Expertise

Six areas, each exercised end to end, none of them tied to one sector

Firebed's product is its expertise. Each area below was demonstrated on ExPriori from an empty repository onward, and each transfers to any organisation that has to prove its software is secure: a bank, an insurer, a pharmaceutical company, a government department or a health system anywhere.

Area 1

Threat modelling and penetration testing

Demonstrated by: a threat model with 13 trust boundaries, STRIDE on each and three attack trees; a control register that records claim, enforcing line and revert-sensitive test; penetration-test rules of engagement with a standing authorisation and an evidence standard; an exploit catalogue re-derived against each new head; a test rig that reproduces findings before they are reported.

Where it transfers: any product with a network listener, a browser surface, a parser or a build pipeline. The method is independent of the domain; only the assets and attackers change.

Area 2

Applied and post-quantum cryptography

Demonstrated by: implementations of FIPS 203 ML-KEM-1024 and FIPS 204 ML-DSA-87 whose provenance is evidenced by byte-level agreement with the independent PQClean reference in both directions; a cross-library known-answer vector programme; hybrid signatures with a forensic classifier that distinguishes a stale form from manipulation; registries for every executed algorithm so that a new suite is added by registration rather than by rewrite. Stated honestly: the implementations are not FIPS-validated and hold no CAVP certificate.

Where it transfers: finance, government, health, legal: any organisation whose data must stay confidential for longer than today's public-key algorithms will survive.

Area 3

Compliance engineering

Demonstrated by: a 49-outcome map of the CAF-aligned Data Security and Protection Toolkit to code, tests and evidence, kept current in the same change as the code it cites; a UK GDPR data inventory, flow map and draft DPIA; a DCB0129 clinical safety case; a DTAC assessment; Cyber Essentials readiness; a map to the Software Security Code of Practice; supply-chain policy with software bills of materials. The map is gated: a framework edition stamp is checked, and the day the 2026-27 DSPT changed its mandated outcomes entirely, the gate is what caught it.

Where it transfers: every regulated sector, and the NCSC Cyber Assessment Framework in particular, because the DSPT is built on it.

Area 4

Secure-by-design software engineering

Demonstrated by: an 11-crate Rust workspace of more than 440,000 lines and more than 4,500 tests; more than 600 requirements traced from register to code to test, with statuses that advance only on code-level evidence; fail-closed defaults for every command and every listener; continuous integration that fails when a scaffold marker, a stale document or an unreachable control appears; a signed Windows installer and a browser console served from the binary itself.

Where it transfers: any team that has to prove what its software does, to a customer, an assessor or a court.

Area 5

Identity, consent and data sovereignty

Demonstrated by: W3C verifiable credentials and decentralised identifiers issued and verified end to end; a consent gate in front of every computation; Solid pod integration behind an adapter that keeps the platform agnostic to who hosts the pod; a linking ceremony between machines that requires both operators to approve a matching code.

Where it transfers: any collaboration where organisations must compute together without surrendering their data or their identity infrastructure.

Area 6

AI-assisted, governed delivery

Demonstrated by: fifteen written secure-coding rules for agentic workflows, each with the defect class it prevents and the mechanical check that enforces it; a delivery workflow in which the strongest model designs, writes the failing tests, implements and adversarially verifies every security-relevant change; a cost block on every tranche stating wall-clock time, tokens by model and price; and Firebed's standing as a verified organisation in Anthropic’s Cyber Verification Program.

Where it transfers: any organisation adopting AI coding assistants that wants the productivity without the unreviewed code.

The standard behind all six

Everything on this page rests on one rule that ExPriori enforces in its own repository: a status advances only on implementation-level evidence, never on a test count. Tests written against a scaffold pass by asserting the scaffold's own behaviour, so a green suite is not proof that a protocol is implemented. Every scaffold carries a marker that continuous integration counts, every known-answer test is cross-checked against an independent implementation, and every claim no run has yet shown is written believed, unverified until one does.

That rule is uncomfortable, and it is the reason our evidence is worth reading.

Evidence on request

The ExPriori repository is private during its Beta. Prospective clients can be walked through the threat model, the exploit catalogue, the compliance map and the continuous-integration gates on request, under an appropriate agreement.