ABOUT BLACK GHOST · CYBER SOVEREIGNTY
Brazil's digital defensemust remain under Brazilian control.
Black Ghost protects organizations today while developing national cyber-defense technologies to reduce external dependencies, safeguard strategic data and strengthen the country's digital resilience.
Technological dependence is also strategic dependence.
Brazilian companies, institutions and essential services depend on security technologies developed, operated and controlled outside the country. These solutions play an important role, but their availability, evolution, jurisdiction and continuity are not under national control.
Cyber defense is not only about stopping attacks. It is about preserving the ability to protect the country even when external vendors are no longer available.
Dependence on foreign technology
Essential components of digital defense remain subject to commercial, political and regulatory decisions made outside Brazil.
Strategic data
Sensitive information may be processed on infrastructure and artificial intelligence outside Brazilian jurisdiction, under rules that are not ours.
Critical infrastructure
Energy, telecommunications, healthcare and transport run systems whose unavailability has immediate physical, economic and social consequences.
Technological sovereignty
Without national research, products and professionals, the country remains a consumer of strategic technologies it neither controls nor can evolve.
Operational dependence risk
Critical defense cannot depend solely on the authorization, availability or commercial policy of third parties to keep working.
We started where the attacks start.
Black Ghost was born in offensive security. Before defending, we spent years understanding how attackers find and exploit real flaws: how a forgotten endpoint becomes an entry point, how a weak credential becomes lateral movement, how one configuration detail becomes full compromise.
Understanding how to attack was the first step to understanding how to build a better defense. That is not a tagline — it is why every architectural decision in our technology starts with the question "how would I break this?".
It is also what separates us from those who build security from a requirements document. We find the problems first. Then we build the answer.
From offensive security to security technology.
Each stage feeds the next. We skip none of them.
Operations, research, technology and capability building.
Operations
We work directly to protect companies, applications, networks, clouds and critical infrastructure through offensive and defensive services. It is what keeps us in contact with the real problem.
Research & development
We turn real operational challenges into applied research, automation and proprietary tooling. What hurts in the operation becomes an engineering priority.
National technology
We are building Brazilian cyber-defense infrastructure, with our own components for telemetry collection, analysis at the edge, detection and response.
Capability building
We develop Brazilian knowledge, processes and professionals capable of operating and evolving critical security technologies. Technology without people who master it is not sovereignty.
Protection for those who keep digital Brazil running.
Government & defense
Protection of public data, strategic systems and essential services under high requirements for secrecy, jurisdiction and continuity.
Critical infrastructure
Defense of energy, telecommunications, industry, transport, healthcare and other environments whose unavailability produces real consequences.
Strategic Brazilian companies
Reducing technological dependencies and strengthening the resilience of organizations responsible for large volumes of data and critical operations.
Technology & SaaS
Offensive and defensive security integrated into the development of Brazilian companies building the next generation of digital services.
Autonomy for Brazil to defend itself. And the principles we won't compromise on.
National technological autonomy
The ability to protect Brazil's strategic data and systems cannot depend solely on the decisions, jurisdictions and commercial priorities of third parties. We work to expand what the country actually controls.
Offensive knowledge in service of defense
We know both sides. We use the same logic an attacker uses to find flaws, but with a single goal: turning that knowledge into real prevention, detection and response.
Continuity over convenience
Critical defense must keep working even amid external restrictions, vendor unavailability or geopolitical change. We design for continuity, not dependence.
Absolute ethics, legality and confidentiality
We always operate within the law, with documented authorization and an NDA before any work begins. Full technical transparency with those who trust us; absolute discretion about what we find.
The specialists behind every operation.
Black Ghost was founded by specialists with complementary backgrounds: software engineering and ethical hacking. The rule is simple: no engagement is delivered without senior technical review.
João Vitor
Co-founder · Software Engineer
Software engineer with experience in government projects, having built systems used by Brazilian city governments (prefeituras and câmaras municipais) to manage laws and contracts affecting millions of citizens, bringing modernization to processes that previously existed only on paper. At Black Ghost, he oversees internal infrastructure, technical reporting, and the translation between offensive findings and remediation paths that engineering teams can actually execute.
Luís Felipe
Co-founder · Ethical Hacker
Ethical hacker who discovered critical vulnerabilities at major companies in the automotive and construction sectors. Previously served as technical leader of Discord's hacker team. At Black Ghost, he leads reconnaissance, pentest, and attack surface analysis operations, responsible for the offensive side of every engagement and the quality of what leaves our door.
The process. Transparent. Documented. No improvisation.
Scoping before pricing
No proposal is sent without a free 30-minute intro call. You don't get a number until we understand what we're going to test or defend.
Full contractual documentation
NDA, MSA, Statement of Work, and Rules of Engagement. All signed before any technical work begins. International standard.
Human operators in command
Automated tools are part of the process, but every critical finding is manually validated by a senior specialist.
Retesting included by default
Confirming your fix worked is part of the job, not an extra cost. The retest is part of the engagement.
Two reports per engagement
Detailed technical document for the engineering team and a one-page executive summary for the C-level. Nothing to translate on your end.
Technology sovereignty is security.
We are not seeking technological isolation. We are seeking autonomy: the ability to choose, integrate, replace and keep operating independently of external decisions.
Our vision is to turn operational knowledge into proprietary technology and, over time, build a platform capable of serving organizations at different levels of criticality — with architecture, processing and continuity under national control.
Brazil cannot fully outsource its ability to defend itself. That is the thesis behind every decision we make.
Ready to strengthen your defense with us?
Talk to our specialists. No sales theater. We understand your context and show you how we can help today.

