Products

The security products we build and run.

AI-Enabled Penetration Testing

Foxhound

Foxhound automates approved assessment steps within your scope. A tester approves active testing, investigates the results, and signs off findings before delivery. Scored with CVSS 4.0 and tracked live in the portal.

See how it works
Extension Security Intelligence

RiskyPlugins

Risk profiles across 550K+ browser and IDE extensions in 9 marketplaces. Know what you’re installing before it becomes a problem.

Visit RiskyPlugins
Private Extension Marketplace (private preview)

PrivateStores

A private VS Code and OpenVSX marketplace for your organisation. Your developers install from a catalogue you approved, with risk thresholds and release holds enforced as policy. Scored by the RiskyPlugins engine. In private preview with a small number of teams.

How it works

Most of what we do ships as a product. Foxhound is how we deliver penetration testing, scoped to your environment rather than sold as a separate service. RiskyPlugins scores the extension supply chain, and PrivateStores turns that intelligence into a marketplace your organisation controls. Where a product can’t do the job alone, our consultancy practice picks it up.

We also build in the open: Fenko Vault, dnsmonster, and foxymirror live on our open-source page.

Inside the Consultancy practice

The Fenko consulting practice covers hands-on security work that needs judgement, context, and implementation help. We pair with internal teams, run focused engagements, and stay long enough to make sure the work sticks.

  • Architecture reviews: assess your infrastructure, cloud setup, or application stack for security gaps.
  • Threat modelling: identify what matters, what’s exposed, and where to focus.
  • AI security: audits, prompt injection testing, inference monitoring, MCP governance, and access control for AI systems.
  • AI agent development: custom autonomous agents, multi-agent orchestration, and RAG pipelines built for your workflows.

Let's talk.

Pentest, extension supply chain, or security programme. We're here.

Contact Us