The practice

A small team that says no a lot

Thirty-four analysts and engineers in Rennes. We work with operators whose downtime has consequences beyond a revenue chart, which is why we turn down more work than we take.

34 Analysts and engineers
2016 Practising since
340+ Engagements delivered
100% Work performed in the EU
Why the practice exists_

Most security work is sold on the promise of coverage. We think the useful question is narrower: what would actually happen if someone competent tried?

That question is harder to answer and much harder to invoice against a framework, but it is the only one that changes decisions. It is also why our reports are short, why our findings are reproducible, and why we would rather tell you three true things than forty defensible ones.

How we work

Four commitments, written into every contract

01

Findings go out the hour we confirm them

Nothing critical waits for the report. If we get domain administrator on a Tuesday afternoon, you know on Tuesday afternoon.

02

We write what we could not determine

Every report has a section on the limits of the engagement. An assessment that claims total coverage is describing a scope, not a reality.

03

The control belongs to your team

We write the evidence, your engineers own the system. A programme that collapses when the consultancy leaves was never a programme.

04

No finding is padded

A report with forty low-severity items exists to justify a fee. If we found three things that matter, the report has three things in it.

History

Ten years, one office

We have grown slowly on purpose. Every analyst who has run an engagement here was hired before we needed them.

  1. 2016

    Founded in Rennes

    Two people, one industrial client and a rented desk. The first engagement was a water utility that had never had its network mapped.

  2. 2019

    PASSI qualification

    Formal qualification for penetration testing and security audit, which opened work with public-sector operators.

  3. 2021

    The SOC goes live

    Continuous monitoring launched with four clients and a rotation of six analysts. Sovereign hosting from the first day.

  4. 2023

    CERT team formed

    A dedicated incident response cell, with a contractual thirty-minute engagement commitment for retainer clients.

  5. 2026

    Thirty-four analysts

    Still one office, still no offshore first line, still refusing engagements we do not think we are the right people for.