Area 1
Threat modelling and penetration testing
Demonstrated by: a threat model with 13 trust boundaries, STRIDE on each and three attack trees; a control register that records claim, enforcing line and revert-sensitive test; penetration-test rules of engagement with a standing authorisation and an evidence standard; an exploit catalogue re-derived against each new head; a test rig that reproduces findings before they are reported.
Where it transfers: any product with a network listener, a browser surface, a parser or a build pipeline. The method is independent of the domain; only the assets and attackers change.
Area 2
Applied and post-quantum cryptography
Demonstrated by: implementations of FIPS 203 ML-KEM-1024 and FIPS 204 ML-DSA-87 whose provenance is evidenced by byte-level agreement with the independent PQClean reference in both directions; a cross-library known-answer vector programme; hybrid signatures with a forensic classifier that distinguishes a stale form from manipulation; registries for every executed algorithm so that a new suite is added by registration rather than by rewrite. Stated honestly: the implementations are not FIPS-validated and hold no CAVP certificate.
Where it transfers: finance, government, health, legal: any organisation whose data must stay confidential for longer than today's public-key algorithms will survive.
Area 3
Compliance engineering
Demonstrated by: a 49-outcome map of the CAF-aligned Data Security and Protection Toolkit to code, tests and evidence, kept current in the same change as the code it cites; a UK GDPR data inventory, flow map and draft DPIA; a DCB0129 clinical safety case; a DTAC assessment; Cyber Essentials readiness; a map to the Software Security Code of Practice; supply-chain policy with software bills of materials. The map is gated: a framework edition stamp is checked, and the day the 2026-27 DSPT changed its mandated outcomes entirely, the gate is what caught it.
Where it transfers: every regulated sector, and the NCSC Cyber Assessment Framework in particular, because the DSPT is built on it.
Area 4
Secure-by-design software engineering
Demonstrated by: an 11-crate Rust workspace of more than 440,000 lines and more than 4,500 tests; more than 600 requirements traced from register to code to test, with statuses that advance only on code-level evidence; fail-closed defaults for every command and every listener; continuous integration that fails when a scaffold marker, a stale document or an unreachable control appears; a signed Windows installer and a browser console served from the binary itself.
Where it transfers: any team that has to prove what its software does, to a customer, an assessor or a court.
Area 5
Identity, consent and data sovereignty
Demonstrated by: W3C verifiable credentials and decentralised identifiers issued and verified end to end; a consent gate in front of every computation; Solid pod integration behind an adapter that keeps the platform agnostic to who hosts the pod; a linking ceremony between machines that requires both operators to approve a matching code.
Where it transfers: any collaboration where organisations must compute together without surrendering their data or their identity infrastructure.
Area 6
AI-assisted, governed delivery
Demonstrated by: fifteen written secure-coding rules for agentic workflows, each with the defect class it prevents and the mechanical check that enforces it; a delivery workflow in which the strongest model designs, writes the failing tests, implements and adversarially verifies every security-relevant change; a cost block on every tranche stating wall-clock time, tokens by model and price; and Firebed's standing as a verified organisation in Anthropic’s Cyber Verification Program.
Where it transfers: any organisation adopting AI coding assistants that wants the productivity without the unreviewed code.