Skip to content
سفينةSAFINA
ABOUT THE COMPANY

We build the tools
we use ourselves

Safina is a cybersecurity company based in Jeddah. We build the tools we use in our own day-to-day work, then ship them to the people who need them: a scanner that tests what is live on the web, and a platform that reads the code it was built on.

WHY SAFINA

The name is not decoration

The company is called Safina — a ship — because that is what the work actually is: carrying an organisation from open water full of threats to safe harbour. A ship does not survive on the strength of its mast alone but on every plank in its hull, and we treat security the same way: not one bright feature, but continuous cover from the outside in.

And because a voyage is not measured in promises, everything we hand over can be checked: a finding with its payload and its request, or a taint path named by file and line. If we cannot prove it, we do not report it.

HOW WE WORK

Four principles behind everything we build

  1. 01

    Your data never leaves your machine

    Our tools run where you run. No code upload, no cloud account, no phone-home — right down to a machine with no network at all.

  2. 02

    Evidence, not guesses

    Every finding carries what proves it: the payload, the request and the injection point, or the complete path from source to sink. A reviewer can reproduce it from the report alone.

  3. 03

    We tell the truth about coverage

    A scan that stopped halfway is reported as exactly that. “No vulnerabilities” is a security verdict, and we only issue it when a run both finished and covered its target.

  4. 04

    Arabic is a first language here, not a translation

    Our interfaces and reports are Arabic with genuine right-to-left support, in the terms Arab practitioners actually use, with the typeface embedded so reports print as designed with no connection.

WHAT WE BUILD

Cover from both directions

One tool tests your application from the outside the way an attacker would; another reads its code from the inside the way an auditor would.

I

Rassed

Web vulnerability discovery

Crawls your applications and APIs, attacks them with real payloads, and hands you only what actually worked — each finding with the proof to reproduce it.

Learn more

II

Misbah

Source code review

Reads the source behind your applications, follows untrusted data to where it turns dangerous, and names the flaw by file and line — with the rule behind it open to read.

Learn more
WHERE WE ARE

From Jeddah, into any air-gapped environment

We are based in Jeddah, Saudi Arabia. Because our tools need no outbound connection, they run inside closed networks and air-gapped environments with no special arrangements.

SET SAIL

Talk to us

Email us with your application or repository, and we will reply with the first steps of the assessment.

sales@safina.sa