Skip to content
Berghem's European Operations

Berilo

— Bergamo, Italy

European Offensive Security

Berilo is Berghem's European subsidiary, headquartered in Bergamo, Italy. We bring over two decades of offensive security expertise to the European market, with a GDPR-first methodology.

Our team delivers the same depth of technical analysis that protects major financial institutions worldwide, tailored for European regulatory requirements and business environments.

GDPR-First Methodology

Data minimization in all testing processes
EU-compliant evidence handling and storage
Privacy impact assessment integration
GDPR Article 32 security testing
Data Protection Officer coordination

Services

OWASP MASTG

Mobile Security

Comprehensive mobile application security testing for Android and iOS platforms.

OWASP WSTG

Web Application Security

Full-scope web application penetration testing with business logic analysis.

OWASP API Top 10

API Testing

REST, GraphQL, and SOAP API security assessment with authentication testing.

NIST SP 800-115

Network Security

Infrastructure penetration testing, network segmentation validation, and wireless security.

PCI-DSS

PayHack

Specialized payment system security testing for European payment processors and fintechs.

OWASP LLM Top 10

AI Pentesting

Security assessment of AI/ML systems, LLM applications, and autonomous agents.

Testing Models

Testing Models

Black Box

Zero prior knowledge — simulates a real external attacker with no inside information.

Gray Box

Partial knowledge — authenticated testing with limited documentation to balance depth and realism.

White Box

Full access — source code review and architecture analysis for maximum vulnerability coverage.

Frequently Asked Questions

What is Berilo?
Berilo S.r.l. is Berghem's European subsidiary, based in Bergamo, Italy. Established to serve the European market, Berilo delivers mobile application security, web application security, and AI security services with a GDPR-first methodology. Berilo combines Berghem's 20+ years of offensive security expertise with deep understanding of European regulatory requirements, providing local presence and language support for Italian and European clients.
Does Berilo offer the same services as Berghem?
Berilo offers a focused subset of Berghem's services optimized for the European market, including mobile application security testing (Android and iOS), web application penetration testing, API security assessment, and AI security services. All testing follows OWASP methodologies with specific attention to GDPR compliance requirements. Engagement models include one-time assessments, subscription-based continuous testing, and development-integrated security testing.
Is Berilo GDPR compliant?
Yes. Berilo operates with a GDPR-first methodology, meaning all testing processes, data handling, and reporting are designed from the ground up to comply with European data protection regulations. Client data is processed and stored within the European Union. Berilo's privacy practices are documented in the joint privacy policy with Berghem, and the company is registered under Italian law with VAT number 04689030163.
What languages does Berilo support?
Berilo provides services in Italian and English, with additional support available in Portuguese and Spanish through coordination with Berghem's São Paulo headquarters. All client-facing deliverables — including reports, executive summaries, and remediation guidance — can be produced in the client's preferred language. Technical findings and vulnerability descriptions maintain industry-standard English terminology regardless of report language.