main logo icon
Two members of a security team reviewing findings on screen in an office

About Stingrai

Real security, not a scanner. Stingrai is a CREST-accredited global offensive security company. We are not just penetration testers, but also battle-tested bug bounty hunters and security researchers, with numerous zero-days and vulnerabilities responsibly reported to top Fortune 500 companies.

Our Mission & Values

To transform offensive security by uniting AI capabilities with expert human pentesters, so vulnerabilities are found, validated, and fixed at the speed attackers move.

Book a Discovery Call
  • Validated Findings

    Every vulnerability is manually checked with a working proof of concept and prioritized remediation guidance, not scanner noise.

  • Human-Led, AI-Accelerated

    Automation expands coverage while humans manually validate, chain, and catch advanced security vulnerabilities missed by scanners.

  • World-Class Expertise

    Experienced certified pentesters only, holding OSCE³, OSWE, and CREST CRT.No hand-offs to juniors.

Leadership & Advisory

Arafat Afzalzada photo

Arafat Afzalzada

Founder

11 years of experience in offensive security, leading penetration testing engagements for start-ups, mid-market, and enterprises across healthcare, financial services, government, and other regulated sectors.

Certifications
CISSPPCNSECCNAITIL
Accomplishments
Speaker at MAX Cybersecurity (Art of Attack and Defense) and ISACA Toronto Chapter.
Eldon Sprickerhoff photo

Eldon Sprickerhoff

Advisory Board

Founder of eSentire, a pioneering Managed Detection and Response (MDR) company that grew from a bootstrapped startup into a billion-dollar cybersecurity leader protecting 2,000+ organizations across 80+ countries.

Recognition
J.W. Graham Medal in Computing & Innovation (University of Waterloo). Waterloo Region Entrepreneur Hall of Fame inductee. Author of Committed: Startup Survival Tips and Uncommon Sense for First-Time Tech Founders.

Penetration Testing Team

Ivan Spiridonov photo

Ivan Spiridonov

Team Lead Penetration Tester

16 years of experience in penetration testing, red teaming, and exploit development.

Certifications
OSCE³OSEDOSWEOSCPCRTLOSEPCRTECRTO
Accomplishments
10 published CVEs across commercial and open-source software, including CVE-2025-50674 and CVE-2024-32136.
Alex Moraga photo

Alex Moraga

Senior Penetration Tester

15 years of experience in application vulnerability research, penetration testing, and red teaming across web, mobile, and LLM environments.

Certifications
OSCP
Accomplishments
Founding member of the Offensive Security team at Uber. Published security researcher with contributions to Hack inSight Magazine.
Armaan Pathan photo

Armaan Pathan

Senior Penetration Tester

11 years of experience in penetration testing, red teaming, and exploit development.

Certifications
OSCPCMSE
Accomplishments
Bug Bounty Hall of Fame (400+ reported): Apple, Facebook, Google, Yahoo, US Department of Defense. Speaker at BSides Ahmedabad and null Dubai.
Utku Yildirim photo

Utku Yildirim

Senior Penetration Tester

7 years of experience in penetration testing, red team operations, and offensive security research.

Certifications
OSCEOSWEOSWPCRTO
Accomplishments
Speaker at DEF CON and BSides Oslo on UAV/GPS spoofing, 5G jamming, and SS7 exploitation. Research featured at NATO Locked Shields.
Omar Hamdi photo

Omar Hamdi

Senior Penetration Tester

7 years of experience in penetration testing, red teaming, and bug bounty research.

Certifications
OSCPeWPTXCrest CRTCRTEOSWP
Accomplishments
Bug Bounty Hall of Fame: US Federal Reserve, PaySafe, Zynga, and other enterprise programs.
Victor Villar photo

Victor Villar

Senior Penetration Tester

6 years of experience in penetration testing, red teaming, and exploit development.

Certifications
OSCE³OSEPOSEDOSWEOSCP
Accomplishments
3 published CVEs in commercial software: CVE-2024-32369, CVE-2024-32370, and CVE-2024-32371.
Akash Khara photo

Akash Khara

Penetration Tester

3+ years of experience in offensive security research, malware analysis, and operating system internals.

Certifications
CRTECRTPeCPPTCEH Practical
Accomplishments
Founder of crow, a cybersecurity YouTube channel and technical community with more than 94,000 subscribers and 1.5 million views. Maintainer of maldev, an open-source offensive security library with 700+ GitHub stars.
CREST member company: certified penetration testing
Top Clutch Cybersecurity Company United Kingdom 2026Top Clutch Cybersecurity Company Canada 2026Top Clutch Compliance Testing Company Canada 2026
ellipse

What Sets Us Apart

World-class pentesting delivered through our modern AI-powered PTaaS platform, competitively priced.

Experienced Team

Experienced Team

With 15+ years of team experience and OSCE³, CRTE, eWPTX and CREST CRT certified penetration testers, we deliver expert-driven security testing.

Competitive Pricing

Competitive Pricing

Fixed, published pricing for one web application and its APIs: Snipe, our autonomous pentest agent, on its own or paired with senior penetration testers, with retests included. For larger scopes, submit the Get a Quote form and receive pricing within 24 hours.

Innovative Portal

Innovative Portal

Every reported vulnerability is verified by our penetration testers, who work alongside Snipe throughout the engagement. Delivered through our AI-powered PTaaS platform.

Trusted by Security Teams Globally

quote icon

Stingrai uncovered vulnerabilities our vulnerability program had missed and helped us harden critical systems with practical guidance. We were impressed with their personalized, transparent approach and delivery against our timelines.

— Manager, IT, 30 Forensic Engineering

quote icon

The team spent time and effort to understand the business cases and uncover vulnerabilities unique to our business. Testing was completed within the promised timeline and within the budget which is very competitive compared to the market.

— CTO, NetNow Financial Inc.

Sample Pentest Report

Explore how we structure executive summaries, prioritized findings, evidence, reproduction steps, and remediation guidance, tailored to SOC 2, ISO 27001, PCI DSS, and HIPAA compliance.

We’ll send a secure download link to your work inbox.