Services
Manual and automated work, across the stack.
Secure architecture, penetration testing, reverse engineering, code review, product security, incident response, AI for cyber, ISO 27001 / NIS2 / NIST, and hands-on technical cyber security training.
01Penetration Testing
Manual and automated testing of web applications, infrastructure, networks, hardware, embedded devices and thick clients. We attack your systems as a real adversary would, then deliver a report of what we achieved and how to fix it.
02Product Security
A holistic service fusing penetration testing, code review, reverse engineering, hardware security and more. We take products apart and exploit them as a hacker would: from mobile phones to embedded servers, applications and cloud infrastructure.
03AI for Cyber Security
Specialists in using AI for offensive and defensive cyber security. Custom systems, run in-house, self-hosted, or in the cloud; on your data, under your control.
04Reverse Engineering
No code? No problem. Decades of experience reversing software and hardware for interoperation, algorithm identification and vulnerability research; x86, x64, ARM, MIPS, SH-4, C#, Java, Rust, Go and others.
05Security Code Review
An experienced pair of eyes on your source code. From close-to-metal C to top-of-stack Rust. Code is kept encrypted and deleted after the engagement. NDAs are honoured in perpetuity.
06Secure Architecture & Threat Modelling
It costs a thousand times more to secure a product after release than in development. We help you plan so those mistakes are never made; and if the product is already out, we still uncover hidden risk with threat modelling.
07Incident Response & Network Monitoring
Have you been hacked? We investigate suspicious activity, determine how the intruders got in, throw them out, and help plug the holes. We can also help you improve network monitoring, logging and SIEM.
08Specialist Security Training
Hands-on courses taught by the people who do the work. Private sessions for your team, plus a public on-demand course on hunting zero-days in embedded devices.
09ISO 27001, NIS2 & NIST
ISO 27001 auditor-qualified consultants for gap analysis, ISMS work and certification support, plus NIS2, NIST CSF 2.0, Cyber Essentials and the technical controls those regimes actually require.
Tell us what you need secured.
Short or long engagements conducted by senior consultants and experts in technical cyber security.