main logo icon

About Stingrai

Real Security, Not a Scanner

Recognized. Proven. Trusted.

Founded in 2021, Stingrai is one of the leading global CREST-approved offensive security companies, backed by a team with an average of over 15 years of hands-on industry experience securing a wide range of organizations, from startups and mid-market companies to large enterprises.

  • Security Research: Active speakers at DEF CON, BSides, and NATO Locked Shields.
  • Top-Tier Credentials: OSCP, OSCE³, OSWE, OSEP, and CREST CRT certified.
  • AI-Powered PTaaS: Real-time reporting, native integrations, and instant retests.

Our Mission & Values

To transform offensive security by uniting AI capabilities with expert human pentesters, so vulnerabilities are found, validated, and fixed at the speed attackers move.

  • World-class Pentesters: Active security researchers with dozens of published CVEs and zero-day disclosures across major commercial and open-source platforms.
  • Snipe, Continuous Pentesting Agent: Instead of point-in-time checks, you are protected by our AI-powered pentesting agent with human pentesters in the loop throughout the year.

Validated Findings

Every vulnerability is manually checked with a working proof of concept and prioritized remediation guidance, not scanner noise.

Human-Led, AI-Accelerated

Automation expands coverage while humans manually validate, chain, and catch advanced security vulnerabilities missed by scanners.

World-Class Expertise

Experienced certified pentesters only, holding OSCE³, OSWE, and CREST CRT. No hand-offs to juniors.

Leadership & Advisory

Arafat Afzalzada photo

Arafat Afzalzada

Founder

11 years of experience in offensive security, leading penetration testing engagements for start-ups, mid-market, and enterprises across healthcare, financial services, government, and other regulated sectors.

Certifications
CISSPPCNSECCNAITIL
Accomplishments
Speaker at MAX Cybersecurity (Art of Attack and Defense) and ISACA Toronto Chapter.
Eldon Sprickerhoff photo

Eldon Sprickerhoff

Advisory Board

Founder of eSentire, a pioneering Managed Detection and Response (MDR) company that grew from a bootstrapped startup into a billion-dollar cybersecurity leader protecting 2,000+ organizations across 80+ countries.

Recognition
J.W. Graham Medal in Computing & Innovation (University of Waterloo). Waterloo Region Entrepreneur Hall of Fame inductee. Author of Committed: Startup Survival Tips and Uncommon Sense for First-Time Tech Founders.

Penetration Testing Team

Ivan Spiridonov photo

Ivan Spiridonov

Team Lead Penetration Tester

16 years of experience in penetration testing, red teaming, and exploit development.

Certifications
OSCE³OSEDOSWEOSCPCRTLOSEPCRTECRTO
Accomplishments
10 published CVEs across commercial and open-source software, including CVE-2025-50674 and CVE-2024-32136.
Alex Moraga photo

Alex Moraga

Senior Penetration Tester

15 years of experience in application vulnerability research, penetration testing, and red teaming across web, mobile, and LLM environments.

Certifications
OSCP
Accomplishments
Founding member of the Offensive Security team at Uber. Published security researcher with contributions to Hack inSight Magazine.
Armaan Pathan photo

Armaan Pathan

Senior Penetration Tester

11 years of experience in penetration testing, red teaming, and exploit development.

Certifications
OSCPCMSE
Accomplishments
Bug Bounty Hall of Fame (400+ reported): Apple, Facebook, Google, Yahoo, US Department of Defense. Speaker at BSides Ahmedabad and null Dubai.
Utku Yildirim photo

Utku Yildirim

Senior Penetration Tester

7 years of experience in penetration testing, red team operations, and offensive security research.

Certifications
OSCEOSWEOSWPCRTO
Accomplishments
Speaker at DEF CON and BSides Oslo on UAV/GPS spoofing, 5G jamming, and SS7 exploitation. Research featured at NATO Locked Shields.
Omar Hamdi photo

Omar Hamdi

Senior Penetration Tester

7 years of experience in penetration testing, red teaming, and bug bounty research.

Certifications
OSCPeWPTXCrest CRTCRTEOSWP
Accomplishments
Bug Bounty Hall of Fame: US Federal Reserve, PaySafe, Zynga, and other enterprise programs.
Victor Villar photo

Victor Villar

Senior Penetration Tester

6 years of experience in penetration testing, red teaming, and exploit development.

Certifications
OSCE³OSEPOSEDOSWEOSCP
Accomplishments
3 published CVEs in commercial software: CVE-2024-32369, CVE-2024-32370, and CVE-2024-32371.

What Our Clients Say

quote icon

Stingrai uncovered vulnerabilities our vulnerability program had missed and helped us harden critical systems with practical guidance. We were impressed with their personalized, transparent approach and delivery against our timelines.

— Manager, IT, 30 Forensic Engineering

quote icon

The team spent time and effort to understand the business cases and uncover vulnerabilities unique to our business. Testing was completed within the promised timeline and within the budget which is very competitive compared to the market.

— CTO, NetNow Financial Inc.

Sample Pentest Report

Explore how we structure executive summaries, prioritized findings, evidence, reproduction steps, and remediation guidance, tailored to SOC 2, ISO 27001, PCI DSS, and HIPAA compliance.

We’ll send a secure download link to your work inbox.