Both Directions
Fenko exists because AI broke security in two directions at once, and both need the same people.
One direction is AI used for security. Autonomous agents that test infrastructure, read code, and chase a finding until it holds up or falls over. That work used to be rate-limited by how many testers you could hire. It is not anymore, and the companies that understand that first will find their own bugs before anyone else does.
The other direction is security applied to AI. Every company is now shipping systems that take instructions from text they do not control, call tools on a user’s behalf, and hold context they should not leak. The old testing playbook has nothing to say about any of it.
Most security companies pick one. Doing only the first makes you a tool vendor who has never had to defend the thing you are selling against. Doing only the second makes you an advisor writing about attacks you have never run. We do both because each one teaches us how to do the other. The agents we build to attack clients’ systems are the reason we know where agents break. The AI security reviews we run are the reason our own agents are built the way they are.
Who We Are
Fenko Limited is a New Zealand security company. Penetration testing runs through Foxhound. Extension and supply-chain risk runs through RiskyPlugins. Passive DNS runs through dnsmonster. The rest is consulting for teams building or deploying AI systems.
Everyone here writes code, runs infrastructure, and maintains tools other people depend on. Security advice from people who cannot build things is guesswork with a letterhead. When we say a fix will work, it is because we have built the thing we are asking you to change.
What We Stand For
AI made it cheap to generate security findings and expensive to check them. Most of the market quietly hands that checking cost to the customer: run an inexpensive model, export everything it produces, and sell the page count as value. We are built the other way around. You pay for findings that hold up. Whatever junk our agents produce along the way is ours to clean up, not yours to triage.
That single decision keeps us honest. Downgrading to a cheaper model to widen our margin stops making sense, because the extra noise lands back on our desk. Killing false positives at the source becomes engineering we benefit from directly. Research that makes the agents more efficient pays out on both sides of the table at once, so we never stop doing it.
Your security comes before our convenience, which sounds obvious until it costs something: a finding that embarrasses a product we like, an engagement we turn down because we are the wrong fit, a deadline that slips because the testing was not finished. We take the cost. The alternative is a security company whose reports you have to second-guess, and there are enough of those.
The same rule covers our own tools. We wrote Foxhound and we still will not pretend automation covers everything. If a tool, ours included, is wrong for your problem, we will say so and point you somewhere better.
We also keep learning in public. AI and security both move monthly, so we run experiments, publish what we find on the blog, and change our methods when the evidence says we are behind. A security company that stopped learning two years ago is testing you against two-year-old attackers.
How We Run It
Foxhound points autonomous agents at real infrastructure, which is exactly the kind of system people are right to be nervous about, so the controls are not bolted on afterwards. Every engagement is scoped and authorised in writing before an agent touches anything. Agents work inside boundaries a human set. A human reviews what they produce. Findings ship with evidence, and an agent that cannot show its work does not get to make claims.
The AI we consume gets the same treatment. Every model and provider is registered internally and rated by how far we trust it, and that rating decides what data it is allowed to see. Client data never reaches experimental models or providers we have no contractual terms with. Inference runs through a gateway we control, so we can log usage (metadata, not your data), cut a provider off quickly, and say which model saw what.
We operate under the New Zealand Privacy Act 2020 and are working towards ISO 27001. The paperwork matters less than the habit underneath it: decide what a system is allowed to do before it does it.
Our Products
Foxhound is our AI-enabled penetration testing platform. It automates approved assessment steps inside your scope, with a tester approving active testing and signing off findings before delivery. Clients get a portal to track progress, read findings as they are published, inspect the evidence, and download reports.
RiskyPlugins analyses the security posture of browser extensions, IDE extensions, and AI-adjacent plugins. Third-party extensions are a supply-chain problem, and RiskyPlugins gives teams a way to inspect that risk before software lands across an organisation.
dnsmonster is our open-source passive DNS capture and indexing project, built for teams that need visibility into DNS traffic from network capture, PCAP, or dnstap. The source lives at FenkoHQ/dnsmonster.
About the Name
Fenko comes from “Fenek”, the Fennec fox. It lives in the desert and its oversized ears pick up prey moving under the sand. Small, fast, and tuned to signals nobody else hears. We liked it enough to put it on the logo.