Business Logic Analysis
We go beyond automated scanners to find vulnerabilities in your application's business logic — the flaws that matter most.
Since 2003, Berghem has operated in critical environments, combining adversarial expertise, business logic and new artificial intelligence capabilities.
Two decades of offensive security, audited and reproducible.
Continuous operation in offensive security since 2003.
Documented engagements with reproducible evidence.
Financial services, healthcare, government, technology and retail.
Pentest, red team, AI, compliance, DevSecOps and IR.
Operations in Latin America and Europe via Berilo.
Berghem was built on a single conviction: the best defense starts with a deep understanding of offense. From day one, our focus has been on offensive security — finding vulnerabilities before attackers do. Our roots are in the financial sector, where over 80% of our historical work has been dedicated to securing payment systems, core banking platforms, and fintech infrastructure for major institutions across the globe. Today, Berghem is at the forefront of AI security, developing AI pentesting methodologies, mission-oriented security agents, and AI-powered risk management frameworks. Our European subsidiary, Berilo, brings this expertise to the European market with GDPR-first methodology.
We go beyond automated scanners to find vulnerabilities in your application's business logic — the flaws that matter most.
20+ years securing payment systems, core banking, and fintech for major financial institutions worldwide.
Pioneering AI security services and autonomous security agents powered by multi-model architecture technology.
Our AI-powered Vendor Risk Management framework automates third-party security assessments.
The names that sign every report.
Four profiles, one operation. Decades in pentesting, AI research, delivery and culture — signing every engagement end to end.
Founder of Berghem with over 25 years of experience in information security and technology management. Matteo established Berghem as a reference in ethical hacking and offensive security, building the company from the ground up into a trusted partner for major banks and financial institutions across the globe.
With deep experience in red team, pentesting and adversarial simulation, he leads a team dedicated to raising the defensive maturity of organizations in regulated, high-criticality environments — combining technical rigor, business reading and a commitment to measurable results.
Gislaine leads Berghem’s talent management strategy, organizational development, and the strengthening of a culture of continuous learning, in a market highly competitive for professionals specialized in offensive security.
Beyond her work in people management, she is also responsible for overseeing projects for large enterprises, connecting business needs to human development and delivery excellence.
Seasoned cybersecurity professional leading Berghem's security operations and service delivery. Raphael oversees the execution of penetration testing engagements, red team exercises, and security assessments for enterprise clients. With extensive experience in offensive security and project management, he ensures the highest quality and consistency across all client engagements.
Responsible for ensuring methodological consistency, on-time delivery and quality across all projects, he leads coordination between offensive teams and client interlocution, sustaining the level of technical excellence that defines Berghem's reputation in critical, regulated environments.
Cybersecurity researcher leading Berghem's AI security practice and the development of Berghem Agents. Specializes in offensive security, AI/LLM vulnerability research, and multi-model architecture development. Has authored thousands of penetration testing reports for major financial institutions worldwide, and leads the European operations through Berilo S.r.l.
Author of thousands of pentest reports for financial institutions, he has consolidated a high-density technical track record in critical and regulated environments. He also leads the group's European operations at Berilo S.r.l., extending Berghem's standard to the international market.
Clear principles and verifiable evidence guide every mission, every claim and every decision.
The investigation starts from what sustains the organization.
Claims, results and demonstrations must be reproducible.
AI amplifies capacity; judgement and accountability remain human.
Autonomy, data and access are defined according to risk.
Berghem develops specialized models from open-weight models and combines different execution options according to task, confidentiality and environment.
CPT, adaptations, evaluations and versioning on controlled infrastructure or contracted compute capacity.
Berghem models, private models, authorized third parties, or served inside the client's own tenant.
Ready to strengthen your security posture? Let's discuss how Berghem can protect your organization.
Get in Touch