Skip to content

Operators

The name on the report is the person who ran the test.

Publishing a roster is easy and buyers have learned to discount it — a name on a website is not a promise about who is assigned to you. So Zero Harbor Security commits to the harder version: the operator who performs your test is the operator who signs it, the seniority mix and hours are disclosed before you sign, and the same operator runs your next test unless you ask for fresh eyes.

The roster

Two operators. One breaks it, one builds it.

That pairing is the point rather than a compromise. The flaws that stop an enterprise deal are rarely a missing patch — they are logic, identity and permission boundaries. Finding them quickly is far easier when somebody on the engagement has had to ship and operate the same kind of system in production.

Suhyun Smith

Founding Principal

Cloud, application, product and AI security testing

Built the end-to-end penetration testing programme at Amazon Web Services — scoping, threat modelling, exploitation, lateral movement and executive reporting. Then three years on Amazon’s red team against shipping consumer hardware including Ring and Alexa, and two more in vulnerability research and patch delivery. Before that, infrastructure, application and physical security testing at a top-ten US bank, identity and access management in a payments environment, and formal product testing to NSS Labs, Tolly Group and ICSA Lab standards for the Korean government — where the Common Criteria associate researcher certificate was earned in 2015. Currently reading for an MS in Computer Science on the machine learning track at Georgia Tech, which is what sits behind the AI red team work.

OSCP · CISSP · AWS Security – Specialty · CEH v9 · AWS AI Practitioner

Signs their own engagements, and co-signs as named reviewer where another operator leads.

Matthew Rachwal

Operator, Engineering

Application internals, APIs, cloud infrastructure

Ten years building production software, the last seven at a Fortune 500 mutual insurer — scalable REST microservices over DynamoDB, MySQL and RDS, backend data transformation, and release automation later adopted across teams. Earlier, APIs that normalised and synced more than twenty million product records a day from six sources, on Node, MongoDB and Elasticsearch with Redis and RabbitMQ. Co-founder of a hosting platform, where he owns the infrastructure end to end. Holds an Associate of Applied Science in IT Cybersecurity Specialist.

AWS Developer – Associate

Signs their own engagements. A named senior reviewer signs alongside, and both names appear on the letter.

Who signs

The attestation carries the name and credentials of the operator who ran the test — junior or principal. Nobody signs for work they did not personally perform. Where a junior leads, a named senior reviewer signs alongside them, and both names appear.

Disclosed before you sign

The seniority mix and the hours at each level are disclosed before you sign, and they are reflected in the price. You are never quoted a senior and delivered a junior.

Continuity

The same operator runs your next test unless you ask for fresh eyes. If they become unavailable you are told before the engagement starts, not when the report arrives with a different name on it.

Limits

What Zero Harbor Security does not do.

A two-person firm that claims to do everything is not a firm, it is a reseller. These are the honest boundaries.

No 24/7 monitoring or SOC

Zero Harbor Security tests systems. It does not watch them. If you need detection and response you need a team, and you will be told that rather than sold a retainer.

No continuous-testing subscription

Platforms sell a year of automated external testing for roughly what one thorough manual engagement costs. If continuous coverage is what you need, buy the platform — and hire us to validate what it finds.

A deliberately small bench

Two operators means a small number of engagements at a time, each led by a named one. Booking usually runs several weeks out. We would rather say no than deliver something thin.

No compliance claims we cannot support

Several regulations are widely misdescribed as requiring a penetration test when they do not. You will be told what your framework actually says, even when the honest answer costs the engagement.

No accredited certifications

PCI ASV scanning, FedRAMP assessment, CMMC certification and Common Criteria evaluation all require accreditation we do not hold. Testing to prepare for them, yes. Issuing them, never.

No financial-services engagements at present

Registered investment advisers, funds and family offices are outside the current practice. A deliberate boundary, not a capability gap.

Start a conversation.

Send the scope, or a rough description of it. A fixed price and a delivery date come back in writing, and you are told which operator is assigned before anything is signed.

Start a scoping call