The same people who write our tools and publish our research do the client work. There is no separate delivery bench.
Source-level review of the parts that matter: authentication, key handling, crypto usage, and the trust boundaries between your services. You get findings with reproductions, not a scanner dump.
Scoped, authorised testing against your applications and infrastructure, with a written rules-of-engagement agreement before anyone touches anything.
Structured STRIDE-style analysis of a system before it ships, mapped to concrete mitigations and owners. Cheapest security work you will ever buy.
Practical training for engineering, support, and leadership teams. Built on the same material Uwitz Juniors teaches, adapted for people with production access.
Strong security is expensive to produce and gets priced accordingly, which pushes it out of reach of exactly the people most exposed to surveillance. Corporate exists so we can charge the organisations that have a security budget and give the results away to the ones that don't.
It also keeps us off the funding models that would compromise the work: no advertisers, no data brokers, and no money that comes with a say in what we publish.
Engagement findings stay confidential to the client. What we publish about third-party software is the core team's call, and paying us doesn't buy a veto.
We take the minimum access needed for the scope, hold artefacts only as long as the engagement requires, and hand back or destroy them at the end.
Into the open-source tools, the public research, and Uwitz Juniors workshops. Reported alongside donations, down to the line item.