We build security and privacy software.

Clickswave Labs is a research-led cybersecurity company. We make Crossfyre for offensive security and SiloCat for end-to-end encrypted file sharing, and we take on security testing directly.

Open source DPIIT recognised Bootstrapped
Products

What we make.

Crossfyre

Distributed recon and offensive-security automation.

  • Recon runs across distributed nodes you control, orchestrated from one console.
  • Operations are stateful and resumable; a dropped node does not lose the run.
  • Adaptive rate limiting backs off and recovers based on how targets respond.
Toolchain is open source
Distributed scan

SiloCat

End-to-end encrypted file storage and sharing.

  • Files are encrypted in your browser with XChaCha20-Poly1305 before upload.
  • Chunked, parallel transfers keep large uploads and downloads fast.
  • Tokenized share links; recipients download without an account.
Fully open source
Encrypted
Services

Work we take on.

Hands-on security work on your apps and APIs, usually the part standard tooling cannot reach. Client work is under NDA, so there are no names on this page.

Mobile app security testing

Most mobile testing stops at the apps that refuse to be intercepted. Pinned builds, Flutter, root and tamper detection: those get tested too.

The findings are in the API behind the app: authorization gaps, another user's data, and fields the app sends that it never needed to send.

What comes back
  • Every finding with the request and response behind it.
  • A hardening note your developers can act on without a call.
  • A retest of the build they produce, pass or fail.
Android only

Web and API testing

Logged-in testing across the whole API surface, not only what is reachable from outside. Most of what comes back is authorization: one account reaching another account's data, with the request that proves it.

Source code review

Read access to the repository, and every finding comes back with the file and line behind it. It reaches what testing a running system cannot: paths behind a flag, a check that was never written, and credentials committed years ago.

Hardening review

A read of the protections you already have and where they actually sit. A check in the wrong place passes review and stops nothing, and that is the common finding rather than a missing one.

Talk about an engagement Scope, price and timeline come back in writing before anything starts.
Research

Research feeds the product.

Crossfyre has a research wing. It works out new ways to test things, and it finds bugs in software other people maintain. Both end up in the product.

New techniques

Ways to test what nothing could test before. Reading the TLS verifier out of a stripped Flutter binary started here, and it runs on every job now.

Bugs we report

Found in software we don't own and sent to the maintainer first. The disclosures page carries a count until they publish, then the whole write-up.

Open source

We build in the open.

Security software you can't inspect is security software you have to trust blindly. We'd rather show you the code.

github.com/clickswave
Contact

Get in touch.

Product questions start at crossfyre.io or silo.cat. For everything else, write to us.