Company / About

An independent Dutch offensive security firm.

Scotoma is an independent Dutch offensive security firm that pentests AI agents and the software they run on, with written permission. We test both layers of a modern product, the model and the stack, and we sell nothing that would profit from what we find.

Updated
Sources
07
SCOTOMA
/skuh-TOH-muh/
n.
a blind spot in an otherwise normal field of view.

Every system has one. We find yours first.

Pronunciation as Merriam-Webster gives it.

What we do.

We pentest AI agents and the software they run on. On the model layer that means chatbots, RAG applications, agents and MCP servers: what they read, what they reveal and what they do. On the stack layer it means the web applications, APIs and cloud underneath. An issue that starts in a conversation can end in an API, so we test both, in one scope when that helps.

Two layers, one test when it helps.

01 / Model layer

AI Pentest

Chatbots, RAG and agents: what the model reads, reveals and does, and how far it reaches.

02 / Stack layer

Stack Pentest

Web applications, APIs and cloud: what one user can do to another, and how far one weak spot reaches.

03 / Clearance

Launch Clearance

Shipping AI on a SaaS platform? The feature and the platform under it, in one scope and one report.

We sell no guardrail, firewall or platform.

So our findings come without an upsell. Since 2025, platform vendors have bought several independent AI security firms, and their tests now come with a product to buy:

2025-07-22
Protect AI, acquired by Palo Alto NetworksNote 1
2025-09-05
Prompt Security, acquired by SentinelOneNote 2
2025-10-22
Lakera, acquired by Check PointNote 3
2025-11-03
SPLX, acquired by ZscalerNote 4
2026-03-09
Promptfoo: OpenAI announced it is buying itNote 5

A test from a company that also sells the fix has a conflict built in. Ours ends with a list of fixes you can make with any vendor, or with none.

How we work.

  1. Written permission first. We test only what its owner has authorized in writing, and nothing outside the agreed scope.
  2. Both layers, equal weight. The model and the stack get the same care, the same report format and the same retest rules.
  3. Evidence you can check. Stack findings come with the exact requests, model findings with a reproduction rate, and every finding maps to a public standard.
  4. Public method. Our method, rules of engagement and a sample report are published, so you can judge the work before you buy it.

Who does the testing.

The founder leads every engagement as its tester. Credentials go on this page as soon as you can verify each one yourself, and not before.

The company.

Our trade register details go here once each one is registered and you can look it up yourself. Until then, these are the ways to check us.

Check us without asking us.

Why the name.

Every eye has a blind spot, about 15 degrees from where you look, and the brain fills it in so well that you never notice it.Note 6 Mariotte described it in 1668.Note 7 Every system has one too: the part nobody looked at, because everything around it looked fine. That is the part we test.

Find your own on our home page.

Read next