Services

Design, develop, pentest, remediate. And the regulation that sits over all four.

The four engineering services run as one loop, so the people who threat-modelled a system are the ones who attack it and the ones who fix it. The consultancy practice applies the same standard of evidence to regulation, assurance and the safe adoption of AI tooling.

1 · Design

Secure design and threat modelling

Before architecture, we name what the system protects, who wants it and where trust changes hands. The threat model is a working document with a control register: for every claimed control, the code line that enforces it and the test that goes red when it is removed. Controls that turn out to be intentions rather than code are listed as such, because an assessor will find them anyway.

What you get

  • A system decomposition: processes, sockets, on-disk state and the environment variables that change the attack surface
  • Trust boundaries with STRIDE analysis on each, and attack trees for the threats STRIDE cannot express
  • An attacker catalogue tied to your sector's threat profile
  • Cryptographic architecture with algorithm agility designed in, so a future migration is a bounded change rather than a rewrite
  • A compliance architecture mapped to the frameworks you will be assessed against

From ExPriori: a threat model with 13 trust boundaries, 3 attack trees, a control register of claim, enforcing line and revert-sensitive test, and a documented list of the blind spots it does not cover.

2 · Develop

Secure software development

We build in Rust, test-first, with every requirement carried in a traceability register and every governance rule turned into a gate that continuous integration runs. The default posture is fail-closed: a command that cannot do the work refuses it by name rather than printing a success message, and a listener that would reach beyond a private network refuses to start unless the operator says otherwise.

What you get

  • Requirements engineering first, acceptance criteria second, failing tests third, code fourth
  • A requirements traceability matrix whose statuses can only advance on code-level evidence
  • Continuous integration with governance gates: scaffold markers, stale evidence, unreachable controls, documentation currency, supply-chain policy
  • Cryptography reached only through registries, with known-answer tests against independent implementations
  • Installers, browser consoles and operator documentation that state honestly what the product does and does not yet do

From ExPriori: an 11-crate Rust workspace of more than 440,000 lines, more than 4,500 tests, more than 600 traced requirements, a signed Windows installer and a browser console served from the binary itself.

3 · Pentest

Penetration testing

Testing is scoped from the threat model, not from a tool's default profile. Every engagement runs under written rules of engagement with a standing authorisation, an evidence standard, a severity scale and a disclosure policy. Findings go into an exploit catalogue with a position, a rung on the escalation ladder and a citation to the line of code, and each is reproduced on a rig before it is reported. A finding that cannot be reproduced is a lead, and is labelled one.

What you get

  • Rules of engagement ratified with you before anything is touched
  • An exploit catalogue with reproducible steps and code citations, re-verified against the head you ship
  • Attacker positions covered and, just as important, the positions no engagement has yet occupied
  • A severity that says what was established, and by what evidence, rather than a colour
  • Mechanical checks you keep: for unreachable controls, environment-derived principals, unread exit status and feature-gated tests nobody enables

From ExPriori: a programme whose re-derived catalogue found that the dominant defect class was not a broken control but an unreachable one, in four independent subsystems. The check that finds that class now runs in CI.

4 · Remediate

Remediation

A finding is closed when the class is fixed, not the instance. Each remediation ships with a regression test that fails if the fix is undone, an updated entry in the compliance map for every control the change touches, and a note in the risk register recording what was found, what was done and what still stands. Where the honest answer is that a risk is accepted, the acceptance is recorded with a reason and a review date.

What you get

  • Fixes that close the defect class, with the mechanical check that would have caught it
  • A regression gate per finding, run on every later change
  • Compliance evidence updated in the same change as the code
  • A risk register that scores from evidence, and says not established where nobody has measured

From ExPriori: dealer-plane modules that led one catalogue were closed by compilation, with a probe crate that requires each removed symbol to be absent from the default build. That is the strongest form of gate we know how to build.

5 · Consultancy

Cyber-security regulation, assurance and the safe adoption of AI

The consultancy practice draws on the founder's experience inside UK government cyber-security regulation and on the compliance engineering done for ExPriori. It is practical work: gap analyses that name the missing evidence, not the missing paragraph.

Regulatory readiness

NIS Regulations 2018 and the Cyber Security and Resilience Bill, the NCSC Cyber Assessment Framework and GovAssure, the CAF-aligned DSPT, NIS2 and DORA for organisations serving EU entities.

Assurance and certification

Cyber Essentials and Cyber Essentials Plus readiness, ISO/IEC 27001 alignment, the Software Security Code of Practice, DCB0129 clinical safety and DTAC for health technology, UK GDPR and DPIAs.

Supply chain and AI tooling

Software bills of materials, dependency policy and licence posture; and a governed way to adopt AI coding assistants, with secure-coding rules, verification passes and measured cost.

The regulation page explains each framework and how we help

Engagement shapes

Three ways to work with us

Assessment

Fixed scope, fixed price

A threat model, a penetration test, a regulatory gap analysis or a code review with a written scope, a start date and a deliverable you can hand to your board or your assessor.

Build

Milestone-based delivery

Design, development, testing and remediation of a system or a component, delivered against milestones with the evidence trail growing alongside the code.

Retained

Advisory days each month

A standing arrangement for organisations that want a security engineer and a regulation specialist on call: design reviews, assessor preparation, incident support, second opinions.