/ PASSI & ISO 27001 qualified
Offensive security for critical infrastructure
We map your attack surface, test it the way an adversary would, then defend it around the clock from a sovereign SOC operated in Rennes.
Incident response engaged within 30 minutes · PASSI-qualified team · Data hosted in France
Trusted with their attack surface.
Clients include Havrelis, Cindre Health, Orbanne, Valmeyre, Tessane Group, Kordyn, Aubrac Energy, Nolven.
From a code review to the endpoint on a desk, we turn every blind spot into a signal you can act on, then into defence you can measure.
/ PASSI & ISO 27001 qualified
Turning uncertainty into a posture you control
Map
We inventory exposed assets, third-party dependencies and the attack paths that are genuinely walkable. Not a theoretical CVE list.
Break
Red team, application testing and configuration review. We break what needs breaking, before an adversary does it without warning.
Defend
Continuous detection, response playbooks and hardening run from the SOC, with metrics your board can actually read.
Defences cut to your exposure
No two estates look alike. Each engagement is scoped against your business criticality, your technical debt and the regulations that bind you.
Penetration testing & red team
Full adversary simulations across external, internal, application, physical and social vectors, delivered with a remediation plan ranked by effort and impact.
Managed SOC, 24/7
Continuous monitoring, multi-source correlation and triage by human analysts. Nothing is subcontracted outside the European Union.
Incident response & forensics
Permanent on-call, containment, eradication and a post-mortem that stands up in front of an insurer and a regulator alike.
NIS2 & ISO 27001 readiness
Gap analysis, a dated compliance path and support through certification audit. Evidence over paperwork.
Cloud security & Zero Trust
Hardening across AWS, Azure and GCP, identity segmentation and conditional access rolled out without breaking production.
Awareness & phishing drills
Realistic campaigns, reporting-rate measurement and short modules. We train your people rather than blame them.
Short mandates, results you can measure
A selection of work delivered between 2024 and 2026. Names are anonymised where the client asked us to.
( 2024–26 )
( Managed SOC )
( 2026 )
Plans you can read, with no trapdoor
Watch
Exposure monitoring and qualified alerting for organisations starting a security programme.
- Monthly attack-surface mapping
- Vulnerability and dark-web exposure watch
- Qualified alerting in business hours
- Quarterly posture report
Defend
The full posture: continuous detection, contractual incident response and regular offensive campaigns.
- Everything in Watch
- Managed SOC, 24 hours a day
- Incident response engaged within 30 minutes
- Two penetration testing campaigns a year
- A named lead analyst
Sovereign
For operators of vital importance and environments under strict sovereignty requirements.
- Everything in Defend
- A dedicated, compartmented team
- SecNumCloud-qualified sovereign hosting
- Annual crisis exercises with the board
- Continuous regulatory support
What the CISOs say
They found a path in eleven days that three consecutive audits had walked straight past.
The SOC woke us at three in the morning for a real incident. That is exactly what we pay them for.
A report our board read to the last page. In twelve years I had not seen that once.
Threat intel & trends
Questions? We have answers
Clients on Defend or Sovereign have a contractual 30-minute engagement commitment, around the clock. A crisis cell opens within the hour when triage warrants it.
Every engagement opens with a rules-of-engagement document setting scope, testing windows and stop conditions. On industrial networks we work passively by default, then against an isolated replica.
In France only, on SecNumCloud-qualified infrastructure. No data leaves the European Union, including for correlation and enrichment processing.
Yes. Watch exists for exactly that: visibility and qualified alerting without requiring an in-house security team. Most clients start there and move to Defend within twelve to eighteen months.
A three-page summary a chief executive can read, reproducible technical detail for every finding, a remediation plan ranked by effort and impact, and a re-test at ninety days included.
Ready to shrink your attack surface?
Let us find the three blind spots most worth an attacker's time, then build the defence that fits your budget and your calendar.