Our story

The rule came first. The software came second.

If the engine cannot reproduce a finding with a real exploit, the finding does not exist. Everything else in this product is a consequence of that one constraint, including the parts that make it slower than a scanner.

Kursad Alsan, founder of Nexich
Kursad AlsanFounder·LinkedIn
A finding nobody reproduced is an opinion. An opinion is a fine thing to argue about and a poor thing to hand somebody who has a process running at the end of the cable. The rule the engine was built around
Where it pointed

The same report, handed to a plant.

On an office network an untested finding costs a quarter of wasted remediation. On a plant floor it costs more than that in both directions. Act on a wrong one and an engineer takes a line down for a weakness that was never there. Miss a real one and the thing at the end of the path is a controller running a process, not a mailbox.

And the usual answer makes it worse, because the tools that would test a plant properly are the ones nobody is allowed to point at it. So industrial networks get the safest possible assessment: a port list, an inventory, and a report that never touched anything. Nexich exists for the gap between those two, which is why it reads controllers rather than writing to them, refuses to send a byte into channels that must never receive one, and states what it declined to do next to what it proved.

The record

Checkable, not asserted.

A company built on "prove it" owes you the same standard, so where a claim can be verified by somebody else, the link is here.

Apple

Listed three times in Apple’s web server security acknowledgements: January 2025, July 2025 and March 2026.

Microsoft

Most Valuable Researcher, 2023. Ranked 8th on the MSRC Q4 2025 Office leaderboard.

Bugcrowd

245 valid submissions at 89.74% accuracy across 17 programs, 9 of them private (profile). The public hall of fame names Cisco, Dell, Bitdefender, Comcast Xfinity, FIS, Opera and Web.com.

HackerOne

Reporting since December 2019, with thanks recorded by AT&T, Elastic and Clario alongside private programs (profile).

Published CVE

CVE-2022-21713, an authorization bypass in Grafana that let an authenticated user reach another team’s data. Fixed in 7.5.15 and 8.3.5.

Recognition and background

Cyber Security champion, University of Nebraska, January 2025. Eight years in offensive security, all of it inside the compliance demands of defence, government, banking and healthcare. BSc Cyber Security Engineering. DEF CON and Black Hat community.

The public record is the floor, not the ceiling. Web and API vulnerabilities rewarded by Samsung Mobile were never assigned CVEs, so they appear in no acknowledgement list anywhere. Nine of the seventeen Bugcrowd programs are private and HackerOne records two more as confidential, which means the counts above exclude most of the work. Where something cannot be linked, this page says so rather than asserting it.

The decision

An unproven finding should never reach a report.

An untested finding still gets delivered, still gets invoiced, and still gets filed. The client spends the next quarter working through a list nobody verified, and ends it no less breachable than they started. That is the ordinary outcome of the industry, not an unusual one.

So the constraint is absolute rather than a setting: a tool obliged to prove its claims cannot take the shortcuts that make a scanner fast, and we would rather be slower and be believed. What cannot be reproduced is held back and marked, not padded into the report to make the page look busy.

The constraint nobody solved

The people who need proof most are the ones forbidden to obtain it.

That part came later, and it is why this became a company rather than an internal tool. Automated, AI-driven offensive testing works. But an AI is only as good as the data it is given, and here that data is your live topology, your credentials and every weakness found along the way.

A few platforms will run inside the perimeter. None of them thinks inside it: the model that plans the attack still runs in a vendor's cloud, and a defence network, a payment environment or a plant floor is not permitted to send it anything. Nexich runs the whole loop, the model included, inside the customer perimeter. That is the entire point of the product.

Where things stand

One engineer, and the honest version of what comes next.

The platform is 397 attack modules, a runtime exploit-authoring layer and an air-gapped AI path, built solo. Its depth is measurable today. The company is earlier than that, and the order was deliberate: engineering came first because in this category the product is the hard part, and credibility with security buyers cannot be manufactured with a landing page.

The gap is named rather than hidden. This is a builder’s company so far, which is why the first hires are an offensive-security engineer and the people who carry the work to market, and why distribution runs through partners rather than through one founder’s calendar.