Marcal Security finds the authorization gaps, exposed secrets, and business-logic flaws that ship silently inside AI-generated and traditionally-built applications alike — verified by hand, not just by scanner.
AI coding tools are remarkably good at producing code that runs. They're far less reliable at producing code that's safe to expose to the internet — and the gap doesn't announce itself in a demo.
For startups built partly or entirely with tools like Cursor, GitHub Copilot, Claude Code, Lovable, or Replit Agent. A hybrid review combining automated coverage of common AI-generated vulnerability classes with manual testing of the logic no scanner understands: who can see what, and why.
A manual, authenticated assessment of a production web application and its API — regardless of how it was built — aligned to the OWASP Top 10 and OWASP API Security Top 10.
We define the target, access level, and what matters most to you before anything is touched.
Automated coverage handles the repetitive ground; every reported finding is manually verified by hand.
A written report with CVSS scoring and a live walkthrough call with your team — not just a PDF and silence.
Marcal Security is run by Sebastian Quesada Calderón, a computer engineer and current Master's candidate in Cybersecurity at Instituto Tecnológico de Costa Rica (TEC). Before moving toward offensive security, Sebastian spent years building production software — which shapes how findings get reported here.
A vulnerability report is only useful if the fix is realistic inside your actual codebase and deploy pipeline. That's the standard every finding is held to: not just "this is broken," but "here's specifically what to change."
A scope call takes 20 minutes and costs nothing. You'll walk away knowing exactly what an assessment would cover and what it would take to run.