Skip to content

Services

Manual and automated work, across the stack.

Secure architecture, penetration testing, reverse engineering, code review, product security, incident response, AI for cyber, ISO 27001 / NIS2 / NIST — and the training that leaves your own people better than we found them.

01

Security Code Review

An experienced pair of eyes on your source. From close-to-metal C to top-of-stack Ruby. Code is kept encrypted and deleted after the engagement. NDAs are honoured in perpetuity.

02

Penetration Testing

Manual and automated testing of web applications, infrastructure, networks, hardware, embedded devices and thick clients. We attack your systems as a real adversary would, then deliver a report of what we achieved and how to fix it.

03

Reverse Engineering

No code? No problem. Decades of experience reversing software and hardware for interoperation, algorithm identification and vulnerability research — x86, x64, ARM, MIPS, SH-4, C#, Java, Rust, Go and others.

04

Secure Architecture & Threat Modelling

It costs a thousand times more to secure a product after release than in development. We help you plan so those mistakes are never made — and if the product is already out, we still uncover hidden risk with threat modelling.

05

Product Security

A holistic service fusing penetration testing, code review, reverse engineering, hardware security and more. We take products apart as a hacker would — from mobile phones to embedded servers, applications and cloud infrastructure.

06

Incident Response & Network Monitoring

Have you been hacked? We investigate suspicious activity, determine how the intruders got in, throw them out, and help plug the holes. We also improve network monitoring, logging and SIEM.

07

Specialist Security Training

Hands-on courses taught by the people who do the work. Private sessions for your team, plus a public on-demand course on hunting zero-days in embedded devices.

08

AI for Cyber Security

Specialists in using AI for offensive and defensive cyber security since 2023. Custom systems, run in-house, self-hosted, or in the cloud — on your data, under your control.

09

ISO 27001, NIS2 & NIST

ISO 27001 auditor-qualified consultants for gap analysis, ISMS work and certification support — plus NIS2, NIST CSF 2.0, Cyber Essentials and the technical controls those regimes actually require.

Tell us what you need tested.

Short engagements, senior consultants, and work we actually sign our names to.