Software engineering
Secure-by-design systems in Rust, from the threat model to the installer. Requirements traced to code and tests, fail-closed defaults, and continuous integration that refuses a change whose evidence has gone stale.
Verified organisation · Anthropic Cyber Verification Program
Firebed is a software engineering, cybersecurity and IT consultancy. We build software that is secure by design, attack it under written rules of engagement, fix what we find, and leave a record that a regulator or an auditor can follow. Our founder brings inside experience of UK government cyber-security regulation, and ExPriori, a privacy-preserving computation platform for NHS data, is our end-to-end proof.
What Firebed does
Whether we are writing code, breaking it or advising on regulation, the deliverable is the same: a claim you can check, with the evidence attached.
Secure-by-design systems in Rust, from the threat model to the installer. Requirements traced to code and tests, fail-closed defaults, and continuous integration that refuses a change whose evidence has gone stale.
Threat modelling, penetration testing and remediation as one programme rather than three events. Findings are catalogued, reproduced and closed with a test that goes red if the fix is ever undone.
Practical readiness for the NCSC Cyber Assessment Framework, the NIS Regulations and their successor Bill, the DSPT, Cyber Essentials and UK GDPR, written by someone who has applied them outcome by outcome to a real codebase.
Proven on ExPriori
ExPriori is an independent, not-for-profit project that Firebed undertook in the public interest: privacy-preserving multi-party computation for NHS data, free to NHS organisations in perpetuity. Every area below was exercised on it from an empty repository to a penetration-tested, post-quantum-ready Beta candidate. None of it depends on the health sector.
| Area of expertise | Demonstrated by | Transfers to |
|---|---|---|
| Threat modelling and penetration testing | 13 trust boundaries, STRIDE on each, attack trees, written rules of engagement, an exploit catalogue and a test rig | Any product with a network, a browser or a parser |
| Applied and post-quantum cryptography | FIPS 203 ML-KEM-1024 and FIPS 204 ML-DSA-87, known-answer vectors cross-checked against PQClean, crypto-agility registries | Finance, government, health: anything whose data must outlive today's algorithms |
| Compliance engineering | A 49-outcome CAF-aligned DSPT map, UK GDPR and a DPIA, DCB0129 clinical safety, DTAC, Cyber Essentials readiness, the Software Security Code of Practice | Every regulated sector; the NCSC CAF in particular |
| Secure-by-design engineering | An 11-crate Rust workspace, more than 4,500 tests, fail-closed defaults, more than 600 traced requirements, honest status enforced in CI | Any team that has to prove what its software does |
| Identity and data sovereignty | W3C verifiable credentials, decentralised identifiers, Solid pod integration, a consent gate in front of every computation | Cross-organisation data collaboration in any sector |
| AI-assisted, governed delivery | 15 secure-coding rules for agentic workflows, adversarial verification of every security-relevant change, measured cost | Any organisation adopting AI coding tools safely |
Regulation, from the inside
Firebed's founder worked in UK government cyber-security regulation: the NIS Regulations 2018, the NCSC Cyber Assessment Framework that competent authorities assess against, and the policy that became the Cyber Security and Resilience Bill now before Parliament. That experience shapes how we read a control: not as a checkbox, but as a claim that an assessor will ask you to evidence.
How we help with NIS, the CAF, the DSPT and Cyber Essentials
Working with AI, under verification
Firebed is a verified organisation in Anthropic’s Cyber Verification Program. The programme admits organisations doing legitimate defensive security work to Claude’s dual-use cyber capabilities, which are restricted by default. It is a verification of who we are and what we do, not an endorsement of our services, and we say so plainly.
What matters more is how we use it. ExPriori was built with AI-assisted engineering under a written set of fifteen secure-coding rules for agentic workflows, an adversarial verification pass on every security-relevant change, and a measured cost for every tranche of work. A control with no call site on the path it guards is indistinguishable at runtime from one that was never written; our rules exist because we found exactly that class of defect and now test for it mechanically.
Reviews
Every review shown here was written by a named person, published with their permission, and can be withdrawn on request.
Firebed is a new firm and this space is kept honest: no review appears here until a client, collaborator or reviewer has written one and agreed to its publication. Be the first to write one.
Tell us what you are building, what you have to comply with, or what keeps you awake. We reply to every message.
Engineers, cryptographers, security testers, information-governance and clinical-safety specialists: the project keeps a register of expressions of interest.