About Us
Breaking It for the Better
TrustFoundry is a penetration testing firm, and that is all we do. Founded in Overland Park in 2014, we test the way an attacker would and write findings the person fixing them can act on.
Our Story
Alex Lauerman started TrustFoundry in Overland Park in 2014, seven years into a career as a penetration tester, to do one thing: manual testing without the scan-and-template shortcuts that were becoming normal.
Since then we have assembled a team of experienced security consultants who have tested everything from Fortune 500 financial platforms to startup mobile applications, from complex Active Directory environments to multi-account cloud environments.
We then went further: we built our own proprietary penetration testing management platform from the ground up. With 500+ curated finding templates, automated discovery pipelines, and AI-assisted quality review layered on human peer review, our platform ensures every assessment is thorough, consistent, and delivered with a full audit trail.
The result? Our consultants spend their time finding vulnerabilities, not fighting with Word formatting. And our clients get higher-quality reports, faster.
Our Mission
Find what an attacker would find, and make it easy to fix
We test the way an attacker would, write each finding so the person fixing it can reproduce it without calling us, and stay on the engagement until the retest passes. That is the whole job. Everything else on this page exists to do that job the same way every time.
The People Behind the Work
Meet the Team
Around ten penetration testers and the small team around them. Certifications across the practice include OSCP, OSWE, BSCP, CRTP, CRTO, CREST CRT and GIAC. One consultant ranks in the top 1% on HackerOne and Bugcrowd, another is a published CVE author on the Microsoft MSRC leaderboard, and the founder started SecKC. Click a name for the full bio.
What Drives Us
100% Focused on Pentesting
We do not do GRC, SOC monitoring, or managed security. Penetration testing is all we do.
A second consultant signs every report
Every finding is peer reviewed before delivery, against 500+ curated templates so severity and remediation language stay consistent. An AI pass checks for typos, gaps and severity mismatches after that human review, not instead of it.
Client Relationships First
Lasting client relationships don't happen by accident. We communicate proactively, explain findings clearly, and stand behind our work.
We built our own tooling
Hexecution exists because Word templates and spreadsheets were eating testing hours. Automated discovery, the finding library and report generation live in one system we maintain ourselves.
Real-World Attack Simulation
Our consultants think like attackers. We simulate real threat scenarios, not just run automated scans and call it a pentest.
Why TrustFoundry
Why Organizations Choose Us
The techniques are published
Our consultants write up what they use on engagements: Kerberos attack chains, AD CS abuse, browser exploitation primitives, DNS tunneling C2. Forty-nine posts on the blog, and CVEs and vendor disclosures to Microsoft, Apple and Mozilla among others.
Platform-Powered Quality
Every assessment is backed by our proprietary PTaaS platform: automated discovery, AI-assisted quality review, 500+ curated finding templates, and structured peer review workflows.
Transparent Communication
Weekly status updates, real-time escalation of critical findings, and detailed reports that non-technical stakeholders can understand. No black-box assessments.
Competitive Pricing
Because our platform makes consultants more efficient, we deliver comprehensive assessments at price points that surprise clients used to enterprise vendor quotes.
Evidence your auditor can trace
Who tested what, when it was approved, when it was fixed and who verified it, kept as a field-level changelog. When a SOC 2 auditor or a PCI assessor asks in month eleven, the answer is an export rather than an email search.
Remediation Partnership
We don't disappear after delivering the report. End-to-end retest workflows, JIRA integration, and ongoing support help you actually fix what we find.
What Clients Say
“Very responsive and knowledgeable team. We have been working with TF and find that the service provided is best in class.”
“We have worked with other pentesting firms that ran scans and outputted a report with little manual exploit effort. TrustFoundry walked us through their processes and was able to intelligently speak to the risk and impact for each finding.”
“Great communication, technical knowledge was awesome, integrated to our team seamlessly. We had a few different vendors who were not necessarily responsive, and did not have an in-depth penetration testing capability.”
“The TrustFoundry team is extremely knowledgeable, professional, and responsive. The reports were well written and testing thorough. Weekly status updates and escalations of critical findings were also great.”
Want This Team On Your Side?
Tell us what you need tested. We'll scope the engagement and walk you through how we run it.
Join Our Team
We're always looking for talented security professionals who are passionate about penetration testing. These positions are some of our common roles, but please reach out if you think you may be a good fit for a position that is not posted.
You would also be testing on Hexecution, the platform we build in-house: automated discovery, a finding library instead of copy-paste, and reports generated in seconds. Less of your week spent fighting Word, more of it spent testing.
Penetration Tester
Mid-level to PrincipalTrustFoundry is looking for an experienced penetration tester with a primary focus on application testing, with additional experience in infrastructure penetration testing. We are a small, specialized penetration testing company based in Kansas City. At TrustFoundry, you'll spend your time hacking, solving interesting problems, and collaborating with talented security professionals.
Perks
- Work from home
- Flexible work environment & schedule
- Unlimited PTO
- Training & Conferences
- Medical and Dental benefits (US FTE)
- Culture that supports employee development
- Work with a high-quality team
Requirements
- Complex application pentests across web technologies
- Well-rounded skillset: networks, cloud, red team, mobile
- Clear, professional report writing & presentation skills
Nice to Have
- Lead pentests from scoping to final delivery
- Published research, CVEs, or open-source tools
- Security certs (OSCP, OSEP, OSWE, BSCP, etc.)
- CTFs, security projects, or community involvement
Why TrustFoundry?
Get to work with a group of ~10 pentesters that love all aspects of hacking. We are the right size for collaborating closely and learning. We typically work with good customers and take on a fair amount of complex or challenging projects, which are fun to work on. It's a great place to sharpen your hacking skills and better yourself. We have a very efficient platform, making report writing much easier. Also, we are flexible, so if you want a lot of R&D time, CTF time, vacation, or something specific, we can generally make that work!
Apply: [email protected]