Monthly
from €1,999
per month, excl. VAT
Monthly testing and a comprehensive findings update.
For stable applications with few changes to the external attack surface.
I build and operate platforms, bring AI applications into production and investigate security weaknesses. From Kubernetes and custom agent frameworks to external pentests and reverse engineering. Working with your teams, not apart from them.
Two starting points, the same operational experience. Choose whether you need to build and operate systems or test their external security.
AI-assisted external pentests with expert review of findings and collaboration with operations.
Kubernetes, SRE and Claude adoption. From platform architecture to production AI applications and their security controls.
These three packages cover recurring, AI-assisted pentests of your internet-facing systems. Monthly, weekly or daily, with expert-reviewed findings and time with your operations team. Your changes and risks determine the right cadence, not the biggest package.
from €1,999
per month, excl. VAT
Monthly testing and a comprehensive findings update.
For stable applications with few changes to the external attack surface.
from €5,999
per month, excl. VAT
Weekly testing and an updated findings report.
For product teams shipping regular releases, new APIs and ongoing changes to internet-facing systems.
from €9,999
per month, excl. VAT
Daily testing and an updated findings report.
For high-output startups, enterprises and critical infrastructure with frequent changes or critical exposure. Otherwise, monthly or weekly is usually enough.
Personal assessment, a prioritized report and agreed ticket handover. Time with operations, remediation support and knowledge transfer to help your teams improve security workflows across the organization.
All packages include retesting of remediated findings within the agreed scope and during the active contract term.
All prices are starting prices. The final monthly fee depends on the number and extent of the agreed scopes and may be higher. Your quote confirms the binding price. Systems, methods, testing windows and communication channels are defined before work starts. The cadence describes the agreed testing and report updates.
Three suitable AI models. Your real tasks. A defensible decision on quality, latency and cost — vendor-neutral, with documented results.
Model comparison on your dataThe metric that matters
Cost per usable result.A lower token price only helps when the model meets your task’s quality requirements. That is what we measure.
#2 VDP Security Researcher Germany
Event listingLead/Sole Engineer. Rebuilt and operated the FreeBSD platform end to end in Go, before its sale to eBay.
Technical referenceSeven projects from Franz Bettag’s work: the problem, his role, architecture and results with evidence.
Review PDF items, quantities and complete descriptions with source evidence. Controlled, schema-validated X83/X84 export.
Convert PDFs and images into reviewable article data. Vision model, JSON schema and DATANORM export with human review.
AI-assisted security research with multiple model families and separate verification phases. #2 VDP researcher in Germany, January–March 2026.
Elixir library for LLM Responses/Chat Completions orchestration, streaming and deterministic record/replay tests.
AI-assisted, read-only Kubernetes insight through an authenticated in-cluster agent.
Source-linked hacker conference badge catalogue with an AI-assisted editorial workflow.
Evidence-linked reset alerts for AI usage limits on a NO/MAYBE/YES scale.
Focused engagements with clear deliverables. Every sprint starts with an NDA and ends with a written report.
Claude, Claude Code, agent workflows, evals, governance, and security controls for teams that want production value instead of another AI pilot.
Architecture review, load-test analysis, and a prioritized roadmap for your next 10x growth milestone. Deliverable: Written assessment with cost-impact matrix.
Cluster security audit, GitOps pipeline, observability stack, and runbook creation. Deliverable: Hardened cluster config + incident response playbook.
From prototype to production: prompt engineering, RAG pipelines, cost optimization, and monitoring. Deliverable: Production-grade AI pipeline with guardrails.
OWASP Top 10 for LLMs audit, prompt injection testing, data exfiltration analysis, and output validation. Deliverable: Threat model + remediation plan.
Ranked #2 on the German HackerOne Vulnerability Disclosure Program leaderboard.
Learn moreDeveloping and applying AI-assisted techniques for vulnerability discovery at scale across web, mobile, and API targets.
Practical security framework based on OWASP Top 10 for LLMs, covering prompt injection, data poisoning, and model denial of service.
Active contributor to security tooling and responsible disclosure. GitHub profile (@fbettag) linked in header.
Timezone-flexible, async-first, NDA upfront.
We clarify your situation and the most important technical risks. The price includes follow-up and concrete first steps.
Focused 1-4 week engagement. I embed with your team, review code and infra, and execute hands-on improvements.
Written report with findings, architecture diagrams, runbooks, and a prioritized action plan you own.
Optional retainer for continued advisory, incident response, and quarterly architecture reviews.
Franz is a rare gem in the industry—someone you hope to find but seldom do. He is exceptionally reliable, efficient, and thoughtful. His communication skills surpass those of any other developer I've encountered. Franz genuinely cares about his craft and the quality of work he delivers. Both developers and clients are consistently amazed by his ability to produce high-quality work at an impressive speed, often referring to him as a "machine."
Since we started working with Bettag Systems in 2018, we're always happy for the continued insights and improvements they are providing to our IT infrastructure and projects.
Out of the box thinking and a out of the norm approach to IT is what we love about Bettag Systems. They are always there when we need them, and they are always providing us with the best solutions.
We are getting Consulting from Bettag Systems for over a year now, and we are very satisfied with the improvements our IT is making. It's not cheap, but it's worth it.
Tell me about your project. Together we will identify the right starting point for platform, AI or security work.