One partner for the three things modern businesses can't afford to get wrong: managed IT & cybersecurity, AI integration & management, and offensive security testing. We pen-test the systems most teams ship untested, run your IT and defense day to day, and build, integrate, and manage AI the right way — because we build and self-host our own in-house. Verified work, proven on our own hardware, reported in plain English.
Selected engagements — one published with the client's permission, the rest under NDA — plus independent recognition. Capability shown on results.
Cross-tenant authorization (IDOR/BOLA) tested in both directions and across both token transports; a full SSRF bypass ladder; stored XSS; database row-level security; OAuth. Manual, positive-control verified, end to end.
Result: no exploitable vulnerabilities identified — two non-exploitable hardening notes reported.Real engagements against production systems across the full offensive spectrum. Client identities and data are withheld under NDA; the technical approach is shown.
Use-after-free and heap primitives developed into remote code execution against compiled services.
SSRF-to-internal-service chains, Host-header vhost routing, package-registry abuse to code execution.
Static and dynamic analysis of compiled binaries to recover logic, keys, and hidden validation.
Attacks on flawed constructions — hash-collision abuse and broken cipher schemes.
Packet-capture analysis, file carving, and layered-archive and protocol reconstruction.
Logic-analyzer signal decode and industrial-protocol analysis against embedded and OT targets.
Independent research on a live multi-tenant marketplace (public program): recon, API-surface mapping, SSRF testing; a valid vulnerability responsibly disclosed.
Beyond client work, offensive skill is validated publicly on Hack The Box. On the "CTF Try Out": 36 of 37 scenarios solved · global rank #93 · 34,100 points. On the MCP Try Out: a 31-solve sweep across all eleven categories for 25,000 points · global rank #39 of 300 teams — binary exploitation, web, reverse engineering, cryptography, forensics, hardware, ICS, blockchain, coding and more. Full profiles & badges available on request.
Three practices, one partner: offensive security, managed IT & cybersecurity, and AI integration & management — for startups and SMBs that want it handled, not juggled.
Full-scope assessment aligned to the OWASP Top 10: access control, authentication and session, injection, SSRF, business-logic flaws, and misconfiguration.
REST and GraphQL testing against the OWASP API Security Top 10: object- and function-level authorization, cross-tenant access, mass assignment, rate-limit gaps.
A new trust boundary most teams ship untested: MCP servers, agent tool-use, and LLM-connected apps — tenant isolation, prompt and tool-call abuse, output handling.
Your outsourced IT department: endpoint management and patching, backups and recovery, email and identity, network and helpdesk — kept current, monitored, and supported so your team can work.
Ongoing defense, not a one-off scan: EDR, log and alert monitoring, vulnerability management, patch governance, and incident response when something does get through.
Configuration baselines, policy, and audit-readiness mapped to NIST, CIS, and SOC 2 — hardening the systems you already run and keeping the evidence your customers ask for.
Put AI to work inside your business: LLM assistants, RAG over your own documents, agentic automation, and tooling wired into the apps and workflows you already use — scoped, secured, and actually useful.
We build and run our own AI stack — self-hosted models, GraphRAG memory, GPU compute, agent harnesses — on in-house hardware with in-house code. We stand the same up for you: private, on-prem, no data leaving your walls, no per-seat SaaS bill.
Run it for you long-term: model updates and evals, guardrails and prompt-injection defense, token-efficiency and cost control, monitoring and uptime. Your AI, maintained — without an ML team on payroll.
A defined piece of work — a pen test, an AI integration, an IT or security buildout — with clear deliverables, a prioritized report, and a debrief.
Ongoing managed IT, security monitoring, and AI operations for a flat monthly fee. We keep it running, patched, defended, and improving.
Re-test after fixes, recurring assessments as you ship, and on-call expertise for the security and AI decisions in between.
Disciplined, authorized, and documented end to end. No test packet leaves without written scope.
Exact targets, windows, and constraints defined in a signed SOW.
Rules of Engagement signed before any testing begins — your legal shield and mine.
Manual assessment across the agreed surface. Critical findings reported out-of-band within hours.
Every finding reproduced with a positive control. No scanner-only claims.
Prioritized report, debrief call, and a re-test after you fix. Attestation on request.
Application security is the day job. The record proves depth across the whole offensive stack — the instinct that finds the bug a checklist misses.
Thirty-one real-world systems taken end to end across all eleven disciplines — production-grade environments with the same stacks, defenses, and bugs as live targets. Each driven from first access to full compromise — not a scaled-down exercise.
This is the depth of AI knowledge we bring to clients. What moves behind this page is our own GraphRAG "AI brain", engineered in-house from scratch — self-hosted memory, a custom tooling harness, and reasoning sessions fused into one living graph, hand-written on our own hardware with no SaaS behind it. We understand these systems because we build them end to end — and we put that expertise to work securing, auditing, and standing up AI for you. Shown as pure topology; contents, names, and client data never leave our machines.
Topology only — contents, identifiers, and client data withheld. Rebuilt from the live graph on every save.
Evidence of how deeply we know the stack — knowledge we bring to your systems. Real telemetry from infrastructure we engineered ourselves: a custom token-efficiency layer, local GPU compute, and our own knowledge graph. Measured on our hardware, built almost entirely on free and open tooling. No client or content data.
We know these models from the inside — and bring that to clients. The real embedding space behind our knowledge base and the encode→rerank pipeline that searches it: self-hosted open models on in-house GPUs, wired with our own code. The same understanding we apply to securing and building AI for you. Projected live from our own vectors; shape only, no contents.
Merriweather Holdings is a managed IT, cybersecurity, and AI partner for startups and SMBs. We run and defend your IT day to day, pen-test the systems most teams ship without testing — web apps, APIs, and AI/MCP trust boundaries — and integrate, host, and manage AI the right way. We build and self-host our own AI infrastructure in-house, which is exactly why we understand how to secure and operate it for you. Every engagement is authorized and documented; every finding proven before it's reported. Hands-on expertise that earns its place on the result.
Tell us what you've built and what you're worried about. You'll get a scoped, fixed-price proposal — no obligation, no jargon.