Penetration testing & vulnerability research
We test applications the way an attacker would, and we document what we find well enough that it can be fixed.
reiver /ˈriːvər/noun
A raider of the Anglo-Scottish border, active from the 13th to the 17th century. Reivers crossed a defended frontier, took what they came for, and left before anyone noticed.
01Capability
Manual, attacker-minded testing. We report a finding once its real impact has been demonstrated against a live target.
Web · API · GraphQL
Authentication and session handling, access control and IDOR, injection, server-side request forgery, and business-logic flaws across web applications and the APIs behind them.
Android · iOS
Static review of decompiled applications and runtime instrumentation on physical devices, covering the hidden endpoints, hardcoded credentials and trust decisions that never surface on the web tier.
Coordinated disclosure
Original research reported through managed bug bounty and vulnerability disclosure programs, with evidence preserved from the moment of discovery.
02Record
Research is published under the handle manbearpigmb. Every figure below is reported by the platform itself.
Figures as of 6 October 2026. Leaderboard position is a rolling 90-day window and moves over time.
Inspectiv publishes its Top Researcher standings to the researcher community. Written confirmation is available to clients on request.
Source: public profile activity
Accepted findings in every month since February 2026. October covers the first six days.
03Contact
Reiver is the operating name of 1001504930 Ontario Inc., a corporation registered in Ontario, Canada.
Scoping, availability, and client verification requests. Written confirmation of platform standing is available on request.