Offensive security in construction firms, developers, BIM, jobsite IoT and buyer portals.
Why now
Construction digitalized fast (BIM, jobsite IoT, buyer portal) without security maturity. Blueprint leaks, measurement manipulation, real-estate cancellation fraud and ransomware in offices halt construction.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Model repository, version control, project leakage.
Contract access, construction status, virtual inspection.
Measurement reports, approval flow, contractor payment.
Site sensors, access control, worker time clock.
Sienge, Totvs Obras, financial integration.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
CREA client — engagement with the regulated sector.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. We audit measurement reports, engineer approval, contractor payment and fraud between stages.
Yes. Repository, versioning, IFC/RVT leakage and model protection.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.