Security-first software for regulated organisations

Since 2011 we have built resilient software for regulated industries, bringing cybersecurity, compliance, and customer journeys together.

Get in Touch Explore Our Products

Who We Are

We are a Lisbon-based team of architects, security engineers, and product strategists dedicated to shipping software that financial institutions and critical infrastructure can trust. Every engagement follows our four pillars: design-first discovery, secure SDLC, compliance built in, and measurable outcomes.

That approach has helped Siemens, Nokia, SIX Group, and other leaders modernise payments, automate SOC workflows, and bring new digital products to market faster.

Products

Three products we build, run, and stand behind. Pick one to see how it is put together.

Sovereign AI Platform

Marmot

Marmot is a local AI deployment your people can actually use, with a border post in front of the internet. One machine holds the chat interface, the local model and your documents, and has no route out. A second holds the cloud credentials and decides, for every single request, whether it may leave.

  • The machine holding your documents has no route to the internet
  • A per-request decision, made in exactly one place
  • Users can force local, and can never force cloud
  • A decision log you can check against your own firewall telemetry
Learn More Get in Touch
How the gate works
A
Your documents, chat, local model

No route to the internet. It can refuse, it cannot send.

B
The border post

The only machine holding cloud credentials. It decides, and it logs.

Stays local Anything touching protected material
Allowed out Answered by a frontier model
Air-Gapped Attack Surface Management

Ibex

Security for the networks the cloud can't reach. Ibex is one sealed appliance inside your perimeter that maps the network, audits the code, reads the posture of your databases and tests the AI running on them, then ties findings to the host they run on. No connection, inbound or outbound, and every finding exported ready for an auditor.

  • Network discovery, shadow assets and shadow AI, compared against your baseline
  • Code audit with nine lenses and blind verification, offline
  • Database posture across PostgreSQL, MySQL, SQL Server, Oracle and MongoDB
  • AI discovery, posture and red-team, with findings tied to the host they run on
Learn More Get in Touch
One sealed box, the whole attack surface
The internet No connection, inbound or outbound
Your perimeter
■
Ibex appliance

Your hardware, models run on the box.

Network segments OT and ICS passive only
Repositories Nine lenses, offline
Databases Read from the catalog
Models and agents Discovered and tested
Verified findings, exported for the auditor SARIF findings, audit PDF and ML-BOM, as files rather than a connection
Self-Service Code Audit

Goshawk

Goshawk turns the source-code security audit into software. Nine independent lenses sweep the repository, every finding is handed to a blind second reviewer instructed to refute it, severity is computed rather than estimated, and the report maps to the framework you actually answer to.

  • Nine lenses, each reading the code with its own question
  • Blind adversarial verification: what survives refutation, ships
  • CVSS v4.0 computed by a deterministic library, never guessed by a model
  • Two tiers, stated honestly: automated scan, or full audit with senior review
Learn More Get in Touch
How a finding earns its place
  1. On every audit
  2. Nine lenses sweep the code

    Each lens reads the repository with its own question, from injection to access control, in parallel.

  3. A blind reviewer attacks each finding

    The second reviewer sees only the claim and its location, and is instructed to refute it. What is refuted is dropped.

  4. Severity is computed

    A full CVSS v4.0 vector per finding, scored by a deterministic library. No model estimates a number.

  5. A defensible report

    Mapped to ISO 27001, NIS2 or the Portuguese national regime, in English and Portuguese.

Where it runs Fully managed, or hybrid: scanning inside your perimeter, judgment in the cloud

Clients

Fintech, telecom, and critical-infrastructure leaders we have shipped for.

SIX Group
Nokia
Siemens
DGEG
Leaseplan
The Lisbon Concierge
Nestle Waters
Holmes Place

Want to see one of these running?

Tell us what you run and we will show you the product that fits.