The company

Every product ships complete.

Uwitz builds commercial, audited security software — no feature-gated editions, no stripped-down free tiers. What you buy is the full product with committed support, indemnity, and engineering behind it.

Structure

Two entities, deliberately separated

Uwitz writes the software, publishes the research, and runs the education programme.

Uwitz Corporate — this company — develops and supports commercial security products. Every product is paid, audited, and shipped complete — no free tiers, no open-source editions. We also sell managed infrastructure, audits, pentests, and engineering time.

Keeping the two entities apart means the software company and the commercial entity have clearly separated responsibilities.

UwitzSoftware

Develops software. Publishes independent research and disclosures. Runs Uwitz Juniors. Funded by transfers from this company.

uwitz.org →
Uwitz CorporateCommercial

Develops and supports commercial security products. Operates managed infrastructure. Sells audit, pentest, and deployment engineering. Holds the customer contracts and liability.

you are here
Commitments

Five things we will not trade away for revenue

These are written into how the two entities relate to each other, not just into a values page.

No artificial feature gates

Every product ships complete. There are no stripped-down editions designed to upsell you later — what we sell is guarantees, support, and engineering time, not access to features we already built.

Zero-knowledge by architecture

Our systems are designed so we cannot hand over what we never held. Server-to-server transport uses AES-256-GCM with ML-KEM post-quantum key exchange. Zero-trust by default — mutual authentication on every connection, no implicit network trust.

Findings belong to the client

Audit and pentest reports are yours to publish in full. We will not ask for an embargo to protect a commercial relationship, ours or anyone else's.

No advertising, no data brokers

Our only revenue is contracts and engineering hours. Customer data is never a product, an input to one, or a bargaining chip in a funding round.

Proprietary by design

We build custom, business-grade software tailored to each company's security requirements. Proprietary code is never open-sourced — it stays closed to prevent scraping, unlicensed self-hosting, and exposure of client-specific infrastructure.

Who we work with

Teams that cannot outsource their trust

Newsrooms, healthcare providers, legal practices, financial firms, and infrastructure operators — organisations where a breach is not an embarrassment but a direct harm to someone who trusted them.

We also turn work down. If an engagement's purpose is to build surveillance capability against a population, or to produce a certificate rather than a secure system, we are not the right supplier and we will say so on the first call.

Start a conversation
Where we operate

Engineering is distributed across the EU and the US.

Legal entity

Uwitz Corporate is not yet a fully incorporated entity — we are preparing to legally register and operate in Estonia in the foreseeable future. We operate under a Founder's Agreement from Uwitz, which governs our relationship and is available to parties we work with upon request. Contracts and liability are held by Uwitz Corporate. Financial transactions are processed via a Financial Representative based in Malaysia.

Billing and remittance →

Tell us what you are building.

Every engagement starts with a conversation, not a checkout page. We scope to your requirements and send an honest number back.

See the products Contact sales