Est. 2026Onshore engineering for operations
Security you can
reproduce.
We do the security work that has to hold up under examination: penetration testing and adversarial validation, operational technology and ICS security, compliance engineering, digital forensics and incident response, and cyber ranges. Findings arrive with a reproduction path attached, not as a scanner export with the severities left in.
- Start
- Fixed-fee discovery, 2–4 weeks
- Estimate
- A range, with its assumptions
- Ownership
- Your code, your cloud, day one
- Exit
- 30 days' notice, any reason
- TypeScript
- React
- Next.js
- Python
- Go
- .NET
- PostgreSQL
- Kafka
- Terraform
- Kubernetes
- AWS
- Azure
- Snowflake
- dbt
- React Native
- FHIR
- EDI X12
- OPC UA
- OpenTelemetry
- Modbus
- IEC 62443
- Zeek
- Ghidra
- NIST 800-171
What we’re for
A finding you cannot reproduce is an opinion. A control you cannot evidence is a hope.
This division finds out whether a system is actually secure, proves it to whoever is asking, and answers what happened when it was not. Security is engineered into everything the software division builds — testing whether that succeeded is a separate practice on purpose, so the people checking the work are not the people who did it.
We’ll tell you not to build it
Roughly one in five inquiries ends with us recommending an off-the-shelf product, an internal hire, or doing nothing for another year. Being wrong about this once costs us a project. Being wrong about it consistently costs us the business.
You own everything
Code, infrastructure, accounts and documentation, in your name from the first commit. No escrow, no runtime licence, no clause that makes leaving expensive.
Senior people, small teams
Four experienced engineers beat twelve inexperienced ones on work like this, and cost less. The people who sell the engagement are the people who deliver it; there is no bait-and-switch to a junior bench, because we don’t have one.
Capabilities
Five disciplines, one delivery team.
Most engagements draw on three or four of these at once. They’re listed separately because the work is distinct, not because we hand it between departments.
- Explore
Security & Compliance Engineering
SOC 2, HIPAA, PCI DSS and CMMC treated as engineering work: controls implemented in code and evidence generated automatically.
- Explore
OT & ICS Security
Security engineering for the part of the business that moves physical things: PLCs, SCADA, historians and the flat network somebody built in 2009 and nobody has touched since.
- Explore
Offensive Security & Red Teaming
Penetration testing, adversary emulation, reverse engineering and hardware assessment, reported with a reproduction path and a fix rather than a severity score.
- Explore
Digital Forensics & Incident Response
Disk, memory and log forensics, malware reverse engineering, and incident response with a defensible evidence trail and a report that holds up outside the room it was written in.
- Explore
Cyber Ranges & Security Training
Hands-on training environments, competition platforms and curriculum: instrumented replicas of your estate where people learn by doing the thing, not by watching a slide about it.
Selected work
Systems carrying real load, with the numbers attached.
Client names are withheld under NDA unless the client has agreed to be named. Everything else (the constraints, the sequence, the results) is described as it happened.
Industries
We learn one domain properly before we claim it.
Six sectors we know well enough to be useful in the first meeting, including which of your constraints are regulation and which are convention.
Restaurants & Hospitality
Restaurants, venues and event operations: the floor systems, networks and audio-visual infrastructure that have to work hardest exactly when the room is busiest.
Regulated by
Logistics & Supply Chain
Dispatch, yard, warehouse and visibility systems for carriers, brokers, 3PLs and shippers operating on margins that don’t forgive rework.
Regulated by
Manufacturing & Industrial
Shop-floor execution, quality, maintenance and traceability systems for discrete and process manufacturers with real plants and real constraints.
Regulated by
Energy & Utilities
Field operations, asset management, metering and grid-edge software for utilities, cooperatives, EPCs and energy producers.
Regulated by
Public Sector & Defense
Citizen services, case management and mission systems for federal, state and local agencies, plus the primes and subs who deliver for them.
Regulated by
Higher Education & Research
Research security, sponsored-program systems, cyber ranges and workforce pipelines for universities, research institutes and the federal programs that fund them.
Regulated by
How it works
Five phases. You can stop after any of them.
Every phase has a defined exit, and the exit is always yours to take. That constraint is what keeps the work honest.
- Phase 1
First call
One conversation to work out whether this is a problem we should be working on together.
- Phase 2
Discovery
Paid, fixed-scope, and it ends in a plan you could hand to another firm, plus working code proving the riskiest assumption.
- Phase 3
First release
A small senior team ships something genuinely useful into production. Real users, real data, real load.
- Phase 4
Iterate & scale
The system grows against evidence from production rather than against a plan written before anyone used it.
- Phase 5
Hand-off
Planned from the first week, so that leaving is a scheduled event rather than a negotiation.
Engineering practice
Depth you can interrogate, not adjectives.
Nobody hires us to build a compiler or a consensus store. They hire us to build the systems that turn out to be those things with the name filed off, and we would rather be tested on that early than trusted on a brochure.
Status accepted 2026-03-04, supersedes ADR-0009Context Legacy pricing is 140k lines of stored procedures, no test suite, four known-wrong edge cases the business depends on.Decision Run both engines on every request for two billing cycles. Legacy stays authoritative, ours is shadow-scored and diffed nightly.Cut over Nightly diff empty for ten cycles running.Cost About 6% added write-path latency until then. Accepted.Rejected Big-bang cutover behind a flag. The flag was never the risk. The absence of a comparison was.Distributed state
Consensus, replication, partition ownership and the reconfiguration problems that only appear when the topology changes underneath live traffic.
Compilers and language tooling
Intermediate representations, dataflow analysis, and the discipline of choosing a model that makes every later stage cheap rather than merely correct.
Operational technology security
Industrial protocol traffic, anomaly detection on deterministic networks, and peer-reviewed research on why enterprise tooling does not transfer.
Vulnerability research
Attack-surface modelling, source review and variant analysis carried out against live third-party systems under public disclosure programs, where a claim is worth nothing until it reproduces.
Applied machine learning
End-to-end pipelines where the modelling is the last and smallest step, built around evaluation sets, honest baselines and calibrated confidence.
Embedded and hardware interfaces
The full path from register-transfer logic through a bus interface and a kernel driver to a user-space program, with each layer brought up and verified in order.
Concurrency
Synchronization primitives implemented from the ground up, in both a forgiving runtime and an unforgiving one, until the higher-level tools stop being magic.
Geometry and optimization
Computational geometry and graph search written from primitives, with benchmarking that regularly contradicts what the asymptotics suggested.
Insights
What we’ve learned, written down.
No gated PDFs, no thought-leadership. These are the arguments we end up making in real client meetings.
- Security8 min read
In vulnerability research, most of the work is ruling things out
We hunt on public disclosure programs between engagements. The part that transfers to paid work is not the findings. It is the machinery for discarding the forty candidates that looked exactly like them.
- Engineering5 min read
Whether you can investigate a breach was decided months ago
The questions asked after an incident are answerable only if somebody made specific, unglamorous logging decisions long before it happened. Almost nobody does.
- Security7 min read
CMMC on the shop floor: scope is the only lever that matters
A prime asked for your certification status and now the plant network is the problem. Almost all of the cost in a Level 2 assessment is decided before a single control is implemented — and since Phase 2 was suspended in July 2026, the person asserting your posture is you.
Next step
Tell us what’s breaking.
Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.