See what an attacker would see, before they do. Ethical offensive security sold by deliverables, not by the hour.
Phylax is my cybersecurity practice: I look at what a company exposes (web, email, infrastructure), confirm the real risk and help close it. I work with established frameworks (PTES, OWASP, NIST) and deliver concrete things: a report with evidence, a signed attestation, a domain under watch. The deep work is always done with written authorization.
Free and non-intrusive: what an attacker sees first.
Confirmed findings, severity and evidence.
Issues get fixed, re-verified and closed with a signed attestation.
Monthly monitoring: I let you know the moment something changes.
The portfolio's "Is your domain spoofable?" checker: a real DMARC check right in the browser.
Assessments for small and mid-size businesses with real findings (spoofable email, exposed surfaces, headers).
A continuous monitoring product (SPF/DMARC/TLS/exposure) with a monthly report.
Process, non-disclosure agreement, rules of engagement and authorization letter, anchored to Law 21.459 (Chilean cybercrime law).
One real case under confidentiality, plus illustrative scenarios of how I work, marked as examples.
A pro-bono exposure assessment for a real client, with prioritized findings. The detail is handled confidentially.
Set up DMARC, SPF and DKIM to close the classic door to email fraud.
A passive exposure diagnostic, with a report you can act on by severity.
Monthly domain watch that flags the moment something changes.
Training and awareness to recognize social engineering.


Start with the free diagnostic. No strings attached.
Write to me →