Hire me NL

Proof of who really has access.Your last audit proved the controls exist.
It never proved who used them.

Independent audits of identity, access and your suppliers, with evidence that holds up with auditors and boards.

Almost two decades inside the machine: SOC floors, audit rooms, ransomware recoveries, smart contracts, AI red teams. Block The Chain thinks in attack paths and failure states, then hands you the evidence a regulator accepts and an adversary cannot argue with. One operator. Zero theoretical findings.

Free · runs in your browser · nothing stored4 exposure signals
>_
Headers
SPF
DMARC
DNSSEC
Sources: MDN HTTP Observatory · Cloudflare DNS over HTTPS. Only check domains you are authorised to assess. More free tools in Labs →
Scroll to verify
01 Services · by depth

Three layers. One operator.

Most audits stop at the surface: policies, scans, checkbox evidence. The failures that matter live deeper, in identities nobody owns and vendors nobody mapped.

01 Surface · controls & compliance

SURFACE LAYER

Where auditors look and attackers start. Block The Chain tests whether the controls you documented actually operate, and writes the evidence file the regulator expects to see.

Security Auditing & Compliance

RDI · ISO 27001 · NIST CSF
Control designOperating effectivenessNIS2 evidence file

End-to-end IT security audits for regulated sectors against RDI, ISO 27001, NIST CSF 2.0 and CIS Controls. Evidence, not opinions.

Vulnerability Management

Tenable · Qualys · OpenVAS
CVSS analysisRisk-based prioritisationTrend reporting

From scanner noise to a ranked remediation program with owners, deadlines and a trend line your board can read.

02 Deep · identity, detection & response

DEEP LAYER

The part scanners never see: who holds which access, which tokens never expire, which vendor still has a working key, and whether anyone would notice.

SIEM, Detection & Threat Hunting

Sentinel · Splunk · Sumo Logic
Detection engineeringATT&CK mappingHypothesis hunts

Detections mapped to the tradecraft that matters for your sector. Logs do not lie, but only if someone is reading them.

Identity, Cloud & Access Audit

Entra · Intune · Zero Trust
Orphaned accountsPrivileged accessLegacy IBM i

Every service account, shared secret and vendor path listed with an owner. Before-and-after numbers, not a policy PDF.

Incident Response & Recovery Validation

Forensics · backup restore
ContainmentTimeline reconstructionRansomware recovery test

Triage to root cause, then proof that your recovery actually works, tested rather than assumed.

Evidence for Disputes and Whistleblowers

Chain of custody · timelines · expert statement
Litigation-grade dossierLog & capture forensicsRegulator packagingNext to your counsel

When the other side is bigger and owns the systems, the records still tell the truth. The operator acquires them with chain of custody, rebuilds the timeline, names every missing log as a finding, and hands your lawyer a file built to be filed. Size is not an argument. Evidence is.

03 Dark · offensive & research

DARK LAYER

Your systems tested the way the adversary would work them. Scoped, authorised, evidence-grade.

Offensive Assessment & Chain-of-Custody Review

Web · API · Cloud · Supply chain
Logic flawsIdentity abuseVendor access pathsHAR & network forensics

Attack paths, not tool output: access-control weaknesses, identity abuse, misconfigurations from commit to production and from vendor to crown jewels. Every finding reproduced, and the session evidence kept as a legal-grade artefact.

AI Red Team & Agentic Attack Chains

LLM · agents · AI platforms
Prompt injectionAgentic attack chainsModel & data exfiltrationAI governance

Red-teaming LLM workflows and autonomous agents, then building the guardrails: rate limits, audit logging, input validation, human-in-the-loop. Tested on production AI platforms built from the ground up.

Blockchain & DeFi Security

Slither · Mythril · fuzzing
Reentrancy · CEIOracle manipulationFlash-loan abuseFront-running

Smart-contract review from static analysis to symbolic execution, plus DeFi threat models for oracles, staking and governance logic. Risks documented before deployment, not after the drain.

01 What gets checked

Three things. Checked with evidence.

Controls

Your controls

Do the controls your last audit listed actually work? Checked, with evidence.

Access

Your people and access

Who can get in, who did, and whether your logs would show it.

Exposure

Your exposure

What an attacker would try on your apps, cloud or AI tools, with your written permission.

02 Selected work · anonymised

Names withheld. Discretion is part of the work.

Nine operations, codenames only. Each tile opens the problem and the result. Sectors named, clients never.

Operations archive · 09 files shownSample evidence file (PDF) →
03 How an engagement runs

Five steps. No surprises.

Fixed scope, fixed price, one operator from the first call to the retest. You review the plan before you commit to anything.

01
Day 0 · 30 min

Scoping call

Your context, the systems in play, what keeps you up at night. No slide deck, no sales script.

02
Within 2 business days

Fixed-price proposal

Scope, method, deliverables, price and date on one page. You decide with the plan in hand.

03
Fieldwork

Evidence gathering

Walkthroughs, configuration reviews, log sampling, testing. Every claim backed by an artefact you can reproduce.

04
Read-out

Findings that carry weight

Ranked findings with owners and one action each, written for the engineer and the board in the same document.

05
Included

Retest and attestation

Fixes verified, the file closed with a signed statement of what was tested and what held.

Reply within 1 business dayYour NDA or mine, signed before scopingEvidence stored EU-side, deleted after hand-overNo subcontracting
02 How it works

Three steps. A fixed price.

Step 01

A 30-minute call

You say what worries you. Nothing to prepare.

Step 02

A fixed price

In writing within two business days. No hourly surprises.

Step 03

The work and a retest

A report ranked by real risk, with the evidence behind it, and a retest once it is fixed.

04 Operating rules

Four rules. No exceptions.

01

No scanner ever stopped a breach.

Tools produce alerts. The operator produces decisions: a finding, its evidence, its owner and the one action attached to it.

02

Logs don't lie. Missing logs confess.

Timelines are rebuilt from the records that exist. The report states plainly which records do not, and what that means. In a dispute, that sentence is the case.

03

The chain ends at the operator.

The person on the call does the work, signs the report and answers for it. No juniors, no subcontractors, no slide decks.

04

Zero theoretical findings.

Every item is reproduced before it is written down. What the system permits is documented; what was not proven is not claimed.

OP About the operator

One operator. Nothing outsourced.

Who does the work, on what terms, and why the findings hold up. No name on the site by design; everything else is on the table.

Independence

No reseller deals, no commissions

No vendor partnerships, no product commissions, no resale margin. Tools are chosen per engagement and named where they matter. The only revenue is the work itself.

One operator

The person on the call does the work

Scoping, testing, evidence, report and read-out by the same person, who signs it and answers for it. No subcontracting, no juniors, limited slots stated up front.

Sectors

Regulated and supervised environments

Telecom, government, finance, healthcare and manufacturing. Legacy and cloud side by side, identity estates nobody owns, AI agents and smart contracts before launch.

Frameworks

Evidence mapped to the standard you answer to

ISO 27001, NIST CSF 2.0, CIS v8, MITRE ATT&CK, RDI and BIO as agreed; OWASP LLM Top 10 for AI work. Findings arrive mapped, so nobody has to translate them afterwards.

Paperwork-ready

Procurement gets a complete pack

Identity documents, data-processing agreement and chain-of-custody statement are part of the standard supplier pack. NDA before any system is named.

Languages and base

Dutch and English, based in the Netherlands

Reports, read-outs and evidence in either language. KvK 84616458. Working across the EU; evidence stays on EU-hosted, encrypted storage and is deleted after hand-over.

03 Why independent

One operator. Nothing outsourced.

Independent

No products to sell

No partner deals, no commissions. Findings are the only thing delivered.

One person

Start to finish

The person on the call does the work. Nothing is subcontracted.

Discreet

Your NDA or ours

Names are never published. Evidence stays in the EU.

TX Transmissions

Hardcore music and hard security as one signal. The first transmission is in production; the channels open with it.

0405 Hire the operator

One email starts it.Tell me what to verify. You get a fixed price.

Say what you need checked. A reply within one business day.

Thirty minutes to scope it. A fixed-price proposal within two business days.

Scoping request

One e-mail starts it. Reply within one business day.

  • Your organisation and your role
  • What you want verified, in a few lines
  • The framework you answer to, if any
  • Two or three moments that suit you for a 30-minute call
Book a 30-minute callEmail a scoping request admin@blockthechain.nl