testclub_

Who's accountable for the outputs?

Specification-led security testing for APIs, AI systems, and LLM evaluations. Because when a system is confidently wrong at scale, the exposure is yours.

// Fuzz attack surface representation

The problem

Systems are being built faster than they can be checked, using tools which are themselves unexamined. While a typical old failure was an outage, a new one is a system working exactly as built, just not as specified, doing damage nobody expected.

01 · 'THE GAP'

It's the post-mortem. Someone senior wants to know why.

"Who defined what the behaviour should have been here?"

Nobody.

That is the hardest problem in software. And it is getting harder.

02 · API SECURITY

The API layers of digital applications are often a huge attack vector, but these load-bearing structures can be the least scrutinised area. Business logic flaws don't show up in automated vulnerability scans. An API must be deeply understood before we can creatively discover where the genuine vulnerabilities are.

03 · AI INPUT/OUTPUT

Who is taking responsibility for the quality of the outputs from your AI application? Inputs are not limited to chatbot interfaces and direct prompting. Are you defining what good looks like and how much variance is acceptable in your system's outputs? Are you checking this at scale?

Our answer

We verify strictly against what the system was designed to do, not only what it's doing now. The gap between those two is where the damage often lives.

What we do

01 · WEB / API SECURITY

Business logic and API security. OWASP Web and API Top 10s, authentication, authorisation, and the flaws built for a different kind of check.

Web / API Security →
02 · LLM SECURITY AND EVALS

Empirical failure rates for AI systems before deployment, mapped against the OWASP Top 10 for LLM Applications. Quantified, characterised, against your criteria. Not the vendor's benchmark. Yours.

LLM Security and Evals →
03 · SPECIFICATION AS METHOD

Twenty-five years of asking the same question, before it was APIs or AI. The discipline behind everything above.

Read the philosophy →

Who

Testclub was founded in 2012 by Omar El Dali, built on twenty-five years at the boundary between specification and implementation, across trading platforms, fintech, insurance, health, energy and government.

A skilled high-agency group who move fast and adapt to what your project actually needs. Every finding arrives with its evidence and the method that produced it, so an engineer can follow every step.

Meet the team →

Clients

View case studies →

Schroders
Nando's
EDF Energy
Nephila Capital
esure
Sportingtech
1Minus1
Valtech
ASquared
Attercop
// Fuzz attack surface representation