About

Security work at the smallest scale, where it actually breaks

We took our name from Max Planck, the physicist who showed that nature sets its rules at the smallest scale. Security fails the same way. A single stale credential, one permissive firewall rule, one unvalidated parameter. Our job is to find those details before someone else does.

Who We Are

A small firm, on purpose

Planck Defense & Aerospace is a focused team of senior security practitioners built around one thing done well: agentic API penetration testing, delivered by Planck Operator and backed by deep offensive-security expertise. Every person on the team carries an operational role. Nobody here only sells, and nobody only manages.

The aerospace in our name reflects where we set the bar. Defense, aerospace, and other high-assurance industries expect precision, documented method, and controlled handling of sensitive material. We apply that standard to every client, including the finance, healthcare, SaaS, energy, manufacturing, and government contracting organizations we work with.

We will not tell you a founding story or quote a headcount. What we can tell you is exactly how an engagement with us runs, what you receive, and who does the work. Those are the claims that matter, and they are the ones you can verify.

What defines our engagements

  • Testers you talk to directly. Questions during an engagement go to the person with their hands on your systems, not through an account layer.
  • Scopes we can deliver in full. We size engagements to the time real testing takes. If a scope cannot be covered properly, we say so before we sign.
  • Findings backed by evidence. Every issue we report ships with reproduction steps, request and response data or equivalent artifacts, and a CVSS v3.1 rating you can defend internally.
  • Advice that survives contact with engineering reality. Remediation guidance is written for the team that has to implement it, with awareness of legacy constraints, release cycles, and what a fix costs in practice.
Principles

Four rules we do not bend

These are not values statements. They are operating constraints that shape how we scope, staff, test, and report.

Evidence over noise

Severity means something in our reports. A critical finding is one we can demonstrate, with a working reproduction path and a clear statement of impact. We do not pad reports with informational filler dressed up as risk, and we do not inflate ratings to make an engagement look productive. Every finding is reproducible by your team from the report alone.

Senior work only

There is no bench of juniors learning on your systems. The practitioners who scope your engagement are the ones who execute it. That keeps teams small and calendars honest, and it means the person reading your architecture diagram has seen a hundred like it and knows where the same mistakes tend to hide.

Straight talk

If something you ask for is out of scope, unsafe to test in production, or simply low risk, we say so. If a finding is a genuine problem but unlikely to be exploited in your environment, the report says that too. You are paying for judgment, not for a longer list, and judgment sometimes means telling you a thing you flagged is fine.

Confidential by default

We sign an NDA before scoping begins, not after. Data handling, retention, and destruction are defined in writing for every engagement. Your findings are never reused as marketing material, never anonymized into case studies without written permission, and never disclosed to anyone you have not authorized.

How We Work

The operating model behind every engagement

Three structural choices, made deliberately, that determine what working with us feels like in practice.

01

Small teams with direct lines

Each engagement is staffed by a small team, and you get direct contact with the people doing the work. When a tester finds something serious mid-engagement, you hear it from the tester, that day, not in the report three weeks later. When your engineers have a question about a finding, they ask the person who wrote it. This removes the translation loss that turns precise technical findings into vague action items.

02

Fixed, honest scopes

A scope is a promise about depth, not just a list of assets. Before we agree to one, we check it against the hours the work demands: authenticated and unauthenticated coverage, the attack classes relevant to the target, and enough room for the unexpected paths that produce the findings that matter. We would rather decline work than dilute it. When a scope and a budget do not fit, we tell you what we would cut and why, and let you make the call with full information.

03

Long relationships over transactions

Most of the value we deliver arrives after the first report: in the retest that confirms your fixes actually closed the hole, in the question your platform team asks six weeks later, in the second engagement that starts from accumulated knowledge of your environment instead of from zero. We include one retest of fixed findings in every assessment and we keep engagement records so continuity is real, not a slide in a sales deck.

Leadership

Built by an operator who breaks these systems for real

Berk Dusunur

Founder & Chief Executive Officer

Berk Dusunur is an offensive-security practitioner with ten years of experience running penetration tests, threat hunting, and vulnerability research across critical infrastructure, public-sector agencies, and high-security financial environments. His prior roles include offensive security at Bank of America, incident response with a computer emergency response team (CERT) at New York City government, and security work at WMATA. He holds a bachelor's degree in computer engineering, serves in the U.S. Air Force, and is a licensed pilot.

He has been recognized in more than 100 vulnerability-disclosure Hall of Fame programs, including the U.S. Department of Defense, Microsoft, and PayPal, and is the author of multiple public CVEs, most recently CVE-2026-75960 (CISA advisory ICSA-26-237-01), a master-PIN authorization flaw (IDOR) in a production access-control system. In practice, he finds, chains, and proves the exact class of API authorization and business-logic exploits that Planck Operator is built to automate.

Why this matters

  • Author of CVE-2026-75960, published as CISA advisory ICSA-26-237-01.
  • 100+ Hall of Fame programs, including the U.S. Department of Defense, Microsoft, and PayPal.
  • Ten years offensive security across critical infrastructure, public sector, and finance.
  • The agent learns from real attacks. Our founder's proven exploits seed the methodology and the models behind Planck Operator.
Responsible Disclosure

Coordinated disclosure, practiced and supported

We practice coordinated disclosure in our own research and we support it as a norm for the industry. When our work surfaces a vulnerability in third-party software, we report it to the vendor privately, allow reasonable time for a fix, and coordinate publication so users are protected before details are public.

The same standard applies to us. If you believe you have found a security issue in our infrastructure or services, write to [email protected]. That address reaches the team that handles reports about our own systems, not a ticket queue.

  • Acknowledged promptly. Reports to [email protected] receive a human response, and good-faith reports are never met with legal threats.
  • Investigated by engineers. The people who run our infrastructure triage every report and keep you informed of the outcome.
  • Credited when fixed. We credit researchers who report responsibly, unless you prefer to stay anonymous.
Get Started

Talk to the people who will do the work

A short scoping conversation is enough to tell you whether we are the right fit. No account managers, no scripted pitch.