Skip to content
Detail of a high-performance compute rack

Est. 2013 · United Kingdom

We hack software, hardware, networks and websites — at your request.

From secure architecture to penetration testing, reverse engineering, code review, incident response, AI for cyber, and specialist training. Boutique quality, without the Big Four price.

2013

Founded in the United Kingdom

200+

Public vulnerabilities

3

Continents of clients

Pwn2Own

Competition pedigree

Services

Work we actually do

All services
01

Security Code Review

An experienced pair of eyes on your source. From close-to-metal C to top-of-stack Ruby. Code is kept encrypted and deleted after the engagement. NDAs are honoured in perpetuity.

02

Penetration Testing

Manual and automated testing of web applications, infrastructure, networks, hardware, embedded devices and thick clients. We attack your systems as a real adversary would, then deliver a report of what we achieved and how to fix it.

03

Reverse Engineering

No code? No problem. Decades of experience reversing software and hardware for interoperation, algorithm identification and vulnerability research — x86, x64, ARM, MIPS, SH-4, C#, Java, Rust, Go and others.

04

Secure Architecture & Threat Modelling

It costs a thousand times more to secure a product after release than in development. We help you plan so those mistakes are never made — and if the product is already out, we still uncover hidden risk with threat modelling.

05

Product Security

A holistic service fusing penetration testing, code review, reverse engineering, hardware security and more. We take products apart as a hacker would — from mobile phones to embedded servers, applications and cloud infrastructure.

06

Incident Response & Network Monitoring

Have you been hacked? We investigate suspicious activity, determine how the intruders got in, throw them out, and help plug the holes. We also improve network monitoring, logging and SIEM.

07

Specialist Security Training

Hands-on courses taught by the people who do the work. Private sessions for your team, plus a public on-demand course on hunting zero-days in embedded devices.

08

AI for Cyber Security

Specialists in using AI for offensive and defensive cyber security since 2023. Custom systems, run in-house, self-hosted, or in the cloud — on your data, under your control.

09

ISO 27001, NIS2 & NIST

ISO 27001 auditor-qualified consultants for gap analysis, ISMS work and certification support — plus NIS2, NIST CSF 2.0, Cyber Essentials and the technical controls those regimes actually require.

Firmware in a reverse-engineering tool

Research

Two hundred public vulnerabilities, and counting

Consultants spend a great deal of time looking for flaws in commercial software, open source, hardware and firmware — disclosed responsibly, above industry norms, with time for vendors to fix. The same techniques underpin the services we sell.

Read the research

Training

Hands-on courses, not slides

Technical specialist training for teams who need reverse engineering, vulnerability research, product security, secure coding or incident response — taught by the consultants who do the work. A public on-demand course on embedded-device zero-days is at flashback.sh.

View training

Offices

United Kingdom, with an office in Portugal

Founded in 2013. Clients on three continents — start-ups, international banks and large multinationals. Higher quality, lower price than the mainstream names.

About the firm

Contact us today to find out how we can help you.

Short engagements, senior consultants, and work we actually sign our names to.