Software & Security Consulting · Karlsruhe, Germany
Baumstark Consulting brings senior-level software engineering and security research to your most challenging problems — from architecture reviews to hands-on vulnerability research.
What we do
We work with startups, scale-ups, and enterprises who need deep technical knowledge — not boilerplate advice.
Thorough black-box and white-box security assessments of web applications, APIs, desktop software, and browser-based products. We find the issues your automated scanners miss.
Targeted research into complex attack surfaces — browsers, virtual machines, operating system kernels, and custom protocols. We have a proven track record of finding critical vulnerabilities in major software products.
Designing systems that are correct, maintainable, and secure from the ground up. We review existing codebases and architectures with a critical eye and provide actionable recommendations.
Binary analysis, protocol reverse engineering, and malware analysis. Whether you need to understand an undocumented file format or investigate a suspicious binary, we have the tools and expertise.
Manual source code audits with a focus on security-critical components. We work across C, C++, Rust, Go, Python, TypeScript, and more — covering both logic errors and memory safety issues.
Hands-on training for engineering teams in secure development practices, exploit mitigation, and offensive security fundamentals. Custom workshops tailored to your stack and threat model.
About us
Baumstark Consulting GmbH was founded by Niklas Baumstark, a security researcher and software engineer based in Germany.
Niklas holds a Master's degree in Informatics from the Karlsruhe Institute of Technology (KIT) and has spent over a decade working at the intersection of software engineering and offensive security. He has publicly demonstrated exploits against products from Apple, Google, Mozilla, and Oracle, and has presented research at international security conferences.
Prior to founding Baumstark Consulting, Niklas served as CTO of a fintech startup and as Chief Research Officer at a specialist security firm, giving him a rare combination of startup engineering experience and deep security research expertise.
We keep our client list small and our involvement deep. When you hire us, you work directly with Niklas — not a junior consultant following a checklist.
Track record
Our work has been recognised by some of the world's leading software companies and presented at top-tier security conferences.
Co-discovered and exploited a sandbox escape vulnerability in Chromium's broker process, chained with a V8 bug to achieve full browser compromise. Presented at OffensiveCon 2019.
Credited in Apple's iOS 11 security advisories for memory corruption vulnerabilities discovered in collaboration with Trend Micro's Zero Day Initiative.
Presented "Unboxing your VirtualBox" — an in-depth exploration of VirtualBox internals, hypervisor attack surfaces, and practical exploitation techniques.
Long-standing member of the competitive CTF community — both as a top-ranked player and as an organiser, designing challenges that push the boundaries of offensive security knowledge.
Software engineering intern at Google (2014, 2016) and research scholar at Carnegie Mellon University (2014), bringing world-class engineering rigour to every engagement.
Co-founded and led the engineering team at Cashlink, a regulated fintech company, bridging the gap between security research and production software delivery.
Contact
Whether you have a well-defined scope or need help figuring out where to start, we're happy to have an initial conversation — no commitment required.
Reach out by email to discuss your requirements. We typically respond within one business day.
✉