU'RE BUILDING.

30-minute call with a senior engineer. Written scope and fixed-price estimate within 48 hours.

► Start a Project