About
Specialists in the security of the systems your business talks through
GoldAgent focuses on one thing: the security of PBX, SIP and VoIP telephony. It is the layer most security programmes overlook, and the one attackers turn into fraud fastest.
Why we exist
Telephony is a security blind spot
Most organisations run a vulnerability-management programme for their servers, endpoints and web applications. Very few extend it to the phone system, even though the PBX is internet-connected, carries every call, and is a direct route to fraudulent spend the business usually has to pay for.
Generalist penetration testing rarely covers SIP, trunking, extension security and toll fraud in depth. GoldAgent exists to close that gap: specialist, authorised telephony security assessment, with findings a decision-maker and a technical team can both act on.
What we stand for
- Authorised testing only, never anything else
- Evidence before assertion, no invented findings
- Human validation over raw scanner output
- Honest, plain reporting, no fear marketing
- Specialist depth over generalist breadth
How we're different
Specialist, not generalist
Telephony depth
We assess SIP, trunking, extensions, dialling and toll fraud specifically, not as an afterthought to a network test.
Right-party authorisation
We take the hosted-PBX authorisation problem seriously and confirm the right party has authorised testing before we begin.
Recurring assurance
Assure repeats the authorised checks on an agreed schedule, human-validated each cycle, so your evidence stays current between assessments, not an always-on monitoring platform.
Who runs it
Founder & lead assessor
Rocco Clayfield
Founder & Lead Assessor
Director, GoldPaid Ltd
Rocco Clayfield is the founder and lead assessor of GoldAgent, the specialist PBX, SIP and VoIP security service operated under GoldPaid Ltd. He leads engagements personally, from scope and authorisation through validation and reporting, so the person who signs off your findings is the person who found them.
GoldAgent exists because the telephony layer is the part of the estate most security programmes overlook, and the part attackers turn into fraud fastest. The approach is deliberately narrow and deep: authorised testing only, evidence over noise, and honest reporting that a board and an engineering team can both act on.
Professional memberships and certifications are published here only once they are genuinely held. Ask directly about current status for a specific engagement.
Credentials & accreditations
We publish accreditations only once they are genuinely held. Where you would expect to see certifications, we would rather show nothing than imply something that is not in place. Ask us directly about our current status for a specific engagement, we will answer plainly.
Find out exactly how exposed your phone system is
Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.
Testing is only performed against systems you own or are explicitly authorised to test.