Security built into the product, not bolted on at the end.
Our background
For over 25 years we have been building and maintaining complete Linux distributions, auditing embedded devices, and running managed server infrastructure — shipping and operating systems where a mistake means bricked devices or exposed user data. Work on the Nokia N9 and the Jolla phone are two of the more visible chapters.
That experience shapes how we approach security: as something you design in from the first commit, not a phase you add before launch.
What "secure by design" looks like
A concrete example: the developer mode for the Jolla phone. From the very beginning, the images were built to allow a developer to log in, register the device for R&D, and transfer it to a fully developer-capable unit. This avoided the classic trap of trying to strip developer tools and debug access closer to launch — a process that almost never works cleanly and usually leaves holes.
The same thinking applies to any system we touch:
- Build security assumptions into the architecture, don't retrofit them
- Developer access and production hardening can coexist if planned for
- Updates, rollback, and recovery are part of the threat model
How we work
We are not a traditional security audit consultancy. We do not compete in that market, and we are not interested in becoming another name on a compliance checklist.
What we do is embed in product teams and bring systems-level security expertise where it matters: during design, during implementation, and during the build and delivery pipeline. If you are building a product that runs Linux — embedded, mobile, or infrastructure — we can help you avoid the mistakes that only show up after shipping.
That said, we do take dedicated security review engagements when the work is a good fit: architecture reviews, hardening assessments, and targeted audits of systems we understand deeply.
Where it connects
Our RFID and NFC work feeds directly into this. Physical access systems, token-based authentication, and proximity protocols have their own threat models — and we have the equipment and experience to test them properly.