Skip to content
devwallssecurity
A dark machine hall, lit doors receding down a corridor of racks
offensive security practiceabuja / london · est. 2026

we break in,write it down,and stay till it's fixed

Penetration testing, red teaming and security advisory for organisations that would rather find out from us. Every fix we recommend gets retested, at no extra cost, within ninety days.

what we are

Most reports tell you what a scanner noticed. Ours tell you what a person did, in your system, and what happened next.

devwalls is thirty-one people across Abuja and London. We run penetration tests, red team operations, cloud reviews and embedded application security work. We publish our research under our own names, we grade findings on whether they are exploitable rather than on whether a tool flagged them, and we retest every fix we recommend without charging for it again.

A single desk lit late in an otherwise dark office

Thirty-one people. Two offices. Every report signed by the person who wrote it.

servicesfour ways we work with you
how an engagement runs
  1. 01

    Scope

    1 week before start

    We argue about scope until it is narrow and written down. A vague scope produces a vague report. This is a call with the people who own the systems, not a form.

  2. 02

    Recon

    Days 1–3

    We build a picture of your attack surface from the outside, the way someone targeting you would. Frequently we find assets you had forgotten you owned. That list alone has ended engagements early.

  3. 03

    Test

    The bulk of the engagement

    Humans in your system, chaining findings rather than listing them. Anything critical is called the same day. You have a shared channel with the testers throughout.

  4. 04

    Report

    Within 5 days of test end

    One document, two audiences. Engineers get reproduction steps and remediation notes. The board gets a page in plain English. Neither is a template with your logo dropped in.

  5. 05

    Fix

    Your timeline

    We stay available while you fix. Most clients use us as a second pair of eyes on the patch. This is included, not billed.

  6. 06

    Retest

    Within 90 days

    We test every fix and update the report. A finding is only closed when we have failed to exploit it again. Included in the original price.

recordsince 2026
480+
Engagements delivered
37
CVEs published
100%
Fixes retested, free
engagementspublished with client consent
All engagements
researchcoordinated disclosure, 90 days
All advisories
A dense city skyline at night, lit windows in red and amber

tell us what you would least like us to reach

Scoping is a conversation with the people who own the systems, not a form. Twenty minutes is usually enough to tell whether we are the right practice for the problem.