Otis™ is Parabellum's proprietary offensive AI capability, leveraging an advanced AI-enhanced offensive security system, directed and validated by senior offensive security experts.
Organisations whose scale, complexity or regulatory obligations demand broader coverage than a standard engagement window allows.

Where scale and complexity mean a time-boxed test can only ever sample. Otis assesses more of the surface that would otherwise go untested.
.webp)
Where the surface is too broad, or changes too fast, for annual sampling to keep pace. Otis extends how much can be assessed in the same window.

Where sovereignty and governance are procurement requirements, not preferences. Otis keeps engagement data isolated and processed in Australia.
"A critical aspect to Otis is the human judgement that decides where to go deep, and that still comes from an experienced security specialist. The machine covers the ground. The expert decides what matters."
Stuart Shanahan
Director of Technical Services

Our proprietary offensive AI capability, directed by a senior consultant from scoping through to final report.
Otis™ was designed, developed and tested in-house by Parabellum's security researchers and offensive security experts, consultants who hold Australian government security clearances and have delivered advanced offensive security engagements for ASX 100 & Fortune 500 companies, all levels of Government, Banking, Energy & Resources, the Defence supply chain and critical Infrastructure entities.
The tradecraft of modern adversaries, threat actors and security consultants is built into the capability itself, not written into a methodology document that gets referenced when someone remembers to. The people who built Otis™ are the people who direct it.
Most penetration tests sample. Not by choice but by arithmetic. A tester covers what they can reach in the days available, and whatever falls outside that window may go untested. The client assumes the surface was covered. The tester knows it was sampled.
Parabellum consultants use Otis™ to assess substantially more of the agreed scope than a time-bound manualtest can reach, equating to more roles, more workflows, more hosts, rather than a sample.
Fully agentic & autonomous tools plateau. An agent finds something shallow, marks the objective met, and moves on because nobody is watching to tell it that it stopped one step short of something that mattered. We call it the lazy agent, and it is why unsupervised autonomy often produces volume rather than insight.
A senior Parabellum consultant directs every Otis™ augmented engagement from start to finish. Not scoping at the front and reviewing at the back but rather, steering, throughout. Recognising the moment an agent settles for something shallow, and redirecting it to the path that actually matters.
The coverage of a machine. The judgment of a senior offensive security expert. On the same engagement.
100% human-validated findings. No finding reaches your report without being checked by a qualified Parabellum consultant, validated, prioritised, and explained in the context of your environment.
What you receive is an assurance a named consultant stands behind. Not a queue of machine output for your team to triage.
Every Otis™ augmented engagement runs in an isolated environment, walled off with a single controlled egress so your engagement never touches another.
Model inference runs on IRAP-assessed infrastructure at the PROTECTED level, the same standard the Australian government relies on for its own classified workloads. Your data is processed in Australia and is never sent to a third-party model provider. Encryption in transit and at rest with KMS-managed keys. Every action logged and attributable, so the engagement is auditable end to end.
Parabellum also participates in the security and safety programmes of frontier AI providers including Anthropic and OpenAI, programmes those providers carefully vet membership into.
Otis™ is where our research compounds. Every engagement teaches our consultants something about how modern systems fail, and that tradecraft is encoded back into the capability, so each assessment benefits from the ones before it.
What never feeds back is your data. No client data is used to train any model, not anonymised, not aggregated, not opt-in. The learning comes from our researchers, not from your environment.
Otis™ augmented delivery applies to external network, wireless network, web application, thick client, APIs, mobile application and source code security testing today.
Where a scope isn't Otis™ capable, or where your own AI-use policy restricts it, the same senior consultants deliver by hand, utilising years of experience across complex environments and advanced, manual offensive tooling.
Our certified offensive security experts, safely simulate real-world cyberattacks to help you identify security weaknesses across your organisation.

Our cleared and certified experts deliver trusted cybersecurity outcomes, uncovering deep vulnerabilities with precision, integrity, and proven impact.


