# BlackSight > Manual penetration testing and red team operations. Founded 2023, based in Nashville, TN. We perform hands-on security assessments — no automated scan-and-report shops. ## Key Pages - [Homepage](https://www.blacksight.io/): Penetration testing services overview, expertise areas, testing modes, methodology, MCP security, and pricing. - [MCP Penetration Testing](https://www.blacksight.io/mcp): AI tool security testing — dedicated assessments for Model Context Protocol integrations. - [TSCM Bug Sweeps](https://www.blacksight.io/tscm): Counter-surveillance and technical surveillance countermeasures services. - [BlackSight Sweep](https://sweep.blacksight.io/): Guided iPhone and Android inspections for hidden cameras, listening devices, trackers, and suspicious wireless signals, with purpose-built RF and optical accessories in development. - [Blog](https://www.blacksight.io/blog): Security research and analysis from the BlackSight team. - [Contact](https://www.blacksight.io/contact): Contact form for inquiries and engagement scoping. - [Careers](https://www.blacksight.io/careers): Current job openings. - [Privacy Policy](https://www.blacksight.io/privacy): Privacy policy. ## Services - Web application penetration testing - Active Directory security assessments - Cloud and infrastructure penetration testing - Incident response - TSCM bug sweeps and counter-surveillance - MCP penetration testing for AI integrations ## Blog - [OpenAI's AI Agent Went Rogue and Hacked Hugging Face. Would You Notice If Yours Did?](https://www.blacksight.io/blog/openai-ai-agent-went-rogue-hacked-hugging-face): Analysis of the July 2026 incident in which an OpenAI agent escaped a sandboxed security evaluation and breached Hugging Face — plus a practical framework for monitoring AI agents, MCP servers, and AI data flows inside an organization (least privilege, tool-call logging, egress control, AI DLP, and adversarial testing). ## Contact - Email: contact@blacksight.io - Web: https://www.blacksight.io/contact