Services

Engineers who have to live with the answer.

The same people who write and maintain Uwitz take the engagements. That means findings come with a working reproduction and a fix you could actually ship — not a CVSS score and a wish of luck.

How an engagement runs

Four steps, no surprises

1
Scope

A written scope with explicit in- and out-of-bounds systems, agreed before anything is signed.

2
Authorise

Signed authorisation, named contacts on both sides, and an escalation path for anything urgent.

3
Execute

Critical findings are reported the day we find them. You never learn about a live hole from a PDF.

4
Retest

Included in the original price. Verifying your fix is part of the job, not a follow-on sale.

Security audits

Source-level review of the systems you ship: cryptographic design, authentication and session handling, key management, and the trust boundaries between your services.

You own the report. Publishing it in full is your right by default — we will not ask you to sit on findings, and we will put our name on the version you release.

Scope an audit
Typically covers
Cryptographic design — key derivation, rotation, storage, and the failure modes of each.
Authentication and sessions — token lifetimes, revocation, replay, and privilege boundaries.
Data handling — what you collect, where it rests, and what an attacker gets with one database.
Supply chain — dependency provenance, build reproducibility, and release signing.
Threat model — written down, argued with you, and kept as a living document afterwards.

Penetration testing

Authorised, scoped, and evidenced testing across network, application, and cloud estates. Every finding arrives with the exact steps to reproduce it and a fix we would accept ourselves.

We test what you asked us to test. If we spot something outside scope, you hear about it immediately and free of charge — it does not become next quarter's proposal.

Book a test
Engagement types
External perimeter — internet-facing surface, exposed services, and the paths between them.
Web and API — authorisation logic, tenant isolation, and business-logic abuse rather than scanner output.
Cloud configuration — IAM blast radius, key exposure, and what one leaked credential really reaches.
Assumed breach — start from a compromised laptop or token and measure how far it goes.

Deployment engineering

Getting Irys into production without a freeze window. Migration plans, cutover rehearsals, rollback paths, and the runbooks your team will actually be holding at 3am.

The goal is to make ourselves unnecessary. Documentation and infrastructure definitions are yours from day one, written so your engineers can take over rather than re-hire us.

Plan a migration
What you get
Migration plan — sequenced, reversible, and rehearsed against a copy of your environment first.
Infrastructure as code — in your repository, under your review process, from the first commit.
Runbooks — failure modes, recovery steps, and break-glass procedures your on-call can follow cold.
Handover — working sessions with your team until they can run it without us on the call.

Proprietary code development

We build software tailored to your organisation's needs, integrated with your systems and security posture. Every engagement produces proprietary, closed-source code — never open-sourced, never shared.

You own the code from day one. Full source in your repository, under your review process, with documentation and handover so your engineers can maintain it without us.

Discuss your project
What we build
Custom applications — built to your specifications, your security level, and your infrastructure.
System integrations — connecting your existing tools and services into cohesive workflows.
Security-hardened tooling — purpose-built utilities and services with post-quantum encryption by default.
Handover — documentation, infrastructure definitions, and working sessions with your team.

Support contracts

Named engineers, contracted response times, and a private disclosure channel that reaches the people who wrote the code. Every tier reaches a person — none of them reach a queue.

Security patches are covered regardless of tier. We are not going to make you buy a higher plan to receive a fix for a vulnerability we shipped.

Discuss coverage
Contract terms
Named engineers — you know who is on the other end, and they know your deployment.
Severity-tiered response — written into the contract with credits if we miss, not aspirational targets.
Private disclosure channel — encrypted, monitored, and answered by engineering rather than triage.
Advance notice — you hear about relevant vulnerabilities before the public advisory goes out.

Send us the scope. We will send back a number.

If the work is not something we are good at, we will say so and point you at someone who is.

Contact sales