Software built with the attacker in the room

Web, mobile, desktop and security tooling. Every release gets attacked before it ships, and you own all of it.

What we build

Already built it? We’ll test it
  1. Android · iOS

    Mobile apps

    Android and iOS apps that keep data on the phone.

  2. macOS · Windows

    Desktop apps

    Native software that handles files carefully and asks before it acts.

We break software for a living, with permission. So we build the way we wish every team did.

House rules

Designed against OWASP ASVS, OWASP MASVS, NIST SSDF and SLSA.

How we work
  • Threat model first

    What it protects, from whom, and where it is weakest. Written before the features.

  • Least privilege, least data

    Every role and token starts at nothing. Data we never collect can’t leak.

  • Dependencies on purpose

    Each package earns its place. Versions pinned, every change scanned.

  • Tests that prove behaviour

    Logic and permission checks are tested on every change.

  • Secrets out of the code

    In a secret store or the platform keychain. Never in the repo or the bundle.

How a build runs

  1. Discovery

    A call and a short brief: who uses it, what data it holds, what it must never do. Then a written quote.

  2. Design

    Screens, data model, interfaces and the threat model, agreed with you.

  3. Short iterations

    Something you can click, install or run every week or two.

  4. Security review

    Built in

    Every release gets a pentest before it ships. We fix what it finds.

  5. Launch

    Hosting, signing, stores or pipelines, signed off with you against a checklist.

  6. Support

    Fixes, patches and answers for an agreed period after launch.

What we reach for first

We pick the stack for the job, and tell you why before we quote.

Web applications and APIs

  • Interface

    AstroReactNext.js

    Astro when a site should ship almost no JavaScript. React or Next.js for an application.

  • APIs and back end

    TypeScriptNode.js

    TypeScript end to end, so the interface and the API agree.

  • Data

    PostgreSQL

    Constraints and permissions live in the database as well as in the code.

More on web apps

Mobile apps

  • Android

    KotlinJava

    Kotlin for new work. Java where a codebase needs it, as in Aegis’s native plugin.

  • iOS

    SwiftSwiftUI

    The Keychain and the privacy prompts used the way Apple intends.

  • Cross-platform

    CapacitorReact Native

    One codebase for both platforms, native code where it has to be.

More on mobile apps

Desktop apps

  • macOS

    SwiftSwiftUI

    Native for Apple silicon.

  • Windows

    .NETWinUI

    For software that should feel at home on Windows.

  • Cross-platform

    TauriElectron

    One app everywhere. Node stays out of the renderer.

More on desktop apps

Security tooling and DevSecOps

  • Languages

    PythonGoSwift

    Python for glue, Go for fast single-binary scanners, Swift for macOS internals.

  • Pipelines

    GitHub ActionsGitLab CI

    Gates live where your code already builds.

  • Analysis

    SASTDASTSCA

    Static analysis on every change, dynamic scans on staging, dependency checks on every lockfile.

  • Output

    SARIF

    SARIF 2.1.0, so findings land in the tools you already use.

More on security tooling
Do you only build security products?

No. Web apps, mobile apps, desktop software and internal tools, for any kind of business. Security is how we build.

Can one project use both practices?

Yes. We can test an existing app, then fix what we found or rebuild the weakest part.

How do you price a build?

After a discovery call you get a written quote for a defined scope. No two builds are alike, so there is no price list.

Tell us what to build. We’ll tell you how.

Who it’s for, what it has to do, when you need it. We’ll book a call and send a written quote.