A boutique offensive-security firm that stayed boutique on purpose.
SentinelForge was founded in 2017 by three engineers who had spent the previous decade running offensive-security teams inside two US regional banks and one federal contractor. The founding thesis was simple: most consulting engagements deliver a scanner PDF with a fancy cover, and most CISOs know it but keep paying because the audit checkbox is real. We thought that was a bad enough problem to build a company around.
Nine years and 217 engagements later, we're 22 people. We've kept the team small on purpose — every senior consultant we hire has to raise the bar of what we can commit to. We turn down more work than we take. In 2025 we declined about 40% of qualified inbound because we couldn't staff it with a senior lead we trusted.
Every engagement lead has at least 8 years of hands-on offensive work — no exceptions. We don't have a junior tier that shadows and learns on your engagement.
We spend real time on scoping before we quote so we don't have to change the invoice mid-engagement. Time-and-materials only when the scope genuinely cannot be defined in advance (rare, mostly IR).
Every engagement gets a shared Slack channel with the delivery team for the duration plus 30 days. Ask us anything, get an answer from the person doing the work.
Our team disclosed 14 CVEs in 2025 across open-source and vendor products. We publish blog posts on techniques we develop internally when we can do so without exposing client work. See our public GitHub for tools we've released.
CEO, Co-founder
Previously CISO office at PNC Financial, red team lead at DoD contractor Riverside Research. OSCP, OSCE, CISSP. Speaks at Black Hat semi-regularly, usually about IAM privilege escalation.
CTO, Co-founder
Previously head of application security at KeyBank. Wrote the internal fuzzing framework we still use for source code review engagements. Kernel-level Windows research background.
Head of Delivery, Co-founder
Previously ran the red team at Fifth Third Bank. Runs delivery and quality across every engagement. If a report goes out, she has read it.