Independent security auditing for Roblox

I find what an attacker would find — before they do — and hand you the fix.

Independent security audits of Roblox experiences, black-box or white-box: exploitable remotes, server validation gaps, and economy abuse. You get a severity-ranked report, a fix for each finding, and a reproduction you can run yourself.

26confirmed findingsacross commissioned audits

8audits delivered

7
high
11
medium
8
low

How an audit runs

Two ways in, one path to the fix

Black-box

You give me the place link

I approach the game like an attacker would — instance dump and live remote capture on the running experience, with nothing but what any player can reach.

White-box

You hand me the files

Faster and more thorough — I read the actual scripts you share, including server logic a black-box pass can't see. You stay in control of what you disclose.

both feed the same pipeline

  1. 01

    Static

    Map remotes, replicated logic, value stores and IDs.

  2. 02

    Harness

    Build a bounded probe per hypothesis — one shot, no farm loops.

  3. 03

    Reproduce

    Confirm each finding live, measured against server state.

  4. 04

    Report

    Severity-ranked findings, a fix for each, a demo you can run.

Think your game has holes?

Send the place and what worries you. I'll take a first look and tell you honestly whether an audit is worth your time.

Request an audit

reports stay private · findings are never published while open