Independent cybersecurity practice Pune, India / Worldwide

Offensive security. Assurance. Engineering.

Beyond
the breach.

We find the weaknesses.
Build the defences.
And stay until it holds.

Let’s talk security
Explore our practice / 01
See your systems through an attacker's eyes.
01 / The practiceClarity in a complex world

The strongest defence
starts with a different
point of view.

Security is technical. The consequences are human. We bring offensive testing, governance, legal insight, and engineering to the same table.

Offensive security

Think like the threat.

We follow the paths an attacker would take. Across your applications, APIs, infrastructure, and cloud, we turn exposure into evidence you can act on.

VAPTAPI & mobile securityCloud security

The Arica experience

Less explaining.
More exploring.

Orbit a connected security system. Follow an attack. Build a defence. See how the decisions change the outcome.

Enter the universe Or jump into the attack globe
Interactive security simulations15 labs / One connected practice
02 / Our approachFrom first question to verified fix

Finding it is
only the beginning.

What happens after the finding is what makes the engagement useful.

Start with the right questions.

Your systems, your business, your constraints. We agree on what matters, what we will test, and how we will work together.

What you leave withAn agreed scope and clear rules of engagement
03 / In practiceAll case studies

Where the work
meets the real world.

Independent AI security research · September 2026

Ten local model scans.
1,021 adversarial attempts.

We evaluated open-weight models on hardware we controlled using a 124-probe battery mapped to OWASP LLM Top 10 2025, OWASP Agentic, MITRE ATLAS, and NIST AI 100-2. The run produced 320 raw detector findings for analyst review.

Read the research note
10Model scans1,021Probe attempts320Raw findings
OpenAI logoOpenAIgpt-oss-20B
Qwen logoQwenQwen 2.5 · 3 · 3.5
Microsoft logoMicrosoftPhi-4
Meta logoMetaLlama 3.1 · 3.2
Mistral AI logoMistral AIMistral 7B
Google logoGoogleGemma 3 4B

Logos and names identify model families evaluated in this controlled run and are trademarks of their respective owners. Arica is not affiliated with or endorsed by these providers. We tested local model copies—not provider services or infrastructure. Results are specific to the tested versions, prompts, runtime, and harness; they are not universal model rankings.

04 / The peopleTechnical minds. Human judgement.

Different minds.
Shared resolve.

Testers, engineers, investigators, and legal minds. The people who find the problem work alongside the people who can help solve it.

Meet the Arica team
10Local AI Model Scans · Sep 2026
1,021Adversarial Attempts · Sep 2026
Top 10TryHackMe India · CTO

Before we begin

Good questions.
Straight answers.

01What should we send for an initial scope?

Start with the system or process, the deadline driving the work, and anything already known. We will turn that context into a practical scope before testing begins.

02How quickly will you respond?

We normally respond within one business day. For an active incident or urgent deadline, call +91 70911 75596 so the situation can be triaged faster.

03Will you help us fix what you find?

Yes. We provide evidence, remediation guidance, and ownership recommendations, with focused retesting where it is part of the engagement.

04Are the security labs live threat feeds?

Most labs are interactive simulations. The Internet Threat Observatory uses public SANS ISC/DShield reports with approximate IP geolocation; none of the experiences display customer telemetry.

05Can Arica issue an ISO 27001 certificate?

We support readiness, ISMS implementation, and audit preparation. Certification is issued independently by an accredited certification body.

The next move is yours.

Let’s make
it secure.

A system to test. An audit to prepare for.
A problem that doesn’t fit a box. Start here.

We normally reply within one business day.