How we work

Every security evaluation, including authorized penetration testing, starts with written authorization and stays inside an agreed scope. It moves from findings to fixes to a retest.

This page covers security evaluations. For chip design projects, see Secure chip design.

Authorization comes first

Nothing is tested until the system owner has authorized the work in writing and the scope is agreed.

If you are commissioning the work for the owner, the owner signs the authorization. We test only systems you own or are authorized to have tested.

Owning a device does not by itself let you authorize us to circumvent protections that belong to someone else, such as a supplier’s or manufacturer’s authentication. For that we need that party’s written authorization.

Steps and sign-offs

Every full evaluation follows these six steps. A step marked Hold point must be signed off before work continues. Steps 3 to 6 happen only inside the authorized scope.

Safe testing

If testing could affect safety, or could reach anything outside the agreed scope, we stop and contact you before going further.

We test only in the agreed test windows and within the agreed limits.

Confidential handling

How we treat the samples, firmware and data you give us.

  • We keep your samples, firmware and data confidential.
  • We store them with access limited to whoever works on your evaluation, and use AI-assisted analysis tools on them only if you have agreed to it in writing.
  • We return or destroy them within 30 days of close-out.

AI-assisted analysis

With your written agreement, we may use AI-assisted analysis tools during an evaluation, only on material inside the authorized scope. Before we start, we tell you that the tool provider keeps a copy of what we submit, and we use these tools only if you accept that in writing.

Work we decline

We do not take on:

  • Testing without the system owner’s written authorization
  • Work outside an agreed scope
  • Requests to circumvent another party’s protections without that party’s authorization

Start an evaluation

Email us what the system is, who owns it, and whether the owner has authorized testing.

Request a security evaluation