About
A software firm built around the part most firms outsource.
Founded in 2026 on a straightforward premise: mid-market and public-sector organizations deserve the same engineering quality that venture-backed software companies buy, and they can have it, if the people building it are senior and in the same time zone.
- To a plan you could hand to another firm
- 2–4 weeksTo a plan you could hand to another firm
- Notice to cancel, any reason
- 30 daysNotice to cancel, any reason
Why we exist
The gap we started in.
There is a category of company (a few hundred to a few thousand people, running something physical or regulated or both) that cannot buy its way out of its software problem. The off-the-shelf platforms are built for a generic version of their process. The large consultancies price them out or staff them with people three years into a career. The offshore option looks cheap until you count the rework and the round trips.
We built the firm for that gap. Small teams of experienced engineers, all in the United States, working directly with the people who do the work rather than through three layers of account management. No bench of juniors to keep busy, and therefore no incentive to make projects larger than they need to be.
That choice has a cost. We lose price-led competitions routinely, and we turn down work in sectors we don’t know. What we get in return is the thing that actually compounds: clients who call us back for the second system, and engineers who stay long enough to be genuinely good at this.
What we hold to
Two things we’re willing to lose work over.
The other two we used to print here are on the process page, where they are commitments rather than sentiments: we will tell you not to build it, and you own everything from the first commit.
Craft is a business argument
Tests, documentation and accessibility are not indulgences. They are what makes the fourth year of a system cost less than the first. We treat them as scope, not as extras.
Understand the work before changing it
We go to the warehouse, the plant, the clinic and the truck. Requirements gathered in a conference room describe how people think the work happens.
The bench
Eight disciplines, and the systems that evidence each one.
There is no separate sales organization to hand you off from. The person who scopes the engagement is on it, and most engagements draw on more than one of these at once.
- Distributed state
- Compilers and language tooling
- Operational technology security
- Vulnerability research
- Applied machine learning
- Embedded and hardware interfaces
- Concurrency
- Geometry and optimization
Each of these is published with something built against it — a compiler front to back, a sharded store on consensus, a detector that finds a changed controller without a signature — and each one carries a written note saying what it is not. That is a harder claim to make than a biography, and it is the one worth reading.
Research
Some of what we know, we found out the hard way.
Peer-reviewed and presented work by people on staff, mostly in industrial control security. We cite it because it is checkable, which is the only kind of credential worth putting on a page.
IEEE CARS · GCRI
Anomaly detection in ICS networks with fuzzy hashing
Similarity-preserving hashes applied to control-network traffic, validated on a multi-vendor PLC bench.
RST CON
Securing interconnected IT and OT systems
Exploitation and defense of programmable logic controllers across the enterprise boundary.
ERAU · NASA · NSF Aero-Cyber
Anomaly detection for satellite hardware tampering
Hardware-level tamper indicators on systems that cannot be physically inspected after deployment.
NSF INSuRE+E
SCADA security in interconnected IT and OT environments
Denial of service, man in the middle and packet manipulation against ladder-logic-driven PLCs.
Los Alamos · Idaho National Laboratory
Presented operational technology research
Findings reviewed by laboratory researchers, which is a harder audience than an internal report gets.
In review
Automated code vulnerability detection using synthetic training data
Plus reverse engineering of FPGA bitstreams, and applied vision and audio detection research.
Credentials & assurance
Procurement questions, answered before you ask.
Certifications and completed training held by engineers on staff, and the standards we build to. Each row says which of the three it is. What we will and won’t sign up to contractually is set out on the process page, in advance of anyone sending paper.
- CompTIA Security+
- CompTIA PenTest+
- GIAC GFACT
- Red Hat RH124
- CISA ICS 301V / 100W
- TEEX DHS-certified
- NIST 800-171
- WCAG 2.2 AA
Certification
Certification
Certification
Completed training
Completed training
Completed training
Standard we build to
Standard we build to
Next step
Tell us what’s breaking.
Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.