Security is what we are expert in, and agentic AI is how we work. Together they decide how each of these is done, and they are why they belong together. Most engagements start with one and grow into another; we will tell you which one fits before you ask, including when the answer is none of them.
Design & Architecture
Decided, not defaulted
Product and software design: what the system is, how its parts divide, where the trust boundaries fall, what the data model has to guarantee, and how it behaves when something fails. Decided deliberately and written down, so that building it is execution rather than a series of improvisations — and so the security properties are structural instead of added afterwards. This is not interface or brand design: we design how a system works, not how it looks.
AI-Driven Development
Agent-assisted, engineer-owned
Design and build, from a first working slice to a system in production. We run a combination of agentic agents across the parts of the work that scale with effort — scaffolding, migrations, test surfaces, refactors, documentation — which shortens the distance between a decision and something running. What does not scale with effort stays with people: the threat model, the key handling and the behaviour under failure are settled in the first weeks, by engineers who sign their name to them. The speed is the agents; the accountability is not.
Distributed Ledger
Trust without an authority
Blockchain-backed architecture, for the cases that genuinely call for one: a record several parties must agree on without appointing one of them as the authority. We will design and build it — and we are equally willing to tell you that a database and a signed audit log would do the same job for a tenth of the cost. That answer is free, and it is the right one more often than the industry admits.
FinTech Systems
Correct to the cent
Design, architecture and implementation of systems that move money or keep score of it: payments, ledgering, settlement, reconciliation and reporting. Built on the standards the sector runs on — ISO 20022 messaging, PCI DSS wherever card data is touched, open-banking interfaces in the line of PSD2 — applied correctly rather than checked off, and with security above all of them: every mistake in financial software is a number someone is owed, so the ledger is double-entry at the core, operations are idempotent, the trail is immutable, and failure leaves the books balanced. From the first design workshop to a system in production.
Consultancy
Adversarial by habit
Architecture review, technical due diligence and second opinions on decisions that are hard to reverse. We read a system the way someone attacking it would, and hand back a document you can circulate and argue with — not a slide deck, and not a list of findings with no order of importance.
Writing & Research
Written to be cited
Books, essays and academic collaboration: the long-form side of the same expertise this company practises — security, distributed systems and how software is built to last — set down where it can be read, cited and disagreed with. We write under our own name and submit to review, and we take part in research rather than sponsor it. We say plainly which claims are settled and which are still arguments.
Fixed scope, time and materials, or a standing arrangement — whichever suits the work. We would rather scope it small and be asked back.
If one of these is the conversation you need, this is where it starts.