Skip to content
Talk to an engineer

About

An engineering firm built around the work that falls between vendors.

Founded in 2026 on a straightforward premise: the problems that hurt an operations business the most are the ones that fall between its vendors, and somebody has to be accountable for the whole of one. Four divisions, staffed separately and briefed together, so the seam is never the customer’s problem to project-manage.

Why we exist

The ceiling we kept hitting.

Every specialist has a ceiling. The managed service provider stops at the firewall. The controls integrator stops at the panel. The ERP partner stops at the data model, the low-voltage contractor stops at the wall, and the security firm arrives once a year and leaves a PDF. Each one is competent inside its own boundary, and none of them owns the space between.

We started this firm because we had been the customer in that position: a folder of vendor contracts, a problem that crossed four of them, and a week of calls establishing only that it was nobody’s. The work that mattered was never inside anyone’s scope. It was in the seams, and the seams are where operations actually break.

So the firm is four divisions rather than one practice with a wide claim. Software, hardware and instrumentation, IT, and security are staffed separately, because pretending one team is expert in all four is how you get a generalist who is a specialist in nothing. They are briefed together, because the seam between them has to be somebody’s job. Small teams of experienced engineers, all in the United States, working directly with the people who do the work rather than through three layers of account management.

That choice has a cost. We lose price-led competitions routinely, and we turn down work in sectors we don’t know. What we get in return is the freedom to take only the work we can finish well.

What we hold to

Two arguments we make on every engagement.

The things you can hold us to (what discovery has to produce, how an engagement ends, what happens when something is not accepted) are contract terms, and they are on the process page rather than here. Cost, ownership and licensing are agreed with you during scoping; the shape of the fee (a fixed-fee discovery, each later phase priced before it starts) is on the process page too.

  • Craft is a business argument

    Tests, documentation and accessibility are not indulgences. They are what makes the fourth year of a system cost less than the first. We treat them as scope, not as extras.

  • Understand the work before changing it

    We go to the warehouse, the plant, the clinic and the truck. Requirements gathered in a conference room describe how people think the work happens.

The bench

Eight disciplines, and something built in each one.

There is no separate sales organization to hand you off from. The person who scopes the engagement is on it, and most engagements draw on more than one of these at once.

  • Distributed state
  • Compilers and language tooling
  • Operational technology security
  • Vulnerability research
  • Applied machine learning
  • Embedded and hardware interfaces
  • Concurrency
  • Geometry and optimization

Each of these is published with something built against it: a compiler front to back, a sharded store on consensus, a detector that finds a changed controller without a signature. Each one carries a written note saying what it is not, which is a harder claim to make than a biography.

When you find out who

Not from this page. We do not publish a team page, and we are new enough that one would be short. The named team on the proposal and the team that arrives are frequently different. Staff turnover is the most reliable predictor of cost and delay on a long engagement.

So what we publish instead is the part that binds us:

  • Key personnel named in the statement of work and not substituted without your consent
  • Interview anyone you want to before they start
  • You can require removal of anyone, for any lawful reason
  • No charge for the ramp-up time of a replacement we initiated
  • All delivery performed in the United States. Nothing subcontracted offshore

Research

Research published by the people who still do the work.

Peer-reviewed and presented work by people on staff, mostly in industrial control security, plus one paper still in review and marked as such below. We cite it because it is checkable, which is the only kind of credential worth putting on a page.

  • IEEE CARS · GCRI

    Anomaly detection in ICS networks with fuzzy hashing

    Similarity-preserving hashes applied to control-network traffic, validated on a multi-vendor PLC bench.

  • RST CON

    Securing interconnected IT and OT systems

    Exploitation and defense of programmable logic controllers across the enterprise boundary.

  • ERAU · NASA · NSF Aero-Cyber

    Anomaly detection for satellite hardware tampering

    Hardware-level tamper indicators on systems that cannot be physically inspected after deployment.

  • NSF INSuRE+E

    SCADA security in interconnected IT and OT environments

    Denial of service, man in the middle and packet manipulation against ladder-logic-driven PLCs.

  • Los Alamos · Idaho National Laboratory

    Presented operational technology research

    Findings reviewed by laboratory researchers, which is a harder audience than an internal report gets.

  • In review

    Automated code vulnerability detection using synthetic training data

    Plus reverse engineering of FPGA bitstreams, and applied vision and audio detection research.

Credentials

Procurement questions, answered before you ask.

Certifications and completed training held by engineers on staff, and the standards we build to. Each row says which of the three it is. What we will and will not sign is on the process page, before anyone sends paper.

Certification

CompTIA Security+
Held on staff, DoDM 8140.03 approved

Certification

CompTIA PenTest+
Held on staff, offensive security practice

Certification

GIAC GFACT
Foundational cybersecurity technologies

Completed training

Red Hat RH124
Course completion, system administration; plus academy instruction

Completed training

CISA ICS 301V / 100W
Course completions, industrial control systems cybersecurity

Completed training

TEEX DHS-certified
DHS-certified course completions: digital forensics, incident response, network assurance, IoT

Standard we build to

NIST 800-171
Aligned controls for CUI handling; not a credential we hold

Standard we build to

WCAG 2.2 AA
Conformance target on every interface we ship; not a credential we hold

Next step

Tell us what’s breaking.

Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether what you already have can be made to work.

Reply
A person replies, not a sequence: within one business day, from someone who would be on the engagement.