For pentesters, IT service providers and security specialists
An automated scan finds vulnerabilities, but does not decide what they mean for an organisation. That interpretation — pentests, advice, remediation — is human work. Which is why Exposentry looks for collaboration: with independent professionals and with companies that deliver security to their own clients.
Exposentry runs on OpenKAT, the open-source security scanner developed within the Dutch government and now continued by the community — Edward Hasekamp, the maker of Exposentry, contributes to it. The product delivers continuous vulnerability monitoring to SME organisations: continuous scans of the public attack surface, with monthly reporting. From 15 August 2026 the Dutch Cyberbeveiligingswet (the NIS2 implementation act) applies, without a transition period. Organisations must demonstrably have their security in order — and demonstrating starts with measuring, not with paperwork.
But a measurement is the beginning, not the end. Findings need interpretation, retesting, sometimes a manual pentest, and often simply someone who fixes them. Hasecon is not going to do all of that itself. That is why Exposentry is building a network of professionals who each master their own trade.
See the OpenKAT contributions on GitHub →A scan stops where manual work begins. When a client asks for depth after their scan findings — a manual pentest, a retest, verification of a vulnerability — Exposentry wants to be able to refer them to freelance pentesters. That network is being built right now; hence this page.
If you manage IT for SME clients, continuous monitoring of their attack surface connects directly to your services: you know the client and fix the findings; Exposentry delivers the measurements and reports.
There is no vacancy open, and yet: if you can do something that makes Exposentry better — from building OpenKAT boefjes to reviewing reports — you are welcome to get in touch. Freelance or in another form: that follows from the conversation.
The knowledge base publishes articles with author attribution and a profile link. If you write well about vulnerability management, NIS2 or the practice of security work in SMEs, a guest article is a concrete first collaboration.
Hasecon, the company behind Exposentry, is small. There is no partner programme with tiers, margins and a portal, and there is no guaranteed lead flow. There is: a working product, a law that demands demonstrable security, and the willingness to shape each collaboration seriously, case by case. Emails land directly with Edward Hasekamp.
No. Exposentry is built by a small company that prefers building a network of freelancers and partner companies over a payroll. An open application is welcome, but expect a conversation about collaboration, not an employment contract.
That differs per collaboration. Possible forms: referral when a client needs manual work, a joint vulnerability-management proposition towards SMEs and supply chains, or visibility through a guest article in the knowledge base. No revenue or lead volume is promised up front; agreements are made case by case.
No. OpenKAT experience helps — Exposentry runs on it and Edward Hasekamp contributes to the project — but for pentesters, service providers and authors, craftsmanship in your own domain weighs more than knowledge of the scanner.
Email info@exposentry.io with a short introduction: who you are, what you do and a link to work you have published or built.
No. Report vulnerabilities in Exposentry via the details in our security.txt file at /.well-known/security.txt. This page is about working together, not about reports.
Send who you are, what you do and where your work can be seen to info@exposentry.io. A link to previous work says more than a pitch deck.
Email info@exposentry.io