Offensive security & compliance · Budapest

We find the gaps before attackers do.

We show you where your systems are weak, before an attacker finds out. Penetration testing, IT security audits and ISO 27001 readiness

// StandardsISO 27001 · SOC 2 · GDPR · NIS2 · OWASP
threat-monitor LIVE
$zelor feed --live # ransomware.live
ransomware victims worldwide in the last 7 days
Latest ransomware attacks
Real, publicly listed victims. This is what skipping security looks like.
Sound familiar?

Does any of this sound familiar?

  • You worry an attacker has already found a gap in your systems.
  • You're preparing for ISO 27001 but don't know where to start.
  • After an incident, you want to be sure it won't happen again.
  • Your clients are asking you to prove you take security seriously.

Then you're in the right place. This is exactly what we help with, in plain, human language. Book a consultation

The report

A report you'll actually use.

After every engagement you get a clear report and a trackable action plan, not a pile of PDFs.

Security reportConfidential
Critical 2High 4Medium 7Low 5
Contents
  1. 01Executive summary
  2. 02Scope & methodology
  3. 03Findings by severity
  4. 04Detailed findings & evidence
  5. 05Prioritised action plan
  6. 06Free re-test results
Every finding includes: description, risk (CVSS 4.0), evidence and a fix.
Threat clustering

Patterns in the noise, not just headlines.

6 clusters · from public sources

We group publicly disclosed ransomware activity into clusters: who targets whom, in which sector, and at what pace. Noise becomes signal.

01LockBit23incidents
Manufacturing · Logistics · Healthcare · EU · US · 3h ago
02ALPHV / BlackCat14incidents
Finance · Technology · US · UK · 9h ago
03Akira11incidents
Retail · Education · EU · 17h ago
04Play8incidents
Public sector · Construction · EU · LATAM · 1d ago
05Medusa6incidents
Healthcare · Legal · US · 2d ago
068Base5incidents
SaaS · Media · EU · US · 3d ago
fewermore incidents

An illustrative view based on public ransomware data. The analysis tailored to you happens during an engagement.

About

Security is the foundation of trust.

There's one person behind Zelor, someone who has worked as an ISO 27001 Lead Auditor and ethical hacker, and for whom security isn't just a job, it's a passion. You always talk directly with the person doing the work.

With a developer's background, we know how systems are really built, so our advice works in practice, not just on paper. And you get clear reports, in both Hungarian and English.

About the founder
Process

Three steps, zero surprises.

The whole path is transparent, from the first conversation to verifying the fixes.

01

Free consultation

We talk through what you need. No obligation, and we reply within 24 hours.

02

Assessment & testing

We find the gaps using real attacker techniques, under controlled, safe conditions.

03

Report & action plan

You get a clear, prioritised report, plus a free re-test after you've fixed things.

Coming soon · in development

Security without an expert, made simple

Our upcoming SaaS product helps solo service providers keep their security and compliance in order, and prove it to clients.

Self-assessment checklists
Policy templates
Client trust badge
Who it's for

Are we a good fit?

Let's be honest: we're not for everyone. Have a look before you reach out, it's better for both of us.

We're a great match if…

  • You're an SME, fintech or SaaS and security genuinely matters.
  • You're preparing for ISO 27001 or another certification.
  • You want a clear, prioritised report, not a 200-page PDF.
  • You value talking directly to the person doing the work.

Maybe not right now if…

  • You need the cheapest possible tick-box audit, just for the paperwork.
  • You want a big, well-known brand name, not a hands-on expert.
  • You need everything by tomorrow, with no scoping.
FAQ

Frequently asked questions

What does Zelor do?

Penetration testing, vulnerability assessment, IT security audit, ISO 27001 lead audit and security-awareness testing.

Who are the services for?

Hungarian and international SMEs, fintech and SaaS companies, and any organisation preparing for certification.

How long does a pentest take?

It depends on scope; a typical web app test takes 1–2 weeks. We give a fixed price after scoping.

Do you work under NDA?

Yes. Every engagement runs under NDA, with strict protection of your data.

Most attacks could have been prevented. That's why I do this: so your systems never end up in the next breach headline. Whatever I find, I explain it in plain language and show you exactly what to do.
ZThe founderFounder & Lead Security Engineer

Curious where the gaps are in your systems?

Book a free, no-obligation consultation. We reply within 24 hours.