Tervaq iconTervaq

Tervaq Security Intelligence

Understand the threat. Strengthen the response.

We investigate digital abuse and AI-enabled threats, assess controls under authorization, and help teams verify the changes they make. The work is evidence-led, confidential by agreement, and grounded in the systems your team actually operates.

The work

From an initial signal
to a defensible decision.

Not every claim is a confirmed incident. Our reports distinguish what was observed, what a source reported, what testing established, and what is still unknown.

Fraud & abuse intelligence

What is happening, and what does the evidence actually show?

Review lawfully obtained information about account abuse, identity misuse, malicious automation, and AI-assisted fraud. Separate source claims from confirmed observations and identify what needs further investigation.

What your team receives

An evidence-led assessment with a timeline, confidence levels, affected workflows, and recommended next steps.

Authorized adversarial research

Where could the controls fail?

Assess agreed application and AI workflows using controlled tests. Examine identity boundaries, agent permissions, business logic, and abuse controls within written authorization and a defined scope.

What your team receives

A technical findings report, safe reproduction evidence, risk priorities, and clearly documented limitations.

Remediation & control validation

Does the change address the problem?

Work alongside your engineering and security teams to review proposed mitigations and retest the affected controls. Record what was fixed, what remains open, and what was outside the assessment.

What your team receives

A remediation review and retest record your team can use to make the next decision.

Research focus

Where identity, automation,
and trust meet.

Our focus includes financial services, digital platforms, and organizations deploying AI into sensitive workflows. Each engagement is shaped around the risks, controls, and operating context of the system being assessed.

  • Account and identity abuse

    Enrollment, recovery, authentication, and transaction-related controls.

  • AI-enabled fraud and automation

    How automation changes the speed, reach, and behavior of abuse.

  • AI system and agent security

    Tool permissions, unintended actions, data exposure, and human review boundaries.

Commercial engagements

Serious research.
Clear commercial terms.

Investigations, technical assessments, and remediation validation are paid professional services. Fees, deliverables, access, and timelines are agreed before commissioned work begins.

Defined project

Focused assessment

A specific research question or risk, a bounded scope, and agreed deliverables. Suitable for an initial investigation or an independent review.

Fixed project fee agreed before work begins.

Milestone-based

Research partnership

A longer collaboration on applied AI, security controls, or complex workflows. Work is divided into reviewable milestones with clear ownership.

A paid statement of work with milestones and acceptance criteria.

Ongoing engagement

Intelligence retainer

Research and briefings around an agreed set of threats, products, or markets. Coverage, review cadence, and escalation arrangements are set together.

A recurring fee for the agreed scope and service level.

Working principles

Clear boundaries.
Responsible research.

The purpose of this work is to help organizations protect their systems and users. Our commercial services and responsible reporting are separate.

Authorization comes first
Testing requires written permission, a defined scope, and agreed test environments or identities. An inquiry is not permission to test.
Handle evidence carefully
Minimize personal data. Agree on secure transfer, access, retention, and deletion before sharing sensitive material. Do not send credentials or customer records through the public inquiry form.
Coordinate disclosure
Report credible risks to the appropriate owner through a responsible channel. Notification is not a threat or a condition of buying our services.
Keep the work defensive
No criminal tooling, unauthorized account access, or movement of customer funds. Findings and limitations are documented without exaggeration.

Security reporting

Reporting an issue is a different conversation.

For an issue affecting Tervaq, start with a brief, non-sensitive summary and request an appropriate disclosure channel. For a third-party system, use that organization’s official reporting process. This page is not a public bounty program or authorization to test.

Contact Tervaq about an issue

Work with Tervaq

Put the evidence to work.

Describe the risk or research question at a high level. We will discuss scope, authorization, and a paid engagement that fits the work.

Discuss an engagement