Services : Available Now
Classical cryptography sunsets under FIPS 140-3 on September 21, 2026, and EU AI Act energy disclosure has been in force since August 2, 2026. These engagements exist because the deadlines are real and most organizations are not ready. Every deliverable is something a third party can verify without taking our word for it.
The tool is public. Reproduce the result yourself.
No-Egress Supply-Chain Audit
You tell customers, regulators, or your own security team that your software runs on-prem with no telemetry. That claim is only as strong as your ability to prove it. We audit your codebase for network-capable imports, git remote operations, shell execution, dynamic code execution, and external references in shipped markup, then sign the result so anyone can verify it without trusting us.
- · Signed, tamper-evident report you can hand to a customer or regulator
- · Findings classified by whether they touch shipped code, tests, or docs
- · The same auditor wired into your CI, so every future build re-proves it
Stated up front, because it is part of the value: static analysis of a Turing-complete language cannot mathematically prove zero egress. This catches the entire class of realistic and accidental egress plus the common deliberate patterns. The report says exactly that, in its own body.
The auditor is open source: clone it and check our work →FIPS 140-3 classical sunset: September 21, 2026
Post-Quantum Cryptography Migration
Classical cryptography (RSA, ECDH, ECDSA) sunsets under FIPS 140-3 in September 2026. We inventory your cryptographic surface, design the ML-KEM (FIPS 203) + ML-DSA (FIPS 204) migration path, and build cryptographic agility in, so the next algorithm transition is a configuration change, not a redesign.
- · Cryptographic inventory & risk map
- · Migration architecture (ML-KEM + ML-DSA)
- · Agility layer: swap algorithms without protocol redesign
EU AI Act GPAI enforcement: August 2, 2026
AI Energy Disclosure & Attestation
The EU AI Act requires general-purpose AI providers to disclose training and inference energy. Most organizations cannot measure it. We deploy a working attestation pipeline that measures energy per workload and per token, and signs the records at the source, so they are machine-verifiable and independently auditable.
- · Per-workload / per-token energy measurement
- · Machine-signed attestation records
- · Regulator-ready disclosure documentation
Provenance is becoming table stakes
Content Provenance & Integrity
Signed provenance chains for organizations that need to prove where their content, data, and model outputs came from, built on the same post-quantum signing core as the attestation work above. C2PA is the alignment target for the manifest format; the engagement delivers the provenance chain and the signing infrastructure.
- · Signed provenance chains, capture to publication
- · Signature infrastructure on a conformance-tested ML-DSA (FIPS 204) path
- · Manifest format aligned to the C2PA claim model
Fixed-fee engagements with a performance royalty tail. Covenant terms in every contract: systems optimized for the people receiving them, structurally.
Start a conversation →