Fenko Security

About Us

AI security, offensive testing, and security products from New Zealand.

Who We Are

Fenko Limited is a New Zealand security company working across AI security, offensive testing, and security products.

We build and test systems where AI, software supply chains, and real-world security overlap. That includes penetration testing through Foxhound, extension intelligence through RiskyPlugins, passive DNS tooling through dnsmonster, and consulting work for teams building or deploying AI systems.

Our Philosophy

The name Fenko is a twist on “Fenek,” referring to the Fennec fox. Native to the desert, the Fennec fox is known for its oversized ears, which allow it to hear prey moving underground. It is small, agile, and hyper-aware of its environment.

That maps cleanly to how we work. We pay attention to weak signals, test assumptions directly, and look for the failure modes that are easy to miss when a system is moving fast.

What We Stand For

We are strongest where security work needs both engineering depth and practical judgement: AI system reviews, prompt injection testing, agent architecture, extension risk, cloud and application testing, and the workflows around remediation.

AI made it cheap to generate security findings and expensive to check them. Most of the market quietly hands that checking cost to the customer: run an inexpensive model, export everything it produces, and call the length of the report value. We’re built the other way around. You pay for findings that hold up; whatever junk our agents generate along the way is ours to deal with, not yours to triage.

That one decision does a lot of work for you. Downgrading to cheaper models to widen our margin stops making sense, because the extra noise lands back on our desk. Cutting false positives at the source becomes engineering we benefit from directly. And research that makes the agents more efficient pays out on both sides of the table at once, so we never stop doing it.

Your security comes before our convenience. That sounds obvious until it costs something: a finding that embarrasses a product we like, an engagement we turn down because we’re not the right fit, a deadline that slips because the testing wasn’t finished. We take the cost. The alternative is a security company whose reports you have to second-guess, and there are enough of those already.

We hold the engineering to a high bar because security advice from people who can’t build things is guesswork with a letterhead. Everyone here writes code, runs infrastructure, and maintains tools that other people depend on. When we tell you a fix will work, it’s because we’ve built the thing we’re asking you to change.

Security work runs on trust, and we try to earn it the boring way: by being straight with people. We’re honest about what we can do, what we can’t, and what the risks actually are. When a finding matters, we show the evidence. When it doesn’t, we say that too.

The same rule covers our own tools. We built Foxhound and we still won’t claim automation covers everything. If a tool, ours included, is the wrong answer for your problem, we’ll say so and point you somewhere better.

And we keep learning in public. AI and security both change monthly, so we run experiments, publish what we find on the blog, and update our methods when the evidence says we’re behind. A security company that stopped learning two years ago is testing you against two-year-old attackers.

How We Think About AI

We build AI that attacks things. Foxhound runs autonomous agents against real infrastructure, which is exactly the kind of system people are right to be cautious about. So the controls are not an afterthought: every engagement is scoped and authorised in writing before an agent touches anything, agents operate inside boundaries a human set, and humans review what they produce. Findings ship with evidence. An agent that can’t show its work doesn’t get to make claims.

The same discipline applies to the AI we consume. Every model and provider we use is registered internally and rated by how much we trust it, and that rating decides what data it is allowed to see. Client data never goes to experimental models or to providers we lack contractual terms with. Inference runs through a gateway we control, so we log usage (metadata, not your data), can cut a provider off quickly, and know which model saw what.

We operate under the New Zealand Privacy Act 2020 and are working towards ISO 27001 certification. The paperwork matters less than the habit behind it: decide what a system is allowed to do before it does it.

Our Products

We build Foxhound, the workflow and delivery platform behind our penetration testing practice. Foxhound gives clients a single portal to track engagement progress, review findings as they’re published, inspect evidence, and download reports.

We are also the creators of RiskyPlugins.com, a platform for analysing the security posture of browser extensions, IDE extensions, and AI-adjacent plugins. Third-party extensions are a supply-chain problem. RiskyPlugins gives teams a way to inspect that risk before software is installed across an organisation.

dnsmonster is our open-source passive DNS capture and indexing project. It is built for teams that need visibility into DNS traffic from network capture, PCAP, or dnstap sources. The source now lives under FenkoHQ/dnsmonster.