Packers, obfuscation, native libraries, anti-tamper — taken apart and tested, not scanned. We also cover Web3 smart contracts, IoT firmware, and automotive ECU systems, backed by 45assigned CVEs across APAC's most critical infrastructure.
Singapore-based. Scope and fixed fee agreed in writing before work begins — 50% on signing, 50% within 30 days of delivery. Engagements run 5–10 business days against the agreed scope.
We reply within one business day. Mutual NDA before any scoping call — we sign yours or ours.
Scoped per target, not per seat. Engagements are procurement-led: NDA, scope letter and a signed rules-of-engagement precede any testing. Findings ship with reproduction steps, working PoC, and a disclosure path your counsel can review.
17 zero-days across 9 vehicle-platform projects, 16 of them MITRE-assigned. Presented with full reproduction detail and vendor-coordinated timelines.
One principal architect owns the engagement end to end — no junior handoff, no offshore triage.
A proprietary security LLM triages against a 50M-line analysis corpus before manual exploitation begins.
Findings ship with reproduction steps, working PoC, and a disclosure plan your counsel can review.

Independent security researcher with 45 assigned CVEs across automotive, IoT, and AI systems. Author of the Hyperlane ISM analysis, ERC-4337 paymaster drain research, and the Kelp DAO LayerZero forensic report.
Engagements are led personally by Feng Ning and run on Innora's own tooling — a domain-specialized security LLM and a 50M+ line analysis corpus — the same pipeline behind the published CVE record. This is a principal-led practice, not a body shop: capacity is deliberately limited so every engagement gets that depth.
Full-depth reverse engineering and adversarial security assessment of a single Android application or website, aligned with OWASP MASVS and MASTG. Static plus dynamic analysis combining AI-assisted decompilation, unpacking and deobfuscation with runtime instrumentation and backend API testing.
Engagements are priced per target from $50,000 to $800,000 USD, delivered in 5–10 business days. Scope and final fee are confirmed in writing before work begins.
Per single target. Final fee is quoted after scoping — hardening (packing, obfuscation, native code), backend API surface and required testing depth set placement in the range.
Independent analyses of production applications, published in full. These were not client engagements — the methodology and the evidence are public so you can evaluate both before you commission anything.
Complete mathematical reverse engineering of a commercial-grade obfuscator: Mersenne Twister PRNG recovery, 3-plane Unicode dispatch, 18 operator identities.
Read full analysis →MD5/RSA-1024 signing certificate still in production use; 28 RSA private keys recovered from public certificate data via Batch GCD.
Read full analysis →Trust-all TrustManager reached through Frida instrumentation, defeating certificate validation on a production banking application.
Read full analysis →Recovering decrypted code from hardened, packed applications that defeat conventional static analysis and gadget injection.
Read full analysis →function test_ISR001_ReentrancyDrain() public {
AttackerContract attacker = new AttackerContract(address(vault));
vm.deal(address(attacker), 1 ether);
attacker.attack();
// [REDACTED] — full exploit withheld until patch confirmed
assertGt(attacker.profit(), 0, "drain confirmed");
}Illustrative sample. Real reports include full Foundry PoCs, remediation guidance, and a fix-verification round. Protocol name redacted per NDA.
All work below is independent research conducted on our own initiative — not client engagements. Client findings are confidential and never published. Every methodology claim on this page is backed by public evidence you can read and reproduce before you commission anything.
17 zero-days across 9 vehicle-platform projects, 16 of them MITRE-assigned CVEs, with vendor-coordinated timelines.
Complete mathematical reverse engineering of a commercial-grade obfuscator, recovering protected string constants at a 72.7% decryption rate across the sample set.
Study of the application signing and integrity chain, documented with 15 proof-of-concept attack scenarios against the verification path.
Protocol-level analyses of a liquid-restaking system, a cross-chain messaging layer, and the account-abstraction standard — $292M+ at-risk reviewed.
Reverse engineering and security assessment of a single APK or website is priced from $50,000 to $800,000 USD per target, delivered in 5–10 business days. Placement in the range is driven by hardening (packing, obfuscation, native code), backend API surface, and the depth of adversarial testing required. Web3 smart contract, IoT firmware, and automotive ECU engagements run $20,000 to $500,000 on the same delivery window. Every fee is fixed in writing before work begins — 50% on signing, 50% within 30 days of delivery — aligned with MAS TRM guidelines for Singapore-based teams.
Every engagement runs the same five steps. Scope and fixed fee are agreed in writing before any work begins.
Send your target and scope. We reply within one business day and hold a scoping call under mutual NDA, then issue a written proposal with fixed fee and delivery date.
50% is invoiced on signing to reserve your delivery window. Work begins immediately — no long sales cycle.
AI-assisted teardown across the full attack surface, with manual expert review of every finding — no unvalidated tool output ships.
Full report within 5–10 business days: reproducible PoC for every Critical and High, plus one fix-verification round after your patch cycle.
The remaining 50% is due within 30 days of delivery — wire or USDC. Client findings stay confidential and are never published without consent.
APK, website, Web3, IoT or automotive — send us the target and the questions you need answered. We reply within one business day and schedule a scoping call under mutual NDA. A written proposal with fixed fee, workplan and deliverable schedule follows.
security@innora.ai · innora.ai/audit · @Innora_sg
Engagements are contracted under a written statement of work covering scope, deliverables, milestones, confidentiality, liability and termination. We can execute on your paper and support vendor onboarding and third-party risk review.