Services
Consulting first. Custom software when a report is not enough — built around the tools you already have.
Cyber security consulting
Assessments and advice across offensive testing, cloud, attack surface, secure development, and response. We write reports that non-specialists can act on, and we stay close to the teams doing the work.
Penetration testing
Web applications, web services, infrastructure, and red team exercises designed to test whether controls actually work.
Attack surface management
A clear view of what you own and where the risk sits — using the data you already have, not only what can be seen from the public internet. When you need more than a review, we also build software to keep that picture current.
Cloud security
Architecture, configuration, and tooling across Azure and AWS — including rolling out standards that teams can actually follow.
Secure software delivery
SecDevOps, secure SDLC pipelines, static analysis, and source code review so applications are built securely rather than tested at the end.
Incident response
Investigation, triage, and working alongside in-house teams when something has already gone wrong.
Threat intelligence and architecture
Network design, threat intelligence, and practical advice on IT and security projects.
Software for clients
We build security software for clients when off-the-shelf tools leave gaps. It is designed around the tooling you already run, with custom integrations so existing data can be used to understand risk.
Custom integrations
We connect to the security tools you already have so that data can be used to judge risk on assets. That might mean internal vulnerability scanning to understand exposure, or Akamai and Cloudflare to see whether a WAF is in place that could mitigate a finding. The work is custom — if you run it, we can integrate with it.
Attack surface software
Software built around an inside-out view of the estate: DNS, IP, and cloud inventory, combined with the tools you already operate, so you are not guessing at what you own.
Scanning at scale
When the estate is large, we can add scanning that scales in the cloud so tens of thousands of applications can be assessed in a short window.
Security automation
Replacing manual processes with reliable tooling so security teams spend less time copying data between systems.