We rebuild the software your business runs on.

The tool from 2004 your whole company still depends on: we take it over, keep it running, and make it better every week.

Software modernization

Built years ago, extended by nobody, too risky to touch. That is where we start.

How an engagement runs

RebuildWe rebuild what you run today, fix what is broken, and tailor it to how you work.
IterateBug fixes and small features: requested one week, shipped the next.
OwnWhat we build is yours, including the IP.

Two practices, one origin: careers spent on software where mistakes cost money.

AI agent audits

Before an AI agent goes live, we attack it: hostile documents, poisoned tool outputs, attempts to exceed its authority.

The method, the engagements, the sample report

What broke.

What held.

Stress-tested first, so the decision to trust it rests on evidence.

What a risk committee receives.

Fictional sample engagement

Findings summary from the fictional sample gate-review report
IDFindingSeverityClass
GR-01Indirect prompt injection via hostile PDF drafts an attacker-directed payoutCriticalAF-01
GR-02Spend and authority limits are prompt-level only, not externally enforcedCriticalAF-04
GR-03Action log is writable by the agent's own service account; not tamper-evidentHighAF-10
What held: fund execution was outside the agent's reach. A manual treasury approval stopped the drafted payout. Tested and held. A single human approval is currently the only barrier.Held
From the sample gate-review report, prepared as a fictional engagement. Request the sample report.

How we work.

  • Scope and price are agreed before we start.
  • You see progress every week, not a report at the end.
  • You talk to the engineers doing the work.

More about the firm

Let's talk.

The people on the call are the engineers who would do the work.