Offensive security that finds exploitable weaknesses before adversaries do.
SubZeroSec was founded in 2026 on a simple conviction: most organizations learn how they are breakable only after they have been breached. We exist to deliver that lesson safely and early - by attacking your systems the way a real adversary would, before a real adversary does.
SubZeroSec is an offensive security firm. We intercept vulnerabilities on the path to becoming zero-days - through VAPT, red teaming, threat hunting, OSINT and attack surface analysis - so a breach never happens.
The name is the thesis. A zero-day is a flaw no one is defending yet. We work to get below zero - to intercept exposure on the path to becoming a zero-day, while there is still time to fix it quietly. That is what Before Zero. Beyond Breach. means.
Every engagement is run by operators who compromise systems for a living, reproduced by hand, and proven with a working exploit. No theoretical severity, no scanner noise - just an honest, ranked picture of where you are actually breakable and a clear path to closing it.

Regulated, high-target environments where a breach carries outsized operational and regulatory consequences.
Fraud, account takeover, and transaction abuse.
Patient data, connected devices, and ransomware exposure.
Nation-state adversaries and critical infrastructure.
Supply-chain, source code, and cloud-native risk.
Signaling, subscriber data, and network core.
Saad co-founded SubZeroSec to put offensive security within reach of organizations that can't afford to learn from a breach. He still reads every critical finding before it reaches a client.
Subhan co-founded SubZeroSec and leads the technical practice - setting the bar for every engagement across application security, cloud, and the messy seams where they meet.
Book a scoped assessment - we will map what is reachable, prove what is exploitable, and give you a ranked path to closing it before someone finds it first.
Book a free scoping call