
Est. 2013 · United Kingdom
We hack software, hardware, networks and websites — at your request.
From secure architecture to penetration testing, reverse engineering, code review, incident response, AI for cyber, and specialist training. Boutique quality, without the Big Four price.
2013
Founded in the United Kingdom
200+
Public vulnerabilities
3
Continents of clients
Pwn2Own
Competition pedigree
Services
Work we actually do
01Security Code Review
An experienced pair of eyes on your source. From close-to-metal C to top-of-stack Ruby. Code is kept encrypted and deleted after the engagement. NDAs are honoured in perpetuity.
02Penetration Testing
Manual and automated testing of web applications, infrastructure, networks, hardware, embedded devices and thick clients. We attack your systems as a real adversary would, then deliver a report of what we achieved and how to fix it.
03Reverse Engineering
No code? No problem. Decades of experience reversing software and hardware for interoperation, algorithm identification and vulnerability research — x86, x64, ARM, MIPS, SH-4, C#, Java, Rust, Go and others.
04Secure Architecture & Threat Modelling
It costs a thousand times more to secure a product after release than in development. We help you plan so those mistakes are never made — and if the product is already out, we still uncover hidden risk with threat modelling.
05Product Security
A holistic service fusing penetration testing, code review, reverse engineering, hardware security and more. We take products apart as a hacker would — from mobile phones to embedded servers, applications and cloud infrastructure.
06Incident Response & Network Monitoring
Have you been hacked? We investigate suspicious activity, determine how the intruders got in, throw them out, and help plug the holes. We also improve network monitoring, logging and SIEM.
07Specialist Security Training
Hands-on courses taught by the people who do the work. Private sessions for your team, plus a public on-demand course on hunting zero-days in embedded devices.
08AI for Cyber Security
Specialists in using AI for offensive and defensive cyber security since 2023. Custom systems, run in-house, self-hosted, or in the cloud — on your data, under your control.
09ISO 27001, NIS2 & NIST
ISO 27001 auditor-qualified consultants for gap analysis, ISMS work and certification support — plus NIS2, NIST CSF 2.0, Cyber Essentials and the technical controls those regimes actually require.

Research
Two hundred public vulnerabilities, and counting
Consultants spend a great deal of time looking for flaws in commercial software, open source, hardware and firmware — disclosed responsibly, above industry norms, with time for vendors to fix. The same techniques underpin the services we sell.
Read the researchTraining
Hands-on courses, not slides
Technical specialist training for teams who need reverse engineering, vulnerability research, product security, secure coding or incident response — taught by the consultants who do the work. A public on-demand course on embedded-device zero-days is at flashback.sh.
View trainingOffices
United Kingdom, with an office in Portugal
Founded in 2013. Clients on three continents — start-ups, international banks and large multinationals. Higher quality, lower price than the mainstream names.
About the firmContact us today to find out how we can help you.
Short engagements, senior consultants, and work we actually sign our names to.