Open Texni Labs Defence Munich

Situation report

Defence

We do not attack. We close gaps.

Systems built with AI need someone who reads them.

Situation

  1. Attacks have become cheaper. What used to need a team is now done by a script with a language model: phishing in flawless German, password lists, scans around the clock.
  2. Software has become cheaper too. Anyone who can prompt a system together in an afternoon gets one that runs. Whether it holds, nobody says.
  3. Both hit the same businesses: small companies without a security staff of their own that still manage customer data, invoices and access.

Sectors

01 Security check

Assignment
Inventory: accounts and access, multi-factor, email and cloud, network and remote access, backups and their restoration, patch level.
Result
A report with an order of work: what comes first, what next, what can wait.
Limit
Reading and checking only. We change nothing before you approve it.

02 Hardening

Assignment
Implementation per the report: servers, remote access, network segments, backups with a restore drill, password management, device and account rules. Control systems and building technology too: configuration, remote access, software.
Result
Every measure approved individually, implemented and documented.
Limit
For the electrical installation, the terms on the Controls page apply. Qualification & limits

03 Review of AI-⁠built systems

Assignment
Code and configuration of applications built with AI tools: sign-in and permissions, tenant isolation, secrets, dependencies, browser protection, how language models are handled inside the product.
Result
A list of the weak points with evidence and a proposed fix, sorted by severity.
Limit
We read with the access you give us. We do not attack a running system.

04 Advice and emergency plan

Assignment
Rules for everyday work, training against phishing, an emergency plan: who calls whom, what is switched off first, where the backups are.
Result
A plan that can hang on the wall.
Limit
In a real incident, forensics and the authorities take over. We prepare, we do not investigate.

Dispatch

This page, checked in the build.

Content-Security-Policy
active
no third-party origins · checked in the build
Third-party requests
0
checked in the build
Own cookies
0
as in the colophon
Local entries
2
appearance, motion · as in the colophon

Assignment

Every job is carried out only on a system named in writing and only with the written authorisation of its owner. We do not carry out penetration tests or attack simulations. We defend.

Report

Own audit

As of 07/09/2026 · 0e8045a

  • 28/28 tables with tenant isolation, enforced by the database, fail-closed.
  • 1,596 automated tests green: 1,239 in the backend against a live database, 357 in the frontend.

Own infrastructure

Internal services are reachable only on the local network or via VPN. Backups are encrypted and the restore is rehearsed. No port of the internal services is open to the internet.

Report your situation

Write what you run and what worries you. You get an assessment, not a sales pitch.