

Flock
In developmentA migration word game. Sort sixteen words into hidden flocks, survive five rounds, reach the final Roost.
Raijuna is an independent security research lab and product studio. Vulnerability assessments with detailed remediation, products born from real work, and honest writeups of both.
The most visual work happens on mobile. Two builds in flight right now, screens straight from the build pipeline.


A migration word game. Sort sixteen words into hidden flocks, survive five rounds, reach the final Roost.

A tiny platformer where every level is lying to you. It is not a troll game. Promise.
Three products in production today. Real screens, captured from the live sites.
From initial reconnaissance to verified remediation — everything your team needs to ship secure software.
Full-scope review of your web applications, APIs, and authentication flows. Static analysis, dynamic testing, and deep manual review of business logic. Every finding verified with proof-of-concept reproduction.
Request AssessmentExecutive summaries for leadership, technical findings for engineers. CVSS scoring, full attack chain documentation, and step-by-step remediation with code-level guidance.
Request AssessmentRetainer-based security reviews, pre-release testing, threat modeling, and remediation verification. We retest after you fix.
Request AssessmentDuring a black-box assessment of a global infrastructure provider, an unauthenticated Harbor container registry exposed the organization's complete internal project structure — service names, repository counts, team namespaces, and architectural relationships — without requiring any credentials. This is how the registry was found, what it disclosed, and why container registries with open access represent a more serious reconnaissance surface than they appear.
Most bugs die in a Jira ticket. We think the interesting ones deserve a proper writeup — the full chain, the dead ends, what actually worked and why.
We combine deep manual testing with systematic analysis to find vulnerabilities that automated scanners can't — broken access control, business logic flaws, and multi-step attack chains.
Comprehensive security assessments with detailed findings, proof-of-concept reproductions, and actionable remediation — delivered as a report you can act on immediately.