About Pentest.md · Project by BSD Management

Security isn’t promised.
It’s proven.

We’re the team that stress-tests the defenses of companies in Moldova and Romania — manually, rigorously, from the perspective of a real attacker. No shallow scanners, no generic reports.

Our story

Why we exist

Moldova is digitizing fast — banks, payment processors and public institutions are moving more and more services online. But attackers have evolved faster than defenses. Too many organizations believe they’re protected because they “passed a scan” — until a real breach proves otherwise.

Pentest.md was born out of BSD Management with a simple conviction: real security is tested like a real attack — manually, by people who think like the adversary. We don’t deliver a report. We deliver the certainty of knowing exactly where you’re vulnerable, before anyone else finds out.

The Pentest.md team 100% manual testing
15+
Projects completed
500+
Vulnerabilities found
10+
Happy clients
99%
Satisfaction rate

Our mission

To deliver the highest-quality penetration testing, helping organizations protect their digital assets and meet international standards — with concrete evidence, not promises.

Our vision

To become the region’s go-to security partner — the firm banks and institutions call when security truly matters.

How we work differently

We don’t just scan. We attack — under control.

Every engagement is a real attack simulation, not a list of automated alerts. Here’s what sets us apart.

100% manual testing

Certified engineers, not just scanners. We validate real impact, not just automated detection.

Attacker’s perspective

OWASP Top 10, realistic scenarios and controlled exploitation — we test the way someone actually would attack.

Actionable reports

CVSS severity, evidence, reproduction steps and clear remediation — for leadership and for the technical team.

Critical & regulated environments

Hands-on experience with banks, fintech and public institutions — and with NIS2, GDPR, PCI-DSS requirements.

Security operations centre Security team
Team & Operations

Certified people, not just tools

Behind every test are certified security engineers with real experience in critical environments. Technology helps — but the decisions, creativity and rigor come from people.

  • OSCP, CEH, CISA certified engineers
  • Manual methodology + real-impact validation
  • Clear, solution-oriented communication
OSCPCEHCISAISO 27001CREST
Partners

Organizations that entrusted us with their security

OTP Bank Biroul de Credit Paynet Paymaster (RunPay) Iute Credit Qiwi Moldova Vcredit
Our values

The principles we work by

Integrity

We act with honesty and transparency. We tell you exactly what we found — and what we couldn’t test.

Excellence

We strive to deliver the best result on every project, not the contractual minimum.

Innovation

We adopt the latest techniques and methodologies to stay one step ahead of attackers.

Let’s talk about your security

A free, no-obligation consultation. We’ll tell you honestly where you stand and how we can help.