A written scope with explicit in- and out-of-bounds systems, agreed before anything is signed.
Signed authorisation, named contacts on both sides, and an escalation path for anything urgent.
Critical findings are reported the day we find them. You never learn about a live hole from a PDF.
Included in the original price. Verifying your fix is part of the job, not a follow-on sale.
Source-level review of the systems you ship: cryptographic design, authentication and session handling, key management, and the trust boundaries between your services.
You own the report. Publishing it in full is your right by default — we will not ask you to sit on findings, and we will put our name on the version you release.
Scope an auditAuthorised, scoped, and evidenced testing across network, application, and cloud estates. Every finding arrives with the exact steps to reproduce it and a fix we would accept ourselves.
We test what you asked us to test. If we spot something outside scope, you hear about it immediately and free of charge — it does not become next quarter's proposal.
Book a testGetting Irys into production without a freeze window. Migration plans, cutover rehearsals, rollback paths, and the runbooks your team will actually be holding at 3am.
The goal is to make ourselves unnecessary. Documentation and infrastructure definitions are yours from day one, written so your engineers can take over rather than re-hire us.
Plan a migrationWe build software tailored to your organisation's needs, integrated with your systems and security posture. Every engagement produces proprietary, closed-source code — never open-sourced, never shared.
You own the code from day one. Full source in your repository, under your review process, with documentation and handover so your engineers can maintain it without us.
Discuss your projectNamed engineers, contracted response times, and a private disclosure channel that reaches the people who wrote the code. Every tier reaches a person — none of them reach a queue.
Security patches are covered regardless of tier. We are not going to make you buy a higher plan to receive a fix for a vulnerability we shipped.
Discuss coverage