Services

Three ways in. One way to keep it true.

Every engagement produces evidence you keep — a report, a file, a record an auditor or buyer can open. Start with whichever rung matches the decision you need to make this quarter.

Where to start

Start small. Judge the work first.

Three productised ways in, each priced and scoped up front (all prices exclude VAT). Small enough to expense, useful enough to stand alone — a second engineer’s eyes on your firmware, risks surfaced before a buyer or regulator finds them.

Sample report

Free

no email required

Published — read it now

A complete firmware readiness review in the exact format a paid engagement delivers, applied to a public open-source subject — the Matter bridge reference application. Nothing is redacted; every finding can be checked against public source, line by line.

  • The complete report — findings, remediation roadmap, evidence annexes
  • Real findings with severity and fix priorities
  • The exact structure a buyer or auditor sees
  • Every claim checkable against public source at a pinned commit
  • Published openly — no form, no email, no drip sequence

Readiness Snapshot

£950

+ VAT · one-off · paid online

Delivered within 5 working days

No code access, no NDA, no scoping call. I test whether you could detect, triage and report an actively exploited vulnerability inside Article 14’s 24 hours — from public information plus whatever artefacts you care to send. Bought online, delivered within five working days.

  • A verdict on the 24-hour clock: detect, triage, report — or not
  • Named gaps in detection, triage and escalation
  • A one-page who-does-what-when-a-report-lands
  • Known-CVE exposure across your public stack
  • Gaps ranked, with a 30-minute readout
  • Fee credited toward a Readiness Review

Readiness Review

£9,500

+ VAT · fixed scope

10 working days

Ten working days inside your firmware, build system and update path. Out the other side: a 13–16 page report that names the risks, assigns the owners, and orders the fixes.

  • 13–16 page technical report
  • Gap analysis against CRA, PSTI and RED EN 18031
  • Prioritised remediation plan with owners
  • 60-minute exec readout

Where it leads

When the evidence has to stay true

A review finds the gaps once. Article 14 then asks a harder question — who is watching on the day something lands — and that is ongoing work, not a document. Deeper project engagements sit behind this too: collecting the evidence your claims rest on, and assembling the technical file itself. Both follow a review, are scoped to your product, and are quoted in writing. Ask, and I will walk you through them.

Evidence Retainer

From £3,200

+ VAT · per month · 6-month minimum

Ongoing · 6-month minimum

Article 14 gives you 24 hours to report, and you cannot report what you cannot detect. The Retainer is continuous cover: a named engineer who already knows your product, monitoring the components you ship, triaging what lands, and keeping the evidence current as firmware moves.

  • Component monitoring against advisories, so a report is detectable
  • Vulnerability triage and the Article 14 24/72/14-day reporting path
  • Release-tied technical-file updates
  • Quarterly review with a written readout
  • Customer security-questionnaire support

11 September won’t move. Your evidence can.

Twenty minutes tells you exactly where you stand — no preparation, no pitch. Or read the sample report first and judge the work before you speak to anyone.