The commercial arm of Uwitz

What we secure internally.
Secured for you.

Uwitz Corporate develops and supports commercial security software — and audits the systems you already run. Same source, same guarantees, with contracts behind them tailored to your organisation.

Every product here is source-available. Read it before you buy it.

root@eu-west-1
$ irys up
detached signature valid
signed byUwitz Corporate
fingerprint8F2A 41C9 D7B0 C1E7
reproducible build matched
sha256e3b0c44298fc1c14…
transparency log entry #48213
$
Source availability
100%

Every product ships with the source you can audit.

Transport
ML-DSA-87

Post-quantum TLS 1.3 across our estate and yours.

Builds
Reproducible

Signed, logged, and byte-for-byte verifiable.

Billing regions
EU · US · UK

Payments accepted via SEPA, ACH, and CHAPS.

Products

Commercial security products

Every product ships complete with committed support, indemnity, and engineering behind it.

Spotlight — Irys SSO

One identity.
Every internal system.
None of it ours.

Irys is not just single sign-on — it is a full identity and access platform. Custom company-specific authentication, utility and resource control, and agents installed on every server for centralized visibility, control, and IDS/IPS. All encrypted with AES-256-GCM + ML-KEM.

Server agents with IDS/IPS. Installed on every server, providing real-time visibility, intrusion detection and prevention across your entire infrastructure.
Custom authentication. Company-specific policies, step-up triggers, and device posture checks — configured as code, versioned and auditable.
Portable on day one. Standard protocols in and out, so adopting Irys is never the reason you cannot leave it.
Explore Irys SSO Book a walkthrough
IRYS SSO Authenticated
TL
Theo Lindqvist
theo@uwitz.org
YubiKey 5C
Entitled systems
Vaultadmin
Consolewrite
Gitmaintain
Mailmember
VPNeu-west
Billingdenied
session 8h · step-up on privileged writes policy.yaml @ 3f9c2a1
Services

Engineering hours, not a retainer you never use

All services →

Security audits

Source-level review of the systems you ship. You get the findings, the reproduction steps, and permission to publish the whole thing.

Penetration testing

Scoped, authorised, and evidenced. Network, application, and cloud engagements with a retest included rather than sold back to you.

Deployment engineering

Migration onto Irys without a freeze window. We write the runbooks, hand them over, and stay on the call until they hold.

Support contracts

Named engineers, defined response times, and a disclosure channel that reaches the people who wrote the code.

How we are structured

Two entities. One codebase. No conflict of interest.

Uwitz develops software. Uwitz Corporate develops and supports commercial security products — and funds Uwitz's work with the margin.

The two entities are deliberately separated so the people building the software and the people selling it have different responsibilities.

How the structure works
UwitzOpen source

Builds and publishes the tools. Runs independent research and the education programme. Funded by donations and by this company.

uwitz.org →
Uwitz CorporateCommercial

Develops and supports commercial security products, runs managed infrastructure, and sells audit and engineering time. Contracts and liability live here.

you are here
Start a conversation

Tell us what you are defending. We will tell you whether we are the right people.

No discovery-call funnel. A real engineer reads the first message and answers with scope, timeline, and a number.

Contact sales See what we do