Open Texni Labs Defence Munich
Situation report
Defence
We do not attack. We close gaps.
Systems built with AI need someone who reads them.
Situation
- Attacks have become cheaper. What used to need a team is now done by a script with a language model: phishing in flawless German, password lists, scans around the clock.
- Software has become cheaper too. Anyone who can prompt a system together in an afternoon gets one that runs. Whether it holds, nobody says.
- Both hit the same businesses: small companies without a security staff of their own that still manage customer data, invoices and access.
Sectors
01 Security check
- Assignment
- Inventory: accounts and access, multi-factor, email and cloud, network and remote access, backups and their restoration, patch level.
- Result
- A report with an order of work: what comes first, what next, what can wait.
- Limit
- Reading and checking only. We change nothing before you approve it.
02 Hardening
- Assignment
- Implementation per the report: servers, remote access, network segments, backups with a restore drill, password management, device and account rules. Control systems and building technology too: configuration, remote access, software.
- Result
- Every measure approved individually, implemented and documented.
- Limit
- For the electrical installation, the terms on the Controls page apply. Qualification & limits
03 Review of AI-built systems
- Assignment
- Code and configuration of applications built with AI tools: sign-in and permissions, tenant isolation, secrets, dependencies, browser protection, how language models are handled inside the product.
- Result
- A list of the weak points with evidence and a proposed fix, sorted by severity.
- Limit
- We read with the access you give us. We do not attack a running system.
04 Advice and emergency plan
- Assignment
- Rules for everyday work, training against phishing, an emergency plan: who calls whom, what is switched off first, where the backups are.
- Result
- A plan that can hang on the wall.
- Limit
- In a real incident, forensics and the authorities take over. We prepare, we do not investigate.
Dispatch
This page, checked in the build.
- Content-Security-Policy
- active
- no third-party origins · checked in the build
- Third-party requests
- 0
- checked in the build
- Own cookies
- 0
- as in the colophon
- Local entries
- 2
- appearance, motion · as in the colophon
Assignment
Every job is carried out only on a system named in writing and only with the written authorisation of its owner. We do not carry out penetration tests or attack simulations. We defend.
Report
Own audit
As of 07/09/2026 · 0e8045a
- 28/28 tables with tenant isolation, enforced by the database, fail-closed.
- 1,596 automated tests green: 1,239 in the backend against a live database, 357 in the frontend.
Own infrastructure
Internal services are reachable only on the local network or via VPN. Backups are encrypted and the restore is rehearsed. No port of the internal services is open to the internet.
Report your situation
Write what you run and what worries you. You get an assessment, not a sales pitch.