Security-first software for regulated organisations
Since 2011 we have built resilient software for regulated industries, bringing cybersecurity, compliance, and customer journeys together.
Get in Touch Explore Our ProductsWho We Are
We are a Lisbon-based team of architects, security engineers, and product strategists dedicated to shipping software that financial institutions and critical infrastructure can trust. Every engagement follows our four pillars: design-first discovery, secure SDLC, compliance built in, and measurable outcomes.
That approach has helped Siemens, Nokia, SIX Group, and other leaders modernise payments, automate SOC workflows, and bring new digital products to market faster.
Services
Every engagement starts with collaborative design sprints and regulatory due diligence so the software we ship is tailor-made, auditable, and resilient. We audit source code against OWASP ASVS, and we embed with your teams to accelerate secure delivery of mission-critical fintech and security programmes.
Products
Three products we build, run, and stand behind. Pick one to see how it is put together.
Marmot
Marmot is a local AI deployment your people can actually use, with a border post in front of the internet. One machine holds the chat interface, the local model and your documents, and has no route out. A second holds the cloud credentials and decides, for every single request, whether it may leave.
- The machine holding your documents has no route to the internet
- A per-request decision, made in exactly one place
- Users can force local, and can never force cloud
- A decision log you can check against your own firewall telemetry
Ibex
Ibex audits your source code where it lives, and hands you the proof that NIS2 and DORA ask for. Nine lenses read the whole codebase, every finding is verified and mapped to the provisions it touches, and the audit runs on a sealed appliance inside your perimeter, on a cloud instance of your own, or as a hybrid of the two. The same platform maps your network and governs the AI inside it.
- Nine lenses plus software composition analysis, with every finding verified
- Mapped to OWASP ASVS 5.0, NIS2 Article 21 and DORA, finding by finding
- Air-gapped, where the report is the only thing that leaves, or cloud, or hybrid
- Attack surface, shadow detection and AI governance on the same platform
Goshawk
Goshawk turns the source-code security audit into software. Nine independent lenses sweep the repository, every finding is handed to a blind second reviewer instructed to refute it, severity is computed rather than estimated, and the report maps to the framework you actually answer to.
- Nine lenses, each reading the code with its own question
- Blind adversarial verification: what survives refutation, ships
- CVSS v4.0 computed by a deterministic library, never guessed by a model
- Two tiers, stated honestly: automated scan, or full audit with senior review

