Skip to content
Available Now 100% Remote Worldwide Est. Innlandet, Norway

Cyber security,
on-demand!

Stux Security packages serious offensive and defensive security work into a catalogue you can actually shop from. Real engineers, real reports, zero jargon you didn't ask for.

12+services on the shelf
2person crew, zero fluff
time zones served
Security Services

Pick your Problem.

Every service below is a real, scoped engagement — priced and ordered through Ko-fi, kicked off with an actual conversation first.

5b2ea4bbf7 Bestseller

Penetration Testing

A hands-on, human-led pentest of your network, apps, or infrastructure — real exploitation attempts, not just a scanner printout.

★★★★★
STX-102 Popular

App Security Testing

OWASP-aligned testing of web apps, APIs, and mobile clients to catch broken auth, injection, and logic flaws before your users do.

★★★★☆
STX-103

Vulnerability Assessment

Wide-coverage scanning and manual triage across your external and internal footprint, prioritized by real-world exploitability.

★★★☆☆
STX-104 Advanced

Red Team Engagement

Goal-based, multi-stage simulated attacks that test people, process, and technology together — the way a real adversary would.

★★★★★
STX-105 24/7

Incident Response

On-call responders for active breaches: containment, forensics, and a clear recovery plan when things are already on fire.

★★★★★
STX-106

Cloud Security Audit

Configuration review across AWS, Azure, and GCP — IAM, storage, network exposure, and drift from your own hardening baseline.

★★★☆☆
STX-107

Security Awareness Training

Short, plain-language training for teams who aren't security people — built around the mistakes that actually cause breaches.

★★☆☆☆
STX-108

Phishing Simulation

Custom phishing and pretexting campaigns with click-through analytics and follow-up coaching, not a public shame list.

★★☆☆☆
STX-109

OSINT & Attack Surface Recon

A map of what the internet already knows about your organization — leaked credentials, shadow IT, exposed assets, and more.

★★★☆☆
STX-110

Malware Analysis & Reverse Engineering

Static and dynamic analysis of suspicious binaries to answer the only question that matters: what does this thing actually do?

★★★★☆
STX-111

Compliance Readiness — ISO 27001, GDPR, NIS2

Gap analysis and remediation roadmap to get audit-ready, mapped in plain language instead of standards-committee jargon.

★★☆☆☆
STX-112 Subscription

Managed Detection & Response

Ongoing monitoring and triage of alerts across your environment, with a human checking the things automation gets wrong.

★★★★☆
Assembly Instructions

How an order actually ships.

No shrink-wrap magic — just a short, real process from checkout to fixed vulnerabilities.

Order or inquire

Grab a package on Ko-fi or send us scope details through the contact form.

Kickoff call or chat

A brief discussion to confirm scope, rules of engagement, and timing — no surprises later.

Testing window

Junk and the team do the actual work: testing, monitoring, or analysis, on schedule.

Plain-language report

Findings ranked by real risk, written so both engineers and executives understand it.

Fix-it support

A follow-up window to verify fixes and answer questions your team has along the way.

Stux Action Figures

Meet the crew on your remote end.

Small on purpose — everything you order is handled and verified by two confident nerds.

Junk
Problem Solver & Cyber Consultant
"Junk"

Runs the offensive and defensive engagements end to end — scoping, testing, and the reports that come out the other side. If it involves breaking (or defending) something on purpose, Junk signs off on it.

Penetration Testing Incident Response Red Teaming
Null
Design Architect & Marketing Wizard
"Null"

Designs how Stux looks, reads, and feels — from this very website to the reports clients actually open. Believes a serious finding still deserves a page that's pleasant to read.

Product Design Report Design Brand
Trustworthy and Confidential

What you can expect from Stux

Remote, worldwide

Every service ships remotely — time zone is never a blocker.

Scoped in writing

Rules of engagement and scope are agreed before anything starts.

Confidential by default

NDAs available on request; findings are shared only with you.

Norway-based

Operated out of Innlandet, Norway, working with clients globally.

Got questions we may already have answered?

Frequently asked questions.

Very real. Every engagement is scoped, contracted, and delivered by working security practitioners with real reports at the end.
Yes. Stux Security is based in Innlandet, Norway, but every service on the shelf is designed to be delivered remotely, anywhere in the world.
Standard packages are listed as products on our Ko-fi shop. For custom scopes, we send a quote first and share a Ko-fi link once scope and price are agreed.
They're a "threat level" — roughly how deep and intensive that engagement is, not a rating of how dangerous your organization is. A 5-star box is a bigger, longer engagement than a 2-star one.
Yes — mention it in the contact form or kickoff call and we'll get one in place before any sensitive scope details change hands.
Not sure what service does what for you?

Let's decrypt your thoughts with a free consultation chat.

Tell us what you need and we'll follow up with a scope and a quote.

Select a Service

We will reply within 1-3 business days (usually), Europe/Oslo time (CET/CEST).

Third-party shop

Prefer to browse and purchase services in our third-party web shop?

All our services are listed as products in our third-party shop at Ko-fi. Pick one and pay quickly and securely with Ko-fi's payment providers, PayPal or credit card. We'll reach out to discuss and schedule your service of choise.

  • Fixed-scope pentests and audits
  • Awareness training bundles
  • Managed Detection & Response plans
If we can't solve your problem, you will get notified and refunded immediately. Open our third-party shop ↗