Security Audits
Architecture and implementation review against the radio and embedded attack surface, with remediation your team can actually ship inside the release you are already planning.
- A design or product is heading for release or certification
- You want problems found before customers do
- You need remediation you can actually schedule
- A certifier will ask for evidence
- The system is already deployed and you want it attacked, that is a pentest
- You want a single protocol researched in depth, that is vulnerability research
How it runs.
You hear from us during, not only at the end. A finding that matters does not wait for the report.
Scoping
What is being built, what it has to pass, and which parts of the stack are in scope. We agree the inputs we need from your side.
Review
Architecture and threat model first, then implementation: firmware, bootchain, radio provisioning and hardware.
Findings
Each issue with its impact, the standard it touches, and a fix your team can ship in the release you are already planning.
Retest
A follow-up pass once the fixes land, with evidence a certifier will accept.
What lands on your desk.
Something an engineer can act on and something a board can read, plus everything needed to reproduce a finding without calling us.
- Audit report
- Findings mapped to the attack surface and the relevant standards
- Remediation plan
- Prioritised, with effort estimates your team can schedule
- Certifier evidence
- Documentation packaged for the certification body
- Design guidance
- What to change in the next revision
- Retest report
- Confirmation of what was fixed
What we can attack.
Pick the rows that apply and we will tell you the days each one costs.
All services| Target | What that involves |
|---|---|
| Radio architecture | Trust boundaries, key handling, provisioning and update paths |
| Firmware and bootchain | Secure boot, signing, rollback protection, secrets at rest |
| Hardware | Debug ports, external interfaces, tamper resistance |
| Provisioning | How devices get their identities and keys in the factory and field |
| Compliance | Radio, product-security and sector-specific requirements |
Questions we get asked.
Do you certify products?
No. We are not a certification body. We produce the evidence and remediation a certifier will want, and we have sat on the other side of that table.
How early can you start?
As early as an architecture diagram. The earlier we look, the cheaper the fixes are.
Tell us what transmits. We will tell you what it leaks.
One call to scope it, a fixed proposal after. NDAs signed before we talk details, if that is how your procurement works.