I
Rassed
Web vulnerability discovery
Crawls your applications and APIs, attacks them with real payloads, and hands you only what actually worked — each finding with the proof to reproduce it.
Learn moreSafina is a cybersecurity company based in Jeddah. We build the tools we use in our own day-to-day work, then ship them to the people who need them: a scanner that tests what is live on the web, and a platform that reads the code it was built on.
The company is called Safina — a ship — because that is what the work actually is: carrying an organisation from open water full of threats to safe harbour. A ship does not survive on the strength of its mast alone but on every plank in its hull, and we treat security the same way: not one bright feature, but continuous cover from the outside in.
And because a voyage is not measured in promises, everything we hand over can be checked: a finding with its payload and its request, or a taint path named by file and line. If we cannot prove it, we do not report it.
Our tools run where you run. No code upload, no cloud account, no phone-home — right down to a machine with no network at all.
Every finding carries what proves it: the payload, the request and the injection point, or the complete path from source to sink. A reviewer can reproduce it from the report alone.
A scan that stopped halfway is reported as exactly that. “No vulnerabilities” is a security verdict, and we only issue it when a run both finished and covered its target.
Our interfaces and reports are Arabic with genuine right-to-left support, in the terms Arab practitioners actually use, with the typeface embedded so reports print as designed with no connection.
One tool tests your application from the outside the way an attacker would; another reads its code from the inside the way an auditor would.
I
Web vulnerability discovery
Crawls your applications and APIs, attacks them with real payloads, and hands you only what actually worked — each finding with the proof to reproduce it.
Learn moreII
Source code review
Reads the source behind your applications, follows untrusted data to where it turns dangerous, and names the flaw by file and line — with the rule behind it open to read.
Learn moreWe are based in Jeddah, Saudi Arabia. Because our tools need no outbound connection, they run inside closed networks and air-gapped environments with no special arrangements.
SET SAIL
Email us with your application or repository, and we will reply with the first steps of the assessment.
sales@safina.sa