Hardware Security
We get onto the board. We seek for debug interfaces, secure boot, TEE, fault and side-channel analysis on ARM SoCs. We love picking the physical stuff people assume is safe because it's hard to do.
Hardware security, firmware engineering, software and the network it all runs on. We build it to be resilient, understand it down to the silicon, and maintain it for you in the long run.
The problem01
Ever felt that moment when you open a board and realise nobody on your team has ever read the bootloader? The vendor wrote it, someone signed it, and it's been running your product ever since. That is the story of most hardware. It works right up until you need to patch it, or defend it. All destined for a common fate: where breaches start and maintainability suffers.
We fill that gap, diving into the parts that no longer "just work", rebuilding them to survive, and running the network that they live on.
What we believe02
Undocumented silicon, stripped binaries, protocols nobody wrote down. Give it enough patience and the right probes and it all opens up eventually.
A system is considered secure when it keeps working in conditions nobody planned for. We go looking for those exact conditions on purpose.
The nastiest failures sit where hardware hands off to firmware, or firmware hands off to the next EL. We work across all of them, so nobody gets to say "not my scope."
Most engagements end with a PDF. Ours end when the next board revision ships, the next device passes, and the 3 a.m. incident is closed.
How we work01
Board in hand, we map what's really there. Debug ports, boot chain, storage, radios, and the vendor blobs sitting in between. Nothing gets judged before we understand it.
How we work02
We pull the firmware, disassemble the binaries apart, sniff the bus and the air. Piece by piece the undocumented parts show up: hidden commands, unsigned update paths, keys that never should have shipped. What you never knew, and what your thread model has to cover now.
How we work03
We fix it at the surface that broke. Secure boot that actually checks signatures. Firmware that fails closed instead of open. All built on the one assumption that a component is already compromised.
How we work04
We host it, watch it, and keep it patched on infrastructure we operate ourselves. The system stays understood because the people who took it apart are still watching it.
Our capabilities
We get onto the board. We seek for debug interfaces, secure boot, TEE, fault and side-channel analysis on ARM SoCs. We love picking the physical stuff people assume is safe because it's hard to do.
We pull closed firmware apart to see what it really does, then rebuild it properly as needed. Bootloaders, drivers, and update paths that don't brick the device when something goes wrong.
We engineer software that holds up when things get weird. Tooling, test harnesses, services. Written so someone can actually read and audit it later, not just ship it.
We run our own IP network (AS206215) along with hosting services. And we've learned a lot doing it. Infrastructure, segmentation, day-to-day operations for your devices and services. Plus a few projects of our own.




















And yes, that's our canary, making sure the servers are up. It's also proficient at breaking open MMU page tables, pumpkin and melon seeds.
Start a conversation