Offensive security in airlines, GDS, check-in systems, IFE and airport operations.
Why now
Aviation is where 'safety' is a heavy word. Check-in systems down stop dozens of flights, IFE attacks expose passengers, mileage program fraud drains brand value. ANAC and IATA don't joke.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Amadeus, Sabre, Travelport, integration with airline PSS.
DCS, kiosk, mobile check-in, biometrics.
Entertainment system, satellite onboard connectivity.
Fraud, ATO, account takeover, redemption bypass.
Baggage, dispatch, boarding and CUTE/CUSS systems.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Engagements with airlines and airport operators.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. We validate operations network security (CUTE/CUSS), baggage and check-in with proper coordination with airport infrastructure.
Yes. ATO, redemption fraud, promotional abuse and partner integration.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.