Skip to content

Offensive security focused on what keeps the business running

Since 2003, Berghem has operated in critical environments, combining adversarial expertise, business logic and new artificial intelligence capabilities.

REG · 003  ·  Berghem by the numbers

Two decades of offensive security, audited and reproducible.

Updated · Q2 2026
01 · LEGACY
20+
Years of Expertise

Continuous operation in offensive security since 2003.

02 · DELIVERY
10K+
Projects Delivered

Documented engagements with reproducible evidence.

03 · SECTORS
5
Industries served

Financial services, healthcare, government, technology and retail.

04 · CATALOG
8
Specialized Pillars

Pentest, red team, AI, compliance, DevSecOps and IR.

05 · REACH
2
Continents

Operations in Latin America and Europe via Berilo.

Source · Audited internal recordsISO 27001 · LGPD · GDPRSão Paulo · Bergamo

Our Story

2003Founded at LSI-TEC, USP
2008First core-banking pentest
2014Trusted by Tier-1 banks
2019Berilo launches in Europe
2023AI Security practice
TodayAgentic EHT in operation

Berghem was built on a single conviction: the best defense starts with a deep understanding of offense. From day one, our focus has been on offensive security — finding vulnerabilities before attackers do. Our roots are in the financial sector, where over 80% of our historical work has been dedicated to securing payment systems, core banking platforms, and fintech infrastructure for major institutions across the globe. Today, Berghem is at the forefront of AI security, developing AI pentesting methodologies, mission-oriented security agents, and AI-powered risk management frameworks. Our European subsidiary, Berilo, brings this expertise to the European market with GDPR-first methodology.

What Sets Us Apart

Hidden flaws

Business Logic Analysis

We go beyond automated scanners to find vulnerabilities in your application's business logic — the flaws that matter most.

20+ years

Financial Expertise

20+ years securing payment systems, core banking, and fintech for major financial institutions worldwide.

AI native

AI-First Approach

Pioneering AI security services and autonomous security agents powered by multi-model architecture technology.

Supplier risk

AI-VRM Framework

Our AI-powered Vendor Risk Management framework automates third-party security assessments.

TEAM

Leadership

The names that sign every report.

Four profiles, one operation. Decades in pentesting, AI research, delivery and culture — signing every engagement end to end.

  1. 01
    FILE/lead/01nava.m

    Matteo Nava

    Founder & CEO
    25 yearsFounder, 2003Banking & Payments

    Matteo Nava is the founder and CEO of Berghem, a company he built from the ground up into a reference in ethical hacking and offensive security, serving major banks and financial institutions in Brazil and abroad. At the head of the operation, he sets the strategic vision, the technical posture and the quality standard of the firm.

    With deep experience in red team, pentest and adversarial simulation, he leads a team dedicated to raising the defensive maturity of organizations in regulated, high-criticality environments — combining technical rigor, business judgment and a commitment to measurable results.

    CertCISSP·CISM
    LinkedIn
  2. 02
    FILE/lead/02bueno.g

    Gislaine Bueno Oliveira

    VP of Human Resources & Compliance
    TalentCultureCompliance

    Gislaine leads Berghem's talent management strategy, organizational development and the strengthening of a culture of continuous learning, in a market highly competitive for professionals specialized in offensive security.

    Beyond her work in people management, she is also responsible for overseeing projects for large enterprises, connecting business needs to human development and delivery excellence.

    FocusSenior recruiting · Culture · L&D · Compliance
    LinkedIn
  3. 03
    FILE/lead/03schneider.r

    Raphael Schneider

    VP of Cybersecurity
    OperationsRed TeamEnterprise Delivery

    Raphael Schneider oversees pentest operations, Red Team exercises and security assessments for Berghem's enterprise clients. He is the central point of technical coordination, ensuring every engagement is run under the firm's proprietary methodology, with analytical depth and adherence to international industry standards.

    Responsible for methodological consistency, on-time delivery and quality across all projects, he leads the articulation between the offensive teams and the client relationship, sustaining the level of technical excellence that defines Berghem's reputation in critical, regulated environments.

  4. 04
    FILE/lead/04nava.l

    Lorenzo Nava

    Lead Security and ML Researcher
    AI / LLM ResearchBerghem AgentsBerilo · EU

    Lorenzo Nava leads Berghem's AI security practice and drives the development of Berghem Agents, the company's agentic EHT capability. His work combines applied research and offensive engineering, positioning the firm at the frontier between artificial intelligence and offensive security.

    He is also responsible for the group's European operations, at the head of Berilo S.r.l., extending Berghem's methodology and quality standard to the international market from Bergamo, Italy.

HOW WE WORK

Principles that guide the work

Clear principles and verifiable evidence guide every mission, every claim and every decision.

Business before tooling

The investigation starts from what sustains the organization.

Evidence before hype

Claims, results and demonstrations must be reproducible.

Experts in command

AI amplifies capacity; judgment and accountability remain human.

Proportional control

Autonomy, data and access are defined according to risk.

AI UNDER CONTROL

Applied research and multi-model architecture

Berghem develops specialized models from open-weight models and combines different execution options according to task, confidentiality and environment.

Development

CPT, adaptations, evaluations and versioning on controlled infrastructure or contracted compute capacity.

Deployment

Berghem models, private models, authorized third parties, or served inside the client's own tenant.

Let's Talk Security

Ready to strengthen your security posture? Let's discuss how Berghem can protect your organization.

Get in Touch