Public leaderboards for LLM hacking skip the hardest part of real client work: the client's data can never leave the building. Pentesters who work under NDAs and data-residency rules cannot simply paste traffic into a cloud model. Most benchmarks ignore that constraint entirely. One answer is to run open models on hardware the testing team owns, with search over past findings. No client data leaves the network. In his SecTor 2026 talk, "The Parts the Leaderboards Skip: Three Years of LLM-Assisted Pentesting Under NDA", on Wednesday, October 7 at 3:25 p.m. in Room 801B, Murat Alagöz shares three years of results from that setup. Speaker: Murat Alagöz, Senior Security Specialist, Digital Boundary Group The demo turns thousands of proxy requests into a ranked map of an application's functional areas. He also covers the negative results that most vendor talks leave out. The session closes with a checklist for scope control, logging and mandatory human review. A sanitized version of the tool is planned for open-source release. Murat Alagöz is a senior security specialist at Digital Boundary Group. He tests web applications, APIs and agentic AI systems. His clients work in finance, healthcare and the public sector. He holds an MSc in Cybersecurity, along with OSCP and GCPN certifications. He also sits on the GIAC Advisory Board. Consultancies and in-house red teams with strict data-handling rules will find a realistic model for using LLMs. Would your clients accept LLM-assisted testing if every model ran on hardware you own?   submitted by   /u/_cybersecurity_   to   r/pwnhub [link]   [comments]