Solutions / Defence & Controlled Goods
Cleared work, defensible evidence.
In defence the test is only half the deliverable. The other half is a document that holds up when a prime's security office, a government reviewer or an auditor reads it line by line, months later, looking for the gap. We write for that reader.
- CCCS approved
- National Defence endorsed
- Canadian owned
Sound familiar
The contract is contingent on this.
- A prime made a security attestation a condition of the subcontract award.
- You handle controlled goods and the program office wants evidence, not assurances.
- A supply-chain questionnaire arrived with 140 questions and a two-week deadline.
- Your product has firmware, radios or an uncrewed platform nobody has ever tested.
- Data residency rules rule out most of the firms who quoted you.
- Someone on the board asked what your post-quantum answer is and the room went quiet.
How it works
Scoped against your obligations, not a template.
-
01
Read the requirement first
We start from the contract clause, the questionnaire or the program requirement that triggered this. The scope is built to answer that specific obligation.
-
02
Test the whole chain
Corporate network, engineering environment, build pipeline and the product itself — because a hardened enterprise wrapped around an unsigned firmware update is not a secure supply chain.
-
03
Go after the platform
Embedded and uncrewed systems assessed the way an adversary approaches them: firmware extraction, command-and-control links, telemetry, GNSS dependence and ground-segment trust.
-
04
Evidence, then re-test
An attestation-grade report with methodology and reproduction detail, followed by verification testing so the closure claim is backed by a second result, not an email.
What you get
Paperwork built to be reviewed.
-
Attestation-grade report
Methodology, scope boundaries and evidence a reviewer can audit rather than trust.
-
Supply-chain evidence pack
The answers to the prime's questionnaire, sourced from testing you actually had done.
-
Platform and firmware findings
Embedded, radio and uncrewed-system results with the exploit path, not a CVE list.
-
Verification re-test
Proof the finding is closed, dated and signed, for the next review cycle.
Why us
Canadian owned is not a marketing line here.
For controlled and defence-adjacent work, who owns the firm and where the data sits decides whether the engagement is possible at all. We're Canadian owned, CCCS approved and endorsed by National Defence — which removes the first three objections before the scoping call starts.
We also build offensive tooling ourselves, on the platform our own operators use. That matters when the target is a proprietary platform with no known-vulnerability list to lean on and the work has to be genuinely original.
Send us the clause.
Forward the requirement, the questionnaire or the RFP section that started this. We'll tell you what it actually demands and what it takes to satisfy it — before you scope anything.