Otis™

Offensive AI, Under Command

Otis™ is Parabellum's proprietary offensive AI capability, leveraging an advanced AI-enhanced offensive security system, directed and validated by senior offensive security experts.

AI Enabled Security Assurance
for Modern Industry
Built In-House
Built In-House
Designed, developed and tested by our own offensive security experts, not a vendor tool purchased.
Expert Controlled
Expert Controlled
A senior consultant directs every Otis™ augmented engagement from start to finish
Extensive Coverage
Extensive Coverage
Every role, workflow and host across the agreed scope, not the portion that fits the window
Every Finding Validated
Every Finding Validated
Checked by a qualified expert before it reaches your report, so nothing arrives unverified
Otis™ Augmented Delivery

Who is Otis™ for?

Organisations whose scale, complexity or regulatory obligations demand broader coverage than a standard engagement window allows.

Complex Systems
Where dep coverage is crucial

Where scale and complexity mean a time-boxed test can only ever sample. Otis assesses more of the surface that would otherwise go untested.

  • Applications with numerous user roles and permission tiers
    01
  • Multi-tenant SaaS and API-heavy platforms
    02
  • Intricate business workflows and logic
    03
Large Attack Surfaces
Where coverage is the hardest to guarantee

Where the surface is too broad, or changes too fast, for annual sampling to keep pace. Otis extends how much can be assessed in the same window.

  • Sprawling external infrastructure
    01
  • Environments that change faster than annual testing
    02
  • Teams needing broad assurance without longer timelines
    03
Regulated & Data-Sensitive
The data matters as much as the findings

Where sovereignty and governance are procurement requirements, not preferences. Otis keeps engagement data isolated and processed in Australia.

  • APRA, SOCI and government-adjacent obligations
    01
  • Organisations requiring sovereign, onshore delivery
    02
  • Teams underserved by shallow or heavily sampled tests
    03

"A critical aspect to Otis is the human judgement that decides where to go deep, and that still comes from an experienced security specialist. The machine covers the ground. The expert decides what matters."

Stuart Shanahan

Director of Technical Services

A View of Sydney Harbour
Otis™ Augmented Delivery

How an Otis™ Engagement Runs

Our proprietary offensive AI capability, directed by a senior consultant from scoping through to final report.

01 – Detailed Scoping & Threat Modelling

A senior consultant leads a focused session to map your attack surface and shape a tailored test scope based on real-world risks. Because coverage isn't capped by available hours, scoping is about what matters most rather than what will fit. The threat model sets the priorities your consultant uses to direct Otis™.

02 – Live Reporting

View findings in real time via a live dashboard. Track progress, ask questions, and get remediation advice directly from your tester. Findings appear as your consultant validates them, throughout the engagement rather than at the end.

03 – 1-on-1 Delivery & Debrief

Receive a 1-on-1 walkthrough of results, with risk contextualised based on your environment, business impact, and compensating controls.

04 – Final Reporting

Get a clear, actionable report with technical details, risk ratings, and prioritised fixes, designed for both engineers and executives. The process doesn't change. How much of your environment it covers does

01
Built by the people who use it
+

Otis™ was designed, developed and tested in-house by Parabellum's security researchers and offensive security experts, consultants who hold Australian government security clearances and have delivered advanced offensive security engagements for ASX 100 & Fortune 500 companies, all levels of Government, Banking, Energy & Resources, the Defence supply chain and critical Infrastructure entities.

The tradecraft of modern adversaries, threat actors and security consultants is built into the capability itself, not written into a methodology document that gets referenced when someone remembers to. The people who built Otis™ are the people who direct it.

02
Coverage that doesn't depend on available hours
+

Most penetration tests sample. Not by choice but by arithmetic. A tester covers what they can reach in the days available, and whatever falls outside that window may go untested. The client assumes the surface was covered. The tester knows it was sampled.

Parabellum consultants use Otis™ to assess substantially more of the agreed scope than a time-bound manualtest can reach, equating to more roles, more workflows, more hosts, rather than a sample.

03
Expert-piloted, continuously
+

Fully agentic & autonomous tools plateau. An agent finds something shallow, marks the objective met, and moves on because nobody is watching to tell it that it stopped one step short of something that mattered. We call it the lazy agent, and it is why unsupervised autonomy often produces volume rather than insight.

A senior Parabellum consultant directs every Otis™ augmented engagement from start to finish. Not scoping at the front and reviewing at the back but rather, steering, throughout. Recognising the moment an agent settles for something shallow, and redirecting it to the path that actually matters.

The coverage of a machine. The judgment of a senior offensive security expert. On the same engagement.

04
Every finding validated by a Parabellum expert
+

100% human-validated findings. No finding reaches your report without being checked by a qualified Parabellum consultant, validated, prioritised, and explained in the context of your environment.

What you receive is an assurance a named consultant stands behind. Not a queue of machine output for your team to triage.

05
Sovereign by architecture
+

Every Otis™ augmented engagement runs in an isolated environment, walled off with a single controlled egress so your engagement never touches another.

Model inference runs on IRAP-assessed infrastructure at the PROTECTED level, the same standard the Australian government relies on for its own classified workloads. Your data is processed in Australia and is never sent to a third-party model provider. Encryption in transit and at rest with KMS-managed keys. Every action logged and attributable, so the engagement is auditable end to end.

Parabellum also participates in the security and safety programmes of frontier AI providers including Anthropic and OpenAI, programmes those providers carefully vet membership into.

06
Built to keep improving
+

Otis™ is where our research compounds. Every engagement teaches our consultants something about how modern systems fail, and that tradecraft is encoded back into the capability, so each assessment benefits from the ones before it.

What never feeds back is your data. No client data is used to train any model, not anonymised, not aggregated, not opt-in. The learning comes from our researchers, not from your environment.

07
Matched to the engagement
+

Otis™ augmented delivery applies to external network, wireless network, web application, thick client, APIs, mobile application and source code security testing today.

Where a scope isn't Otis™ capable, or where your own AI-use policy restricts it, the same senior consultants deliver by hand, utilising years of experience across complex environments and advanced, manual offensive tooling.

Scope an Otis™ Engagement

Our certified offensive security experts, safely simulate real-world cyberattacks to help you identify security weaknesses across your organisation.

Book a Consult
Martin & Stuart from Parabellum
Impact

Trusted by Industry, Certified to Deliver

Our cleared and certified experts deliver trusted cybersecurity outcomes, uncovering deep vulnerabilities with precision, integrity, and proven impact.

“Parabellum’s friendly, knowledgeable team are true experts in securing both IT and OT environments."
Ben Mackay
IT Manager, Tianqi Lithium Energy Australia
"Parabellum were exceptional at helping us improve our security processes. Highly recommend."
Shane Brunette
CEO, Crypto Tax Calculator
"The team brought an unparalleled depth of knowledge...and were able to uncover a number of issues deep within our authentication mechanisms that I don’t believe any other organisation we’ve worked with would have discovered."
Ben Davey
SVP Product, Darwinium
"It was a completely different experience compared to our previous provider. I would highly recommend Parabellum, rather than just running through a checklist they will find the real cracks you have in your security..."
John Shanks
Director, Kraken Coding
“The results were both illuminating and crucial to our ongoing cybersecurity posture, a testament to Parabellum’s capability, experience, and attention to detail.”
Peter Bainbridge
Head of IT Operations, Secure Parking
“The testing and reviews were executed with meticulous attention to detail... Parabellum provided practical, actionable recommendations that will significantly enhance our security framework and resilience.”
Jurgen Kusel
Head of Technology, Pinnacle Investment Management Group