CLIENT SUCCESS STORIES

What Our Clients Say

Hear from teams we've worked with

dermanostic GmbH logo
We have been working with Machine Spirits for several years and value their technical expertise and straightforward collaboration. Their actionable recommendations have been instrumental in sustainably strengthening the protection of the patient data entrusted to us.
Lucas Habrich
CTO, dermanostic GmbH
Elona Health GmbH logo
As a security partner for our DiGA, Machine Spirits impressed us with their in-depth pentests. Their competent TR-03161 consulting and clear recommendations were crucial in meeting the demanding BSI requirements quickly and securely.
Leon Hillebrandt
CTO, Elona Health GmbH
Noah Labs GmbH logo
Machine Spirits helped uncover vulnerabilities in our platform early with a structured and in-depth pentest before we went through MDR certification. The clear reports and pragmatic communication helped us quickly close security gaps and efficiently update our documentation.
Marcus Hott
CTO, Noah Labs GmbH
relios.vision GmbH logo
Very pleasant collaboration with Volker and Simon from Machinespirits. Both are extremely professional and very flexible. We would be happy to continue working with Machinespirits in the future.
Dr. Martin Garbade
CTO, relios.vision GmbH

In the media

heise online

Interview

Sicherheitslücken in ePA-Clients: „Die Implementierungen hatten blinde Flecken“

In an interview with Marie-Claire Koch, Dr. Simon Weber discusses our research into ePA client security, the implementation gaps we found, and what developers can learn from them.

Recognition

gematik GmbH

Security Heroes

Recognized by gematik for the responsible disclosure of critical vulnerabilities in healthcare authentication infrastructure. The coordinated disclosure was highlighted for its quality, technical depth, and professional collaboration.

gematik GmbH

Robert Koch Institute

Coordinated Disclosure

Acknowledged by the Robert Koch Institute for the coordinated disclosure of a broken access control flaw in its MEx metadata platform, where read-only credentials were enough to delete a merged item and every record linked to it.

Robert Koch Institute

Element

Security Hall of Fame

Listed in Element's Security Hall of Fame for the coordinated disclosure of two vulnerabilities in the Matrix clients Element Web and Element X Android, published as CVE-2026-55850 and CVE-2026-55080.

Element

Let's Talk About Your Security

Contact us today and learn how we can help you secure your digital assets and achieve regulatory compliance.

Schedule Your Consultation