One partner for the three things modern businesses can't afford to get wrong: managed IT & cybersecurity, AI integration & management, and offensive security testing. We pen-test the systems most teams ship untested, run your IT and defense day to day, and build, integrate, and manage AI the right way — because we build and self-host our own in-house. Verified work, proven on our own hardware, reported in plain English.
Selected engagements — one published with the client's permission, the rest under NDA — plus independent recognition. Capability shown on results.
Cross-tenant authorization (IDOR/BOLA) tested in both directions and across both token transports; a full SSRF bypass ladder; stored XSS; database row-level security; OAuth. Manual, positive-control verified, end to end.
Result: no exploitable vulnerabilities identified — two non-exploitable hardening notes reported.Real engagements against production systems across the full offensive spectrum. Client identities and data are withheld under NDA; the technical approach is shown.
Use-after-free and heap primitives developed into remote code execution against compiled services.
SSRF-to-internal-service chains, Host-header vhost routing, package-registry abuse to code execution.
Static and dynamic analysis of compiled binaries to recover logic, keys, and hidden validation.
Attacks on flawed constructions — hash-collision abuse and broken cipher schemes.
Packet-capture analysis, file carving, and layered-archive and protocol reconstruction.
Logic-analyzer signal decode and industrial-protocol analysis against embedded and OT targets.
Independent research on a live multi-tenant marketplace (public program): recon, API-surface mapping, SSRF testing; a valid vulnerability responsibly disclosed.
Beyond client work, offensive skill is validated publicly on Hack The Box. On the "CTF Try Out": 36 of 37 scenarios solved · global rank #93 · 34,100 points. On the MCP Try Out: a 31-solve sweep across all eleven categories for 25,000 points · global rank #39 of 300 teams — binary exploitation, web, reverse engineering, cryptography, forensics, hardware, ICS, blockchain, coding and more. Full profiles & badges available on request.
Three practices, one partner: offensive security, managed IT & cybersecurity, and AI integration & management — for startups and SMBs that want it handled, not juggled.
Full-scope assessment aligned to the OWASP Top 10: access control, authentication and session, injection, SSRF, business-logic flaws, and misconfiguration.
REST and GraphQL testing against the OWASP API Security Top 10: object- and function-level authorization, cross-tenant access, mass assignment, rate-limit gaps.
A new trust boundary most teams ship untested: MCP servers, agent tool-use, and LLM-connected apps — tenant isolation, prompt and tool-call abuse, output handling.
Your outsourced IT department: endpoint management and patching, backups and recovery, email and identity, network and helpdesk — kept current, monitored, and supported so your team can work.
Ongoing defense, not a one-off scan: EDR, log and alert monitoring, vulnerability management, patch governance, and incident response when something does get through.
We take you to audit-ready and keep you there — gap assessment, control implementation, policy, and the evidence trail — mapped to SOC 2, PCI DSS, HIPAA, NIST and CIS. We prepare you for the auditor; the certification itself is issued by them. Backed by our own NIST-control tooling.
Put AI to work inside your business: LLM assistants, RAG over your own documents, agentic automation, and tooling wired into the apps and workflows you already use — scoped, secured, and actually useful.
We build and run our own AI stack — self-hosted models, GraphRAG memory, GPU compute, agent harnesses — on in-house hardware with in-house code. We stand the same up for you: private, on-prem, no data leaving your walls, no per-seat SaaS bill.
Run it for you long-term: model updates and evals, guardrails and prompt-injection defense, token-efficiency and cost control, monitoring and uptime. Your AI, maintained — without an ML team on payroll.
A defined piece of work — a pen test, an AI integration, an IT or security buildout — with clear deliverables, a prioritized report, and a debrief.
Ongoing managed IT, security monitoring, and AI operations for a flat monthly fee. We keep it running, patched, defended, and improving.
Re-test after fixes, recurring assessments as you ship, and on-call expertise for the security and AI decisions in between.
Disciplined, authorized, and documented end to end. No test packet leaves without written scope.
Exact targets, windows, and constraints defined in a signed SOW.
Rules of Engagement signed before any testing begins — your legal shield and mine.
Manual assessment across the agreed surface. Critical findings reported out-of-band within hours.
Every finding reproduced with a positive control. No scanner-only claims.
Prioritized report, debrief call, and a re-test after you fix. Attestation on request.
Application security is the day job. The record proves depth across the whole offensive stack — the instinct that finds the bug a checklist misses.
Thirty-one real-world systems taken end to end across all eleven disciplines — production-grade environments with the same stacks, defenses, and bugs as live targets. Each driven from first access to full compromise — not a scaled-down exercise.
We don't just advise — we ship and operate our own production software. Proof that the security and AI work we bring to clients is built on real engineering, not slides.
A dynamic-QR SaaS: codes stay editable after they're printed — destination, WiFi password, label, expiration, password-gate — with no reprint. Correct WPA3 WiFi encoding (most generators silently downgrade and fail to connect), real scan analytics, custom styling, bulk CSV, a public API, and its own MCP server. Four-tier Stripe billing, live.
We pentested our own app and fixed it: stored XSS in the WiFi/vCard render, a TOCTOU free-tier race (closed with a Postgres advisory lock), endpoint DoS (rate-limited at the edge), and a WPA3 encoding bug competitors ship broken.
Security monitoring for MCP servers and agentic AI — the trust boundary most teams ship untested. Continuous checks for tool-call abuse, cross-tenant isolation, prompt and indirect injection, and unsafe LLM output handling across AI-connected apps.
Built on the same in-house AI-security tooling and self-hosted models we run in Live Operations below. Launching to early clients soon.
This is the depth of AI knowledge we bring to clients. What moves behind this page is our own GraphRAG "AI brain", engineered in-house from scratch — self-hosted memory, a custom tooling harness, and reasoning sessions fused into one living graph, hand-written on our own hardware with no SaaS behind it. We understand these systems because we build them end to end — and we put that expertise to work securing, auditing, and standing up AI for you. Shown as pure topology; contents, names, and client data never leave our machines.
We know these models from the inside — and bring that to clients. The real embedding space behind our knowledge base and the encode→rerank pipeline that searches it: self-hosted open models on in-house GPUs, wired with our own code. The same understanding we apply to securing and building AI for you. Projected live from our own vectors; shape only, no contents.
Evidence of how deeply we know the stack — knowledge we bring to your systems. Real telemetry from infrastructure we engineered ourselves: a custom token-efficiency layer, local GPU compute, and our own knowledge graph. Measured on our hardware, built almost entirely on free and open tooling. No client or content data.
Topology only — contents, identifiers, and client data withheld. Rebuilt from the live graph on every save.
Merriweather Holdings is a managed IT, cybersecurity, and AI partner for startups and SMBs. We run and defend your IT day to day, pen-test the systems most teams ship without testing — web apps, APIs, and AI/MCP trust boundaries — and integrate, host, and manage AI the right way. We build and self-host our own AI infrastructure in-house, which is exactly why we understand how to secure and operate it for you. Every engagement is authorized and documented; every finding proven before it's reported. Hands-on expertise that earns its place on the result.
Tell us what you've built and what you're worried about. You'll get a scoped, fixed-price proposal — no obligation, no jargon.