Offensive Security for the AI-Built Era

Your AI shipped the feature fast.
It didn't check who else could see it.

Marcal Security finds the authorization gaps, exposed secrets, and business-logic flaws that ship silently inside AI-generated and traditionally-built applications alike — verified by hand, not just by scanner.

vibe-security-radar.log
// CVEs attributed to AI-generated code, monthly (2026)
Jan
6
Feb
15
Mar
35
Source: Georgia Tech SSLab, Vibe Security Radar (2026)
The Gap

Speed and security aren't the same review.

AI coding tools are remarkably good at producing code that runs. They're far less reliable at producing code that's safe to expose to the internet — and the gap doesn't announce itself in a demo.

Independent testing found that close to half of AI-generated code samples fail basic OWASP security checks on first pass — a rate that hasn't meaningfully improved across recent model generations.
In controlled tests, the large majority of AI-generated samples failed to defend against cross-site scripting, one of the most basic and well-documented web vulnerability classes.
AI-assisted commits have been shown to expose hardcoded secrets at roughly twice the rate of human-written commits.
Automated scanners are structurally weak at catching the failures that matter most in practice: broken authorization between users or accounts, and business logic that behaves incorrectly — exactly the class of issue that tends to expose one customer's data to another.
Sources: Veracode State of Software Security research; Georgia Tech SSLab; Cloud Security Alliance, 2026.
Services

Two ways to find out before an attacker does.

Web & API

Web Application & API Penetration Test

A manual, authenticated assessment of a production web application and its API — regardless of how it was built — aligned to the OWASP Top 10 and OWASP API Security Top 10.

  • Authentication & session security
  • Horizontal and vertical authorization testing
  • Endpoint enumeration and access-control review
  • CVSS-scored findings with remediation guidance
Process

Scoped, manual, and reported in plain language.

SCOPE

A short call, not a form

We define the target, access level, and what matters most to you before anything is touched.

TEST

Hybrid, not just a scan

Automated coverage handles the repetitive ground; every reported finding is manually verified by hand.

REPORT

Findings you can act on

A written report with CVSS scoring and a live walkthrough call with your team — not just a PDF and silence.

About

An engineer first, a tester second.

Marcal Security is run by Sebastian Quesada Calderón, a computer engineer and current Master's candidate in Cybersecurity at Instituto Tecnológico de Costa Rica (TEC). Before moving toward offensive security, Sebastian spent years building production software — which shapes how findings get reported here.

A vulnerability report is only useful if the fix is realistic inside your actual codebase and deploy pipeline. That's the standard every finding is held to: not just "this is broken," but "here's specifically what to change."

Background
Computer Engineering, fullstack & cloud infrastructure experience
Education
M.Sc. Cybersecurity (in progress), Instituto Tecnológico de Costa Rica
Research
Published research on npm supply-chain security
Approach
Manual verification of every reported finding — no unverified scanner output
Get Started

Find out what's actually exposed.

A scope call takes 20 minutes and costs nothing. You'll walk away knowing exactly what an assessment would cover and what it would take to run.

First-engagement pricing available for new clients.