Products

Useful software. Defensive research. Clear boundaries.

Commission focused software and security work with a defined purpose, a documented scope and real authorization. We review every request before accepting it.

Publicly accessible does not mean free to collect, combine or reuse for any purpose. We minimize personal data and refuse requests that target third parties or enable harm.

Capability desk

Select a mission profile.

Explore the process, expected output and operating boundary before opening a commission request.

Mission 01Custom software & automation
Available

A focused utility built around one real workflow, with a clear handover instead of unnecessary platform complexity.

ProcessMap → prototype → validate
OutputCode, tests and setup notes
BoundaryNo credential collection or covert access
Configure this request →

Software & automation

Custom tools and Python scripts

Compact software that removes repetitive work, connects services or gives your team a purpose-built internal utility.

  • Python scripts and command-line tools
  • API integrations and data workflows
  • Desktop utilities and small web interfaces
  • Setup notes, tests and documented handover
Commission this product

Community systems

Discord and Telegram bots

Custom bots for communities, private groups and operational teams, designed around the flows you actually need.

  • Moderation, roles and onboarding
  • Notifications, commands and scheduled actions
  • External service and database integrations
  • No impersonation, spam, credential collection or surveillance
Commission this product

Self-audit OSINT

Personal digital-footprint tools

Local tools that help a person inspect identifiers and accounts they provide about themselves, then reduce unwanted exposure.

  • Designed for the requesting user’s own data
  • Public sources only, with no access-control bypass
  • No people search, facial recognition or third-party dossiers
  • No breach credentials or sensitive-data enrichment
Commission this product

Owned digital assets

External exposure review

A non-intrusive review of domains, services and public technical exposure belonging to your organization.

  • Verified ownership or written authorization required
  • Defined domains, accounts and infrastructure only
  • No exploitation, persistence or employee profiling
  • Prioritized findings and defensive recommendations
Commission this product

Defensive analysis

Malware analysis and detection

Isolated analysis of a suspicious sample obtained from a system you own or are authorized to defend, focused on understanding and detection.

  • Static and sandboxed behavioral analysis
  • Behavior summary and indicators of compromise
  • Detection guidance and YARA or Sigma rules where appropriate
  • No sample redistribution or operational malicious payload
Commission this product

Security validation

Detection engineering and safe simulation

Benign, non-propagating simulations that validate controls in an isolated lab or a system covered by written authorization.

  • Inert test artifacts and non-destructive behavior
  • Documented success criteria and stop conditions
  • No credential theft, covert surveillance or exfiltration
  • No evasion, persistence, ransomware or destructive actions
Commission this product

Service boundary

What we accept — and what we do not sell.

A disclaimer cannot turn an unsafe commission into a legitimate one. Product design, the likely use, the customer’s authority and the requested capabilities all matter.

Accepted defensive work

  • Self-audit tools for the customer’s own identifiers
  • Technical reviews of owned or authorized digital assets
  • Defensive analysis of legitimately obtained malware samples
  • Detection rules, hardening guidance and inert simulations
  • General OSINT education using synthetic or non-personal examples

Not offered

  • Investigations, profiling or dossiers about third parties
  • Unauthorized access, interception, exploitation or credential use
  • Ransomware, stealers, RATs, keyloggers, botnets or spyware
  • Droppers, persistence, stealth, security-evasion or destructive code
  • Phishing kits, credential databases or covert surveillance tools
Project Lunas does not currently offer private-investigation services or manual research reports about natural persons. That category will remain unavailable unless the required Italian licensing and privacy obligations are independently verified.

Authorization gate

Every sensitive request passes four checks.

Identity

We identify the customer and a reliable point of contact.

Authority

The customer proves ownership, control or written authorization for every in-scope asset.

Scope

Targets, purpose, permitted actions, dates and stop conditions are documented before work starts.

Minimization

We collect only what is necessary, protect it and agree how outputs and working data will be deleted.

Commission a product

Describe the outcome, not sensitive target data.

We first assess fit, safety and authorization. Submitting a request does not mean it has been accepted; unclear or high-risk work is refused.

Do not send credentials, private datasets, personal dossiers, malware samples, live targets or exploit code through this form.
Local preview · no transmissionTypical reply: 2–3 business days

In this localhost preview, the form is validated but nothing leaves your device. Once Supabase is connected, submissions will be sent through a protected server function.You can alwaysuse the email fallback or write toprojectlunas@tutamail.com.

Preview receiptRequest validated locally