testclub_

Who's accountable for the outputs?

Specification-led security testing for APIs and AI systems. When a system is confidently wrong at scale, the exposure is yours.

// Fuzz attack surface representation

The problem

Systems are being built faster than anyone can check them, by tools nobody can fully explain. The old failure was an outage. The new one is a system working exactly as built, doing damage nobody authorised.

01 · 'THE GAP'

It's the post-mortem. Someone senior wants to know why.

"Who defined what the behaviour should have been here?"

Nobody.

That is the hardest problem in software. And it is getting harder.

02 · API SECURITY

The API layers of digital applications are often a huge attack vector, but these load-bearing structures can be the least scrutinised area. Business logic flaws don't show up in automated vulnerability scans. An API must be deeply understood before we can creatively discover where the genuine vulnerabilities are.

03 · AI INPUT/OUTPUT

Who is taking responsibility for the quality of the outputs from your AI application? Inputs are not limited to chatbot interfaces and direct prompting. Are you defining what good looks like and how much variance is acceptable in your system's outputs? Are you checking this at scale?

What we do

01 · WEB / API SECURITY

Business logic and API security. OWASP Web and API Top 10s, authentication, authorisation, and the flaws built for a different kind of check.

Web / API Security →
02 · LLM SECURITY AND EVALS

Empirical failure rates for AI systems before deployment, mapped against the OWASP Top 10 for LLM Applications. Quantified, characterised, against your criteria. Not the vendor's benchmark. Yours.

LLM Security and Evals →
03 · SPECIFICATION AS METHOD

Twenty-five years of asking the same question, before it was APIs or AI. The discipline behind everything above.

Read the philosophy →

Who

Testclub was founded in 2012 by Omar El Dali, built on twenty-five years at the boundary between specification and implementation, across trading platforms, fintech, insurance, health, energy and government.

A skilled high-agency group who move fast and adapt to what your project actually needs. Every finding arrives with its evidence and the method that produced it, so an engineer can follow every step.

Meet the team →

Clients

View case studies →

Schroders
Nando's
EDF Energy
Nephila Capital
esure
Sportingtech
1Minus1
MRM Global
Valtech
ASquared
Attercop
// Fuzz attack surface representation