Security validation for access control, cameras, remote concierge, resident app and outsourced administration.
Why now
Buildings are a treasure of personal data — address, license plate, photo, biometrics, routine — and operations are outsourced to cheap, misconfigured systems that are never tested. Hacked cameras, gates bypassed by tag replay, remote concierge with password 1234. When it leaks, the building manager is on the hook.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Authorization bypass, call replay, third-party gate control, release fraud.
RFID cloning, NFC replay, fingerprint fraud and contractor credential abuse.
Exposed DVR/NVR, default credentials, improper retention, unnecessary WAN exposure.
IDOR on packages, common area reservations, communication with administrator, visitor data.
Individualized water, gas, electricity — reading manipulation, fraud in cost apportionment.
Shared Wi-Fi, segregation between admin and residents, outsourced IT firm access.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Highly fragmented market with rapid tech adoption; total lack of independent validation.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Both. Managers often request after an incident; professional administrators are starting to offer pentest as a competitive differentiator.
No. We work in agreed windows. RF tests (tag cloning) use client-provided tags returned at the end.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.