Services

Consulting first. Custom software when a report is not enough — built around the tools you already have.

Cyber security consulting

Assessments and advice across offensive testing, cloud, attack surface, secure development, and response. We write reports that non-specialists can act on, and we stay close to the teams doing the work.

  • Penetration testing

    Web applications, web services, infrastructure, and red team exercises designed to test whether controls actually work.

  • Attack surface management

    A clear view of what you own and where the risk sits — using the data you already have, not only what can be seen from the public internet. When you need more than a review, we also build software to keep that picture current.

  • Cloud security

    Architecture, configuration, and tooling across Azure and AWS — including rolling out standards that teams can actually follow.

  • Secure software delivery

    SecDevOps, secure SDLC pipelines, static analysis, and source code review so applications are built securely rather than tested at the end.

  • Incident response

    Investigation, triage, and working alongside in-house teams when something has already gone wrong.

  • Threat intelligence and architecture

    Network design, threat intelligence, and practical advice on IT and security projects.

Software for clients

We build security software for clients when off-the-shelf tools leave gaps. It is designed around the tooling you already run, with custom integrations so existing data can be used to understand risk.

  • Custom integrations

    We connect to the security tools you already have so that data can be used to judge risk on assets. That might mean internal vulnerability scanning to understand exposure, or Akamai and Cloudflare to see whether a WAF is in place that could mitigate a finding. The work is custom — if you run it, we can integrate with it.

  • Attack surface software

    Software built around an inside-out view of the estate: DNS, IP, and cloud inventory, combined with the tools you already operate, so you are not guessing at what you own.

  • Scanning at scale

    When the estate is large, we can add scanning that scales in the cloud so tens of thousands of applications can be assessed in a short window.

  • Security automation

    Replacing manual processes with reliable tooling so security teams spend less time copying data between systems.