Alpha inferno Avis 

7
TrustScore 3 sur 5

2,9

Bien que nous ne vérifiions pas les affirmations individuelles, car les avis reflètent l’opinion personnelle des utilisateurs, certains avis sont accompagnés du statut « vérifié » lorsqu’il est possible de confirmer qu’une interaction avec l’entreprise a eu lieu. En savoir plus

Pour protéger l’intégrité de la plateforme, chaque avis, qu’il soit vérifié ou non, est analysé par notre logiciel automatisé 24 h/24 et 7 j/7. Il identifie et retire tout contenu qui enfreint nos conditions d'utilisation, y compris les avis qui ne se basent pas sur des expériences authentiques. Nous sommes conscients que nous ne pouvons pas tout détecter, et vous pouvez nous signaler tout élément qui aurait pu nous échapper. En savoir plus


Coordonnées de contact

2,9

Moyen

TrustScore 3 sur 5

7 avis

5 étoiles
4 étoiles
3 étoiles
2 étoiles
1 étoile

Aucun historique récent de demande d’avis

Cette entreprise n’a pas récemment invité ses clients à l'évaluer, donc les avis ne sont peut-être pas représentatifs.

N'a pas répondu aux avis négatifs

Comment cette entreprise utilise Trustpilot

Découvrez comment les avis de l’entreprise sont collectés, notés et modérés.

2,9

Tous les avis

(7)

4 avis reçus au cours des 12 derniers mois

Écrire un avis

Nous vérifions les avis

Les entreprises sur Trustpilot n’ont pas le droit d’offrir des incitatifs ni de payer pour masquer des avis. Les avis reflètent l’opinion des utilisateurs et non celle de Trustpilot. En savoir plus

Noté 1 sur 5 étoiles

We ran the same checks back at them. They failed both.

My experience with this company is an unsolicited email exchange. They cold-emailed us two "Security Vulnerability Reports," both rated Critical, signed by a "Cyber Security Researcher" whose name appears nowhere on their own website. We did not buy anything.

We triaged both the way we triage any inbound report. Neither survived first contact.

No scope. No rules of engagement. No authorization. No prior relationship. That isn't research, it's a domain list and a free scanner, and not doing it is the first thing anyone in this field is taught.

The findings are passive DNS lookups. No active testing was performed, and they didn't conceal it: Report 02 lists our "Vulnerable Location" as a URL on somebody else's scanning website. They screenshotted a third-party tool and invoiced it as an assessment.

The technical content is worse than the methodology.

Report 01 asserts that a missing MTA-STS record allows spoofed mail from our domain. It does not. MTA-STS is transport security between mail servers. Sender authentication is SPF, DKIM and DMARC, all three of which we publish, all three of which were in the same DNS response they screenshotted. They inverted the threat model while looking at the evidence that contradicted them.

Report 02, on CAA records, is copy-pasted from 2017 press coverage and unedited. Still in the future tense: the requirement "goes into effect on September 8." That was September 8, 2017. It cites Symantec certificates being distrusted "until October 2018." Nine years stale, and nobody read it before sending.

Out of professional courtesy we ran the same checks back at them. Passive only, ninety seconds:

No CAA record. No MTA-STS. No DNSSEC. No Content-Security-Policy. PHP 8.0.30, which reached end of life in November 2023, so 32 months without security patches, serving a live storefront checkout. Registrant hidden behind a privacy proxy.

Both "Critical" findings they billed us for are absent from their own zone.

Their public website matches the standard of the reports. Every team bio on their published team page is lorem ipsum filler. Every testimonial on their site is attributed to the same name, listed as CEO of a company called "Company." Their published team page lists two well-known real figures from the security industry as staff, with the WordPress theme's stock demo images beside their names, one of which is reused four times for four different entries. Their credentials page is beginner course-completion screenshots with no verification links, including a blockchain mock exam presented as a certification.

They advertise $800 to $3,000 per issue and $10,000+ per audit.

Fundamentals: they cannot describe what a mail security protocol does, cannot read a DNS response they screenshotted themselves, and cannot patch a four-year-old runtime on their own storefront. The only tradecraft on display was the fake name in the signature block, and even that failed. If you get one of these, you are not being audited. You are being billed for a command someone else ran.

31 juillet 2026
Avis spontané
Noté 1 sur 5 étoiles

Spam

They sent beg-bounty spam to our client support email, raising a ticket and wasting our developer's time, overstating an issue as "critical" despite it being a low severity issue with no credible exploit.

7 juillet 2026
Avis spontané
Noté 5 sur 5 étoiles

A huge thank you to @Husnain Iqbal at…

A huge thank you to @Husnain Iqbal at Alpha Inferno Private Limited for spotting and reporting a critical vulnerability in our code! Your vigilance and expertise helped us strengthen our security, and we’re grateful for your commitment to keeping our product safe for all users.

7 octobre 2024
Avis spontané

L’expérience Trustpilot

Tout le monde peut écrire un avis Trustpilot. Les auteurs d'avis peuvent les modifier ou les supprimer à tout moment et les avis sont affichés tant que les comptes utilisateurs respectifs sont actifs.

Nous avons des personnes dédiées et des technologies intelligentes pour nous aider à protéger notre plateforme. Découvrez comment nous combattons les faux avis.

En savoir plus sur le parcours des avis sur Trustpilot.

Voici 8 conseils pour écrire des avis de qualité.

La vérification permet de s'assurer que des personnes réelles écrivent les avis que vous lisez sur Trustpilot.

Offrir des incitatifs en échange d'avis ou demander des avis de manière sélective peut fausser le TrustScore, ce qui va à l'encontre de nos conditions d'utilisation.

En savoir plus