// security · malmö, sweden
Security you can prove, not just promise
We harden the software you build and run, and help you meet the Cyber Resilience Act with evidence that survives an audit, not a compliance slide deck.
// what we do
Security that maps to a real threat model
Most breaches are not clever attacks, they are a missing patch, a forgotten secret or an overly permissive policy. We close those gaps and keep the evidence along the way.
Cyber Resilience Act readiness
The CRA applies to products with digital elements sold in the EU, from firmware to SaaS. We map your product to the essential requirements, figure out what already exists and build a realistic plan before the deadlines land.
Security architecture review
We read the code, the networking and the identity model, then give you a prioritized list of what to fix and what is actually fine. No checkbox theatre, no scare slides.
Threat modeling
We sit with your team, walk the attack surface and write down the threats that matter for your product, then decide which controls actually reduce risk.
Secure software supply chain
Signed builds with Sigstore, SBOMs that are actually useful, dependency scanning wired into CI and a practical playbook for when a CVE drops on a Friday night.
Vulnerability management
Not every CVE is a patch. We help you build an intake that separates the noise from the real exposure and a cadence that keeps you safe without chasing every advisory.
Incident response
A clear runbook, tested in advance, so that when something happens you know who does what and when to call in help. We drill the scenario before it is real.
// the path
From unknown exposure to evidence you can hand over
- 01→InventoryMap your product, its components and their provenance.
- 02→AssessCompare against the CRA essential requirements and your own risk.
- 03→HardenFix the controls that move the needle, in the right order.
- 04→EvidenceCollect the records an auditor actually wants to see.
- 05MaintainA cadence for scanning, patching and re-assessment.
// tooling
The security stack we work with
// our take
What we do not believe in
Security by checklist. A list of controls with nobody knowing why they exist is a liability, not a defence. Every control we recommend has a threat behind it.
Blame the victim of the bug. When a vulnerability slips through, the fix is a better process, not a harder conversation. We build systems that make the right thing the easy thing.
Compliance theatre. The CRA is a legal obligation, but the honest reading of it is good engineering. We aim for the outcome, and the paperwork follows.
// faq
Common questions
Does the Cyber Resilience Act apply to us?
If you sell a product with digital elements into the EU, chances are it does, or will shortly. That includes connected hardware, software and many SaaS services. We help you work out whether your product is in scope before investing in the full program.
When does the CRA take effect?
The regulation has been adopted and obligations phase in over the coming years, with many reporting duties landing before the full product requirements. We track the timeline for you and keep the plan realistic against the dates that matter for your product.
We already pass security scans. Why do we need help?
A scanner finding an issue is not the same as knowing your risk. Compliance under the CRA is about evidence and process: provenance, vulnerability handling and documentation. We build the parts a scanner cannot see.
Are you engineers or compliance consultants?
Engineers. We write the code, build the pipelines and operate the platforms, so the evidence we help you collect is generated by real systems, not a questionnaire filled in from memory.
// how we work
// contact
Not sure if the CRA applies to your product?
Tell us what you build and we will tell you where you stand.
office: Malmö, Sweden · uppdrag across Europe