Skip to content
Client access

Experts who attack.
An engine that keeps watch.

Continuous monitoring of your attack surface with Kynapt, our own engine: it detects exposed assets and newly published vulnerabilities, and every finding goes through a certified pentester before it reaches you. No reports that go stale.

Certified.

Ethical.

Rigorous.

Trusted.

Our team is certified in offensive security

  • OSCP — OffSec Certified Professional (OffSec)
  • OSCP+ — OffSec Certified Professional Plus (OffSec)
  • CRTP — Certified Red Team Professional (Altered Security)
  • eWPTXv2 — Web Application Penetration Tester eXtreme (INE Security)
  • eCPPTv2 — Certified Professional Penetration Tester (INE Security)
  • eWPT — Web Application Penetration Tester (INE Security)
  • eMAPT — Mobile Application Penetration Tester (INE Security)
  • eJPT — Junior Penetration Tester (INE Security)

Hands-on certifications held by Kamaya Secure consultants, earned by compromising real systems under exam conditions.

About Kamaya Secure

We are a Peruvian consultancy specialized in offensive security. Kynapt, our continuous monitoring engine, works all year round: it discovers your exposed assets, detects newly published vulnerabilities and cross-checks the versions of your technology. Certified pentesters validate every finding before it reaches your team, and you see it in your portal in real time.

We combine certified technical expertise with first-hand knowledge of Peruvian regulation and operating context, so every finding translates into concrete decisions.

We work with clear rules, formal authorization and full confidentiality: our clients’ trust is the foundation of everything we do.

Certified pentesters

Hands-on certifications such as OSCP, OSCP+, CRTP, eCPPT, eWPTX, eWPT, eMAPT and eJPT, earned by compromising real systems under exam conditions.

Traceable methodology

Findings with reproducible evidence, mapped to MITRE ATT&CK: what to fix, why, and in what order.

Local presence

From Lima, in your language and time zone, with on-site work and deliverables aligned with SBS and Law No. 29733.

Reports for two audiences

An executive summary for leadership and a technical report for IT, prioritized by business impact.

Our team

The team that attacks to protect

Pentesters, researchers and engineers who design, run and validate every assessment and every Kynapt finding.

  • Alejandro Manuel Vega Vásquez

    Alejandro Manuel Vega Vásquez

    Managing Partner · Head of Offensive Security

    Managing partner at Kamaya Secure and head of offensive security. He leads the technical relationship with clients in mining, banking and the public sector, aligning every pentest and Red Team exercise with the business. Telecommunications Engineer (UNI).

  • Percy Jayo

    Percy Jayo

    CTO

    As CTO, he leads Kamaya Secure’s technical area. He is a bug hunter and penetration tester with experience finding vulnerabilities in real-world environments. He speaks at academic events on offensive techniques such as data exfiltration over DNS.

  • Paulo Puicón Gallardo

    Paulo Puicón Gallardo

    Project Director

    As project director, he coordinates the planning and execution of every assessment, from scoping to the delivery of results. He is the client’s point of contact throughout the engagement and oversees timelines and the quality of deliverables.

  • Jesús Arturo Espinoza Soto

    Jesús Arturo Espinoza Soto

    Senior Penetration Tester · Associate Consultant

    Penetration tester with over 7 years of experience in web, mobile and infrastructure assessments, recognized in responsible disclosure programs. Certified OSCP, CEH, eCPPTv2, CREST CPSA and Burp Suite Certified Practitioner. Master’s in Cybersecurity.

Kynapt platform

Always on. Always validated.

Kynapt watches your attack surface between engagements: it discovers what you expose, retests it when a new vulnerability is published and only delivers what a certified pentester confirmed. All of it, in your client portal.

01

Attack surface radar

Keep an up-to-date inventory of what your organization exposes to the internet, without relying on spreadsheets.

  • Discovers subdomains, web services, APIs, ports and technologies from the domains and IP ranges you approved.
  • Classifies every asset by type and criticality: remote access, admin panels and sensitive services first.
  • Nothing is tested without authorization: every new asset is reviewed by a pentester before it enters monitoring.
  • Your portal shows what is being monitored and when it was last checked.
Monitoring tab of the client portal: an active engagement with weekly cadence, last and next scan dates, and the list of monitored assets with their type and criticality
Kamaya Secure client portal · demo data

02

Validation engine

Recurring tests on your authorized assets, and a human filter before anything reaches your team.

  • Scheduled scans (daily, weekly or monthly) or on demand, with rate limiting so your operations are not affected.
  • Detects vulnerabilities with a published CVE, insecure configurations, exposed services and default credentials.
  • Triage removes duplicates and prioritizes; every critical or high finding always goes to a pentester.
  • By default, only what a certified pentester confirmed is published to your portal.
Critical finding in the client portal: detected by continuous monitoring on a staging asset and under technical review by an analyst before it is final
Kamaya Secure client portal · demo data

03

Remediation hub

From finding to verified fix, with traceability for your team and your auditors.

  • Findings with severity, affected asset and recommendation, visible as soon as they are published.
  • Your team records the fix and requests a retest; a pentester verifies it and closes the finding.
  • Alerts by email, Slack or Jira, without exposing finding details outside the portal.
  • Versioned reports and documents, with an integrity check on every download.
Client portal home: indicators for active engagements, critical findings, coverage and pending retests, with charts of findings by severity and by status
Kamaya Secure client portal · demo data

Explore our cyber security capabilities

Ten services covering the full cycle (anticipate, withstand and respond), backed by Kynapt, our continuous monitoring engine. Every engagement is tailored to your organization’s maturity, industry and regulatory obligations.

Red Team & Ethical Hacking

Human-led adversary exercises that test whether your organization detects and contains a real attack, with tactics mapped to MITRE ATT&CK.

Automation
Between exercises, Kynapt keeps the map of your exposed attack surface up to date, so every campaign starts from what an attacker would see today.
Human validation
Certified operators design the attack chain and evasion techniques, and your portal shows what was tested and what your team detected.
Learn more: Red Team & Ethical Hacking
Penetration Testing

Manual testing of web applications, APIs, mobile apps, infrastructure and cloud that goes where a scanner can’t.

Automation
Kynapt, our continuous monitoring engine, discovers your exposed assets, identifies technologies and versions, and retests them whenever a vulnerability that affects them is published.
Human validation
Certified pentesters (OSCP, OSCP+, CRTP, eCPPT, eWPTX and more) manually exploit what Kynapt flags and look for what no tool can see. You follow progress in your portal.
Learn more: Penetration Testing
Source Code Review

We find vulnerabilities in your code before they reach production, in any language.

Automation
Automated analysis scans your entire codebase and its open-source dependencies for insecure patterns and known CVEs.
Human validation
Our reviewers manually validate critical logic (authentication, authorization and data handling) and discard false positives.
Learn more: Source Code Review
OT/ICS Security

We assess your industrial control systems (IT/OT segmentation, IEC 62443 and NERC CIP) without stopping operations.

Automation
Kynapt watches the internet-facing edge of your industrial network. Inside the OT network we use passive methods only, never active scanning.
Human validation
Our specialists validate every test in a lab before touching a production environment, and you see the status in your portal.
Learn more: OT/ICS Security
Social Engineering & Awareness

Controlled phishing, vishing and malicious QR campaigns that measure the human factor and turn it into a line of defense.

Human validation
Specialists design realistic scenarios for your industry and turn the results into concrete training.
Learn more: Social Engineering & Awareness
Bug Bounty & Vulnerability Disclosure

We design and run your responsible disclosure and bug bounty program with our own community of researchers.

Automation
Every report is checked against your program’s authorized scope, so out-of-scope submissions don’t take up your team’s time.
Human validation
Our pentesters reproduce every report and confirm its severity before it reaches you.
Learn more: Bug Bounty & Vulnerability Disclosure
Incident Response & Forensics

We contain the incident, identify the root cause and guide recovery following NIST SP 800-61.

Automation
If your organization uses Kynapt, the asset inventory and previous findings are already in the portal, which shortens the initial analysis.
Human validation
Our team leads containment and preserves evidence with chain of custody.
Learn more: Incident Response & Forensics
Compliance & Risk Management

We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.

Automation
The history of Kynapt scans, findings and retests in the portal serves as documented evidence of your vulnerability management cycle.
Human validation
Our consultants prove that each control actually works, not just that it is written in a policy.
Learn more: Compliance & Risk Management
CISO as a Service

Outsourced security leadership: strategy, roadmap and board reporting, without the cost of a full-time executive.

Automation
The portal gives your board up-to-date indicators: open findings by severity, pending retests and the progress of each engagement.
Human validation
Your outsourced CISO prioritizes risks according to your business and drives execution with our technical team.
Learn more: CISO as a Service
Zero Trust

Consulting to design and adopt a zero trust model: identity, segmentation and continuous verification.

Automation
Kynapt checks from the outside that no services remain exposed beyond the perimeter your Zero Trust architecture should close.
Human validation
Our pentesters attack the implementation to confirm that segmentation and access controls hold up in practice.
Learn more: Zero Trust

Sectors where continuity is non-negotiable

Every industry has its own attack surface, regulators and timelines. We tailor the scope and language of each engagement to your operational reality.

Mining

Remote operations, critical OT assets and extended supply chains. We protect production continuity.

Banking & Fintech

SBS and PCI DSS requirements, digital fraud and exposed APIs. We assess your risk through an attacker’s eyes.

Government

Digital citizen services, personal data and legacy systems. We help public entities protect them.

View all insights →

Kamaya Secure logo on an office wall

Attackers don’t wait. Get ahead with Kamaya Secure.

Knowing in time how your organization could be attacked is the most efficient way to protect your operations, your reputation and your customers.

Talk to a specialist: together we agree on scope, rules of engagement and deliverables before we start.

Chat on WhatsApp (opens in a new tab)