Verified organisation · Anthropic Cyber Verification Program

Design. Develop. Pentest. Remediate. One team, one evidence trail.

Firebed is a software engineering, cybersecurity and IT consultancy. We build software that is secure by design, attack it under written rules of engagement, fix what we find, and leave a record that a regulator or an auditor can follow. Our founder brings inside experience of UK government cyber-security regulation, and ExPriori, a privacy-preserving computation platform for NHS data, is our end-to-end proof.

  1. 1DesignThreat model, trust boundaries, cryptographic and compliance architecture before a line is written.
  2. 2DevelopRust, tests before code, every requirement traced, governance gates in continuous integration.
  3. 3PentestRules of engagement, an exploit catalogue derived from the threat model, reproducible on a rig.
  4. 4RemediateFix the class, add the regression gate, update the compliance map in the same change.

What Firebed does

Three practices, one standard of evidence

Whether we are writing code, breaking it or advising on regulation, the deliverable is the same: a claim you can check, with the evidence attached.

Software engineering

Secure-by-design systems in Rust, from the threat model to the installer. Requirements traced to code and tests, fail-closed defaults, and continuous integration that refuses a change whose evidence has gone stale.

Development services

Cybersecurity

Threat modelling, penetration testing and remediation as one programme rather than three events. Findings are catalogued, reproduced and closed with a test that goes red if the fix is ever undone.

Security services

IT consultancy and regulation

Practical readiness for the NCSC Cyber Assessment Framework, the NIS Regulations and their successor Bill, the DSPT, Cyber Essentials and UK GDPR, written by someone who has applied them outcome by outcome to a real codebase.

Regulation services

Proven on ExPriori

Expertise exercised end to end on one codebase, transferable to your sector

ExPriori is an independent, not-for-profit project that Firebed undertook in the public interest: privacy-preserving multi-party computation for NHS data, free to NHS organisations in perpetuity. Every area below was exercised on it from an empty repository to a penetration-tested, post-quantum-ready Beta candidate. None of it depends on the health sector.

Area of expertiseDemonstrated byTransfers to
Threat modelling and penetration testing13 trust boundaries, STRIDE on each, attack trees, written rules of engagement, an exploit catalogue and a test rigAny product with a network, a browser or a parser
Applied and post-quantum cryptographyFIPS 203 ML-KEM-1024 and FIPS 204 ML-DSA-87, known-answer vectors cross-checked against PQClean, crypto-agility registriesFinance, government, health: anything whose data must outlive today's algorithms
Compliance engineeringA 49-outcome CAF-aligned DSPT map, UK GDPR and a DPIA, DCB0129 clinical safety, DTAC, Cyber Essentials readiness, the Software Security Code of PracticeEvery regulated sector; the NCSC CAF in particular
Secure-by-design engineeringAn 11-crate Rust workspace, more than 4,500 tests, fail-closed defaults, more than 600 traced requirements, honest status enforced in CIAny team that has to prove what its software does
Identity and data sovereigntyW3C verifiable credentials, decentralised identifiers, Solid pod integration, a consent gate in front of every computationCross-organisation data collaboration in any sector
AI-assisted, governed delivery15 secure-coding rules for agentic workflows, adversarial verification of every security-relevant change, measured costAny organisation adopting AI coding tools safely

Regulation, from the inside

We have sat on the regulator's side of the table

Firebed's founder worked in UK government cyber-security regulation: the NIS Regulations 2018, the NCSC Cyber Assessment Framework that competent authorities assess against, and the policy that became the Cyber Security and Resilience Bill now before Parliament. That experience shapes how we read a control: not as a checkbox, but as a claim that an assessor will ask you to evidence.

How we help with NIS, the CAF, the DSPT and Cyber Essentials

49CAF-aligned DSPT outcomes mapped to code and evidence
13trust boundaries in the threat model, each STRIDE-analysed
4,500+tests, with known-answer vectors cross-checked against independent implementations
600+requirements traced from register to code to test

Working with AI, under verification

Frontier models for defensive security, with the guard rails written down

Firebed is a verified organisation in Anthropic’s Cyber Verification Program. The programme admits organisations doing legitimate defensive security work to Claude’s dual-use cyber capabilities, which are restricted by default. It is a verification of who we are and what we do, not an endorsement of our services, and we say so plainly.

What matters more is how we use it. ExPriori was built with AI-assisted engineering under a written set of fifteen secure-coding rules for agentic workflows, an adversarial verification pass on every security-relevant change, and a measured cost for every tranche of work. A control with no call site on the path it guards is indistinguishable at runtime from one that was never written; our rules exist because we found exactly that class of defect and now test for it mechanically.

How Firebed works

Reviews

What people say about working with Firebed

Every review shown here was written by a named person, published with their permission, and can be withdrawn on request.

Write a review

Start a conversation

Tell us what you are building, what you have to comply with, or what keeps you awake. We reply to every message.

Contact Firebed

Contribute to ExPriori

Engineers, cryptographers, security testers, information-governance and clinical-safety specialists: the project keeps a register of expressions of interest.

Register your interest