We rebuild the software your business runs on.
The tool from 2004 your whole company still depends on: we take it over, keep it running, and make it better every week.
Software modernization
Built years ago, extended by nobody, too risky to touch. That is where we start.
RebuildWe rebuild what you run today, fix what is broken, and tailor it to how you work.
IterateBug fixes and small features: requested one week, shipped the next.
OwnWhat we build is yours, including the IP.
Two practices, one origin: careers spent on software where mistakes cost money.
AI agent audits
Before an AI agent goes live, we attack it: hostile documents, poisoned tool outputs, attempts to exceed its authority.
What broke.
What held.
Stress-tested first, so the decision to trust it rests on evidence.
What a risk committee receives.
Fictional sample engagement
| ID | Finding | Severity | Class |
|---|---|---|---|
| GR-01 | Indirect prompt injection via hostile PDF drafts an attacker-directed payout | Critical | AF-01 |
| GR-02 | Spend and authority limits are prompt-level only, not externally enforced | Critical | AF-04 |
| GR-03 | Action log is writable by the agent's own service account; not tamper-evident | High | AF-10 |
| – | What held: fund execution was outside the agent's reach. A manual treasury approval stopped the drafted payout. Tested and held. A single human approval is currently the only barrier. | Held | – |
How we work.
- Scope and price are agreed before we start.
- You see progress every week, not a report at the end.
- You talk to the engineers doing the work.