Practical cybersecurity engineering.
Threat modelling, secure system design, penetration testing and security training, drawing on advisors with two decades of academic and applied research. We take on work where the result is working code or a hardened system.
Get in touchSimulated scan output — the kind of findings we surface and remediate
Security is part of how we build AI systems, not a separate service added afterwards. Threat modelling, secrets management, audit logging and access control go in with the first commit. D-PLUS, which begins in October 2026, is a cybersecurity training platform built on this approach.
For standalone security work, we agree the scope first: web applications, APIs, cloud configuration, internal networks or AI systems. We also agree what a successful result looks like before we start. You receive a remediation guide with findings ranked by how easily they can be exploited and what they mean for your business, not just a list of CVEs.
We have a particular interest in threats to AI systems: prompt injection, training data extraction, model inversion and adversarial inputs. These are practical engineering problems, and they are becoming part of most serious security assessments.
Frequently asked questions
What does a penetration test with Smartifier include?
A scoped engagement covering the attack surface we agree with you: web applications, APIs, cloud configuration or an internal network. You receive a report of findings ranked by how easily they can be exploited and what they mean for your business, a remediation guide, and a retest of critical issues once they are fixed.
Do you work with AI-adjacent security threats?
Yes. Prompt injection, training data extraction, model inversion and adversarial inputs are practical engineering problems, and we assess AI systems against them as part of standard engagements.
What sectors do you work in?
We take work in healthcare, education, financial services and the public sector, where our funded research has operated. We prefer engagements where the security posture can genuinely be improved, rather than box-ticking compliance.
How is threat modelling integrated into a build project?
When a client commissions AI or automation work alongside security, we model threats at the start of the project. Secrets management, audit logging and access control are specified before any production code is written.