Skip to content

Services

From the first pixel to the last private key.

Ten disciplines that we practise properly rather than list optimistically. Take one of them, or let us join the pieces up for you.

Design Website

A site is the first security signal a customer reads. We make it look like the company you actually are.

  • Discovery, information architecture and copy direction
  • A reusable design system, not a one-off page
  • Responsive and accessible to WCAG 2.2 AA
  • Core Web Vitals, SEO and analytics wired in

Web Hosting & Maintenance

Hosting is not a commodity when the site carries your certificates, your forms and your reputation.

  • Hardened Linux hosts with TLS and HSTS by default
  • Nightly backups with restores tested, not assumed
  • Uptime, latency and certificate-expiry alerting
  • Monthly patching and dependency review

Email Hosting

Business email on your own domain, configured so it arrives and so nobody can send as you.

  • SPF, DKIM and DMARC published and monitored
  • Anti-spam and anti-malware filtering
  • Shared calendars, contacts and mobile sync
  • Archiving and retention to match your policy

YubiKey & HSM Integration

Move private keys out of configuration files and into hardware you can hold in your hand.

  • YubiHSM 2 provisioning and PKCS#11 wiring
  • YubiKey PIV enrolment, issuance and revocation
  • Dual-control and M-of-N key ceremonies, documented
  • Key rotation and recovery procedures your team can run

Root CA Integration

A certificate authority is easy to install and hard to run. We do the part that comes after installation.

  • Certificate Policy and CPS drafted with you
  • Offline root ceremony, backup and witness records
  • OCSP, CRL and timestamping endpoints published
  • Enrolment via ACME, SCEP, EST or REST for your apps

Keycloak Customization

Keycloak does almost everything out of the box. The last ten percent, the part that matches how your organisation actually signs in, is where we come in.

  • Realm, client and role design mapped to how your teams really work
  • Custom authentication flows: step-up, risk-based and hardware-token login
  • Provider plugins (SPI) for your own user stores, credentials and audit sinks
  • Login themes, email templates and account console in your own brand

FTP Integration

Most breaches we are called in to review begin with a file that moved the wrong way.

  • Migrate legacy FTP to SFTP or FTPS without retraining users
  • Certificate, SSH CA or hardware-token based access
  • Event triggers that push files into the systems that need them
  • Full transfer audit trail with retention and search

N8N Automation Workflow

Automate the handoffs between your systems instead of hiring around them.

  • Self-hosted n8n inside your own network
  • Custom nodes for your internal and legacy APIs
  • Approval gates, retries and error routing that pages a human
  • Runbooks, versioning and observability for every workflow

Develop Web Application

Product engineering with the security model designed in on day one, not bolted on at go-live.

  • Java and Spring Boot backends with clean, documented APIs
  • Vaadin or server-rendered Thymeleaf for the user interface
  • SSO, role-based access control and audit logging built in
  • CI/CD, infrastructure as code and load testing before launch

Develop Mobile Application

Native Android and iOS applications, or one Kotlin Multiplatform codebase, working with your security model rather than around it.

  • Jetpack Compose on Android, Swift on iOS, or Compose Multiplatform for both
  • Biometric, certificate and hardware-key authentication
  • Offline-first sync and conflict handling
  • Store submission, phased rollout and release management

Engagement

Three ways to work with us.

Whichever you pick, the deliverable includes documentation your own engineers can act on without calling us first.

Assessment

Fixed fee, 2 to 3 weeks

We review what you have — PKI, transfer channels, hosting, application security — and hand back a prioritised, costed remediation plan.

  • Architecture and threat-model review
  • Key management and certificate inventory
  • Written findings with severity and effort
  • Executive summary for the board

Build

Fixed scope, milestone billed

We design and deliver the system: a root CA, an SftpS deployment, an automation platform, a web or mobile product.

  • Architecture and policy documents
  • Two-week increments with live demos
  • Security review inside the build
  • Runbooks, training and handover

Operate

Monthly retainer

We keep it running: monitoring, patching, certificate lifecycle, incident response and a named engineer who knows your estate.

  • 24/7 monitoring and alerting
  • Patch and dependency management
  • Certificate expiry and CRL health watch
  • Quarterly review with a written report

Not sure which of the ten you need?

Describe the problem in plain language. We will tell you which discipline it belongs to, even if the answer is that you do not need us.