Home / About
About TEQNIX
An offensive security consultancy based in Australia, working with clients internationally. Specialised in Penetration Testing and Continuous Offensive Security Testing.
Why the service is built this way
Most organisations buy a penetration test once a year because that is how the industry has always sold testing, and because an annual report satisfies an auditor. The report is accurate. It is also a description of a fortnight that has already passed, and it starts ageing immediately.
We built a continuous service because the gap between tests is where exposure accumulates, and because agentic AI makes it affordable to test repeatedly rather than occasionally. Continuous testing delivered entirely by hand would cost several times as much, which is why it has not been available to the mid-market until now.
What has not changed is who does the work. Consultants run the testing and are accountable for it; automation covers ground so that coverage can be continuous rather than occasional. The difference between confirmed findings and raw automated output is the difference that matters.
Who does the work
Our team is based in Australia and brings more than 15 years of hands-on offensive security experience across financial services, technology, energy, retail, healthcare, education and insurance.
The team holds internationally recognised offensive security certifications, including OSCP and OSCE. Testing is directed by consultants with that background, engaged across the year rather than for a single scheduled week.
On frameworks and standards
Where you see OWASP ASVS, the OWASP API and LLM Top 10, MITRE ATT&CK, PTES or CIS Benchmarks mentioned on this site, they are methodologies we test against and map findings to.
How we work
- Every finding is manually validated before it reaches you. Either a consultant reproduced it, or they confirmed the evidence and said so in the finding.
- Scope boundaries are set out up front. What the service covers, and where it stops, is described before you sign rather than discovered afterwards.
- Findings are written for the people who have to fix them. A CVSS score alone does not tell a developer what to change on Monday.
- Authorisation is verified. We check domain ownership ourselves and confirm the asset register before testing begins.
- Data handling is documented. Including which AI provider processes engagement data and where that processing happens. See the privacy policy.