Four ways we get hired.
Pick the one closest to your situation. If none of them fits, the scoping call sorts it out. We scope before we quote, and the quote is fixed.
Pentest & Red Team
We attack the system the way somebody else would: from outside, over the air, without credentials you did not hand out. Then we give your engineers the exact path we took, in the order we took it.
For teams with a system already in the field.
Scope a pentest- Wireless and OT penetration testing
- Physical intrusion over the air
- Automotive, V2X and vehicle buses
- Adversary simulation against a real objective
- Findings shared as we go, not only at the end
- A report ranked by what an attacker would do
- Reproduction steps and captures
- A retest once you have fixed them
Security Audits
Architecture and implementation review against the radio and embedded attack surface, with remediation your team can actually ship inside the release you are already planning.
For product teams before a release or a certification.
Scope an audit- Architecture and threat-model review
- Firmware and bootchain review
- Hardware inspection and port discovery
- Radio configuration and provisioning review
- A prioritised remediation plan
- Evidence you can hand to a certifier
- Design guidance for the next revision
- A follow-up review of the fixes
Vulnerability Research
Long-form research against a target of your choosing: protocol fuzzing, baseband analysis and CVE-grade findings, written up in full and disclosed the way you want them disclosed.
For vendors and operators funding deep work.
Discuss a research scope- Protocol and stack fuzzing
- Baseband and modem analysis
- Reverse engineering of proprietary radio
- Exploit development where it is warranted
- Full technical write-up
- Proof-of-concept tooling you keep
- Coordinated disclosure support
- CVE publication where appropriate
R&D & Tooling
Custom SDR tools, testbeds and secure product development consulting, built on the same stack as RF Swift so your team can keep running it after we leave.
For teams building their own capability.
Discuss your R&D needs- Custom SDR tool development
- Testbed and lab construction
- Secure development consulting
- Knowledge transfer to your engineers
- Tooling with source, documented
- A lab your team can operate alone
- Architecture guidance in writing
- Hands-on handover sessions
Tell us what transmits. We will tell you what it leaks.
One call to scope it, a fixed proposal after. Intrusion tests, vulnerability hunting, fuzzing, testbeds, trainings. Offices near Paris, Mon to Fri 09:00 to 19:00.