SektionEins
SektionEins GmbH is a Bonn-based boutique IT security consultancy (founded 2007) providing vendor-independent security consulting, audits, and training for web and mobile applications, supported by a portfolio of open-source security tools and a high-margin iOS kernel exploitation training franchise.
- Company typePrivate
- Founded2007
- HeadquartersCologne, Germany
- Headcount1–10
- GTM typeB2B
- OfferingServices
What SektionEins does
SektionEins GmbH is a German boutique IT security consultancy headquartered in Bonn (Mozartstr. 4-10, 53115 Bonn), founded in 2007 and registered as a private limited liability company (HRB 23021, Amtsgericht Bonn). The firm specializes in identifying vulnerabilities and security weaknesses in web applications — covering server-side languages (Java, PHP, Ruby, Perl, Python) and client-side technologies (JavaScript, AJAX, WebSockets, Flash, AIR) — as well as mobile platforms (iOS, Android). It delivers vendor-independent security consulting across the concept, development and production phases, including the introduction of a Secure Development Lifecycle (SDL) into client projects. SektionEins' service portfolio is organized into three professional-services streams: Security Consulting Services, Security Audits (source code analysis, manual and automated penetration testing, infrastructure analysis), and Security Training and Workshops (multi-day developer and DevOps courses, plus a recurring iOS Kernel Exploitation Training led by Stefan Esser, priced at EUR 4,000-5,000 per attendee).
The company operates an adjacent portfolio of open-source security tools and one consumer iOS application: the PHP Secure Configuration Checker (PCC, v0.3.0 in 2026), the OpenSSH Security Configuration Checker (SSHDCC, v0.3 in 2025), the Suhosin/Suhosin-NG PHP hardening extension (relaunched 2019 under NLnet funding), the µ-CA-Tool for X.509 certificate management with SmartCards, the SCD-PKCS#11 authentication module bridging GnuPG's scdaemon to PKCS#11, the OSX Installer Verifier, and the System and Security Info iOS app (AppStore, 2016). Revenue is generated through project-based consulting, fixed-scope audits, and fee-based training; pricing for consulting and audits is not publicly disclosed, while training uses published Early Bird / Regular / Late EUR tiers. SektionEins is founder/owner-operated — with Stefan Esser as lead researcher, Johann-Peter Hartmann as Managing Director and Benjamin Fuhrmannek as responsible for editorial content under § 18 Abs. 2 MStV — and has no parent company, public listing, or institutional investor; the only external funding event disclosed is a 2019 NLnet grant for Suhosin-NG. EU export control on "Intrusion Software Technology" restricts the exploitation training to students from approved jurisdictions.
SektionEins firmographics
Firmographics- Name
- SektionEins
- Legal name
- SektionEins GmbH
- Website
- https://sektioneins.de
- Company type
- Private
- Founded year
- 2007
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- SektionEins GmbH is a Bonn-based boutique IT security consultancy (founded 2007) providing vendor-independent security consulting, audits, and training for web and mobile applications, supported by a portfolio of open-source security tools and a high-margin iOS kernel exploitation training franchise.
- Ownership category
- akta.pro rank
SektionEins industry classification
Industry- Product category
- IT Security Consulting
- NAICS
- Computer Systems Design and Related Services (54151), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Educational Services (8200), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Application Security & Secure Software (DevSecOps) (EDAOAIAK)
- akta.pro secondary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
Keywords
Where SektionEins is headquartered
LocationHeadquarters
- HQ city
- Cologne
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
SektionEins business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Security consulting engagements: Vendor-independent consulting across concept phase, in-development, production and Secure Development Lifecycle (SDL) introduction phases; sold as project-based professional services.
- Security audits: Source code analysis, penetration testing, and infrastructure analysis engagements delivered as fixed-scope audits with detailed reports including risk assessment and remediation recommendations.
- Training courses and workshops: Multi-day technical training courses (e.g., iOS Kernel Exploitation Training at 4000-5000 EUR + VAT, OS X and iOS Kernel Internals, web security workshops) plus in-house and conference-delivered variants.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Pay-as-you-go | iOS Kernel Exploitation Training - Early Bird 4000 EUR, Regular 4500 EUR, Late 5000 EUR (plus VAT) |
| Other | Pay-as-you-go | OS X and iOS Kernel Internals Training - Early Bird 4000 EUR, Regular 4500 EUR, Late 5000 EUR (plus VAT) |
| Other | Multi-year contract | Security consulting and audit services - quote-based |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels7 records
SektionEins product offering
Product offeringCore offering
SektionEins is a boutique IT security consultancy that delivers vendor-independent security consulting, source code audits, penetration tests, and infrastructure analyses for web and mobile applications, alongside multi-day specialized training (notably a recurring iOS Kernel Exploitation Training) and a portfolio of open-source security tools (Suhosin-NG, SSHDCC, PCC, OSX Installer Verifier, µ-CA-Tool, SCD-PKCS#11) and a consumer iOS app (System and Security Info). Revenue is generated primarily through professional services engagements, with training sold on a tiered EUR price schedule and a small set of security tools published free under open-source licenses.
Product overview
SektionEins offers a combined portfolio of professional IT security services and accompanying open source security tools, headquartered in Bonn, Germany. The service offerings are organized into Security Consulting Services (concept phase, development phase, production phase, and SDL introduction), Security Audits (source code analysis, penetration testing, infrastructure analysis), Security Training and Workshops (developer and DevOps training, including a recurring iOS Kernel Exploitation Training), and Security Advisories (published vulnerability research). The open source tool portfolio directly supports and extends these services: the PHP Secure Configuration Checker (PCC) and Suhosin-NG PHP hardening extension secure PHP environments; the SSHDCC audits OpenSSH server configurations; the µ-CA-Tool and SCD-PKCS#11 Authentication Module provide smart card and certificate management built around OpenSSL, OpenSC and GnuPG; the OSX Installer Verifier validates Mac OS X installer integrity; and the System and Security Info iOS app surfaces process lists and detects compromised iPhones. Together the tools and services target vulnerabilities in server-side (Java, PHP, Ruby, Perl, Python) and client-side (JavaScript, AJAX, WebSockets, Flash, AIR) web technologies as well as mobile platforms (iOS, Android).
Differentiator
Problem solved
Functional benefit
Brands
- Suhosin-NG: Suhosin-NG is a PHP runtime hardening and protection extension (successor to the original Suhosin) developed by SektionEins to secure PHP 7/8 web application environments, accepted for the 2019-04 NLnet open call.
- System and Security Info
- Suhosin
Products and services
- Security Consulting Services Vendor-independent consulting engagements covering the concept phase, the development phase, the production phase, and the introduction of a Secure Development Lifecycle (SDL) into client projects.
- Security Audits Fixed-scope security audit engagements combining detailed source code analysis, manual and automated penetration testing against running systems, and infrastructure analysis; deliverables are concise or detailed reports including vulnerability descriptions, remediation recommendations, and risk assessments.
- Security Training and Workshops Multi-day workshops for developers and for system administrators / DevOps covering web security fundamentals, application attacks (XSS, CSRF, SQL injection, code injection, HTTP header injection, unserialize, clickjacking), session management, AI + Security, cryptographic functions and random numbers, password protection, error handling, configuration and server hardening, threat modeling, SDL, and security testing; available in German and English.
- iOS Kernel Exploitation Training Recurring 5-day instructor-led course led by Stefan Esser in Frankfurt covering iOS kernel internals (ARM/ARM64, page tables, MAC policy hooks, sandbox, code signing), kernel reversing and debugging (KDP, panic dumps, heap visualization), kernel exploit mitigations and their weaknesses, exploitation of real kernel vulnerabilities, kernel heap layout control techniques, and jailbreak-related kernel patches; each attendee receives a training iPad.
- OS X and iOS Kernel Internals Training 5-day hands-on training course at Le Méridien Parkhotel Frankfurt focused on OS X platform kernel internals, with attendees supplying their own Apple Mac Notebook, IDA Pro 6.x license, and VMWare Fusion.
- PHP Secure Configuration Checker (PCC) Open source tool that checks PHP 8.x runtime configuration for security-relevant misconfigurations; v0.3.0 released as the 'Big 2026 Update' with new security checks, bug fixes, and cleanup.
- SSHDCC (OpenSSH Security Configuration Checker) Open source Tcl-based tool that audits OpenSSH server configuration files for security issues; supports online mode against live Linux/BSD/MacOS hosts and offline mode against config files, with severity-graded output, Match-block checks, and CSV export; covers OpenSSH 7.6 (2018) through 10.0 (2025).
- Suhosin-NG PHP 7+ hardening extension and successor to the original Suhosin for PHP 5; designed to enable most PHP 7 users to run their web applications in a secure environment without becoming IT security experts; released as open source.
- µ-CA-Tool (micro CA Tool) High-level Bash CLI frontend for OpenSSL, OpenSC, and GnuPG that simplifies creation and management of X.509 CAs, intermediate CAs, and client certificates with optional SmartCard storage and n-of-m key backup, focused on Nitrokey Pro, Crypto Stick, and other PKCS#11/OpenPGP-Card tokens.
- SCD-PKCS#11 Authentication Module Open source PKCS#11 provider that uses GnuPG's scdaemon (instead of PCSCd) for smart card access, enabling TLS client authentication with Firefox and OpenSSH login using RSA signatures from OpenPGP-Cards like Nitrokey Pro and Crypto Stick on OSX/Linux.
- OSX Installer Verifier Open source tool and accompanying JSON hash database that verifies OS X installer app bundles via SHA256 hashes; provides an independent, third-party-verifiable alternative to Apple's undocumented codesign verification for downloads distributed via the Mac App Store.
- System and Security Info (iOS app) iOS app published on the Apple App Store that displays device CPU/memory/disk usage and a full process list enriched with SHA1 hash, code signature, and entitlements; performs jailbreak detection, security anomaly detection (tampered code-signing flags, unexpected injected libraries), and malware detection on iOS 9+.
Quantifiable outcome
- Identified CVE-2018-1000858 (CSRF/SSRF and DoS in GnuPG's WKD handling), disclosed 23 November 2018, fixed in GnuPG 2.2.10 and 2.2.12.
- +2 more outcomes
Companies that use SektionEins
Customer profileNamed customers1 record
Ideal customer profiles3 records
SektionEins technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration10 records
Feature7 records
SektionEins partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered minor.
- MySQLminorJoint webinar with MySQL (now Oracle) on 14 August 2008 themed 'Bau sicherer LAMP Anwendungen' (Building secure LAMP applications), delivered by Stefan Esser. The webinar was published as on-demand content on the MySQL website.
- ZendminorPlanned co-marketing webinar between SektionEins and Zend on 'Sichere Programmierung mit dem Zend Framework' (Secure programming with the Zend Framework), announced October 2009.
- Le Méridien Parkhotel FrankfurtminorLong-running training venue partner hosting multi-day iOS Kernel Exploitation and OS X/iOS Kernel Internals Trainings in Frankfurt, Germany; offers special room rates for attendees booking early.
Scale indicators5 records
Recent moves6 records
Expansion highlights4 records
SektionEins competitors and assessment
Company assessmentBroad incumbents
- NetSPI: Enterprise-focused security testing firm with broad penetration testing and attack surface management portfolio. Represents a larger scaled player competing for similar mid-market and enterprise audit budgets.
- IOActive: Global security consultancy with strong mobile and IoT device assessment capabilities. Comparable iOS/Android research heritage though operating at materially larger scale.
- NCC Group: Global, publicly listed cybersecurity services firm offering application security, penetration testing, and managed security services. Represents the scaled incumbent whose enterprise relationships SektionEins occasionally services.
- Bishop Fox: US-based offensive security consultancy combining traditional pen testing with proprietary continuous assessment tooling (Continuous Attack Surface Testing). Comparable research brand but materially larger scale.
Direct peers
- Cure53: Berlin-based boutique web application and browser security consultancy founded by a former SektionEins colleague. Closest comparable in size, service mix (penetration testing, source code audits, security research), and Germanic boutique model.
- Include Security: Boutique application and web security consultancy offering penetration testing and code review. Similar scale and service mix targeting enterprise developers needing deep technical assessments.
- Trail of Bits: US-based security research and consulting firm specializing in software security audits, formal verification, and tooling (e.g., Semgrep). Closely comparable research-led boutique with overlapping web and cryptography expertise.
- Independent Security Evaluators: US-based boutique consultancy specializing in application and hardware security audits with a strong research orientation. Closely comparable boutique structure and advisory-driven go-to-market.
- Recurity Labs: Berlin-based independent IT security consultancy focused on application security, penetration testing and security research. Comparable boutique structure with similar web and mobile assessment offerings.
- SR Labs (Security Research Labs): Berlin-based security research and consulting firm delivering advisory, audits, and training to enterprise and government clients. Comparable boutique research-led service model with adjacent iOS/mobile expertise.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
SektionEins social profiles
Digital presenceSektionEins compliance and trust
Trust signalCompliance1 record
SektionEins financial estimates
Financial estimateRevenue estimate
Valuation estimate
SektionEins leadership team
Management profileNumber of profiles
Profiles3 records
SektionEins funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SektionEins M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SektionEins
What does SektionEins do?
SektionEins is a boutique IT security consultancy that delivers vendor-independent security consulting, source code audits, penetration tests, and infrastructure analyses for web and mobile applications, alongside multi-day specialized training (notably a recurring iOS Kernel Exploitation Training) and a portfolio of open-source security tools (Suhosin-NG, SSHDCC, PCC, OSX Installer Verifier, µ-CA-Tool, SCD-PKCS#11) and a consumer iOS app (System and Security Info). Revenue is generated primarily through professional services engagements, with training sold on a tiered EUR price schedule and a small set of security tools published free under open-source licenses.
Is SektionEins a public or private company?
SektionEins is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was SektionEins founded?
SektionEins was founded in 2007. It employs 1 to 10 people.
Where is SektionEins based?
SektionEins is headquartered in Cologne, Germany, in the Europe region.
How does SektionEins make money?
Three revenue lines are on record. Security consulting engagements are the primary driver. The others are security audits and training courses and workshops.
Who are SektionEins's main competitors?
Broad incumbents on record are NetSPI, IOActive, NCC Group and Bishop Fox. Direct peers are Cure53, Include Security, Trail of Bits, Independent Security Evaluators, Recurity Labs and SR Labs (Security Research Labs).
Does SektionEins have an API?
No public API is recorded for SektionEins.
What industry is SektionEins in?
SektionEins's product category is IT Security Consulting. Its primary akta.pro industry code is EDAOAIAK, Application Security & Secure Software (DevSecOps), with a secondary code of EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking. Its NAICS code is 54151 and its SIC code is 8200.