We test the product. Not just the perimeter.
Deep security testing across hardware, firmware, software, protocols, cloud backends and cryptography. For teams building security-critical B2B products and platforms.
Industrial products are systems, not single interfaces.
Industrial and security-critical B2B products rarely stop at one technical boundary. A device may extend into applications and cloud services; a digital product may depend on APIs, Kubernetes, identity and secrets. We test the layers that define the real attack surface.
A security defect can scale with the product.
Once deployed, a shared weakness can affect devices, customer environments and the infrastructure behind the product.
Follow the attack path
across product layers.
Start with the physical or embedded product itself, or with the software platform around it. We scope the test around the product architecture and the attack paths that matter.
Industrial Device & Firmware Security Assessment
For products where the device itself is part of the target. We test the system from physical interfaces, hardware security controls and boot chains through firmware, protocols, applications and backend components.
Device & Firmware Assessment →Product Penetration Testing
For products where hardware analysis is not required. We test web and mobile applications, APIs, cloud-native backends, Kubernetes, management interfaces and network services as the product attack surface.
Product Penetration Testing →Cryptography, protocols
and security-critical code.
Review scope can be limited to a specific trust model, protocol implementation or security-critical code path.
Cryptography Review
We review where trust is established, how it propagates through the product and where implementation or lifecycle decisions can break it.
Cryptography Review →Protocol & Wireless Security
Proprietary protocols, RF, pairing, authentication and protocol reverse engineering.
Firmware & Source Code Review
Embedded code, bootloaders, protocol parsers, update agents and security-critical components.
Product Vulnerability Response
Technical response for reported product vulnerabilities, reproduction, exploitability analysis, remediation support, coordinated disclosure and retesting.
Dr. Ewan Fleischmann
Redlings is technically led by Dr. Ewan Fleischmann, a PhD cryptographer with a background in offensive security, security research and complex product-security assessments.
We investigate products
to understand how they fail.
Original technical work across devices, firmware, protocols and cryptography.
Reverse engineering, analysis and tooling.
Original technical work across devices, firmware, protocols, cryptography and product infrastructure.
Scope. Attack & Review. Verify.
We scope with the engineers who build the product, test the relevant attack paths, and return findings in a form they can reproduce and fix.
Scope with engineering
Map architecture, trust boundaries, attacker assumptions and the access needed for the assessment.
Attack & review
Use the methods the target requires: penetration testing, reverse engineering, protocol analysis, cryptographic review, source code review or hardware analysis.
Findings and retest
Document reproducible findings, technical impact and remediation context. Retest fixes against the original attack path.
Need the testing to support a regulatory requirement?
Where required, assessment work and findings can be mapped to relevant technical requirements from the CRA, EN 18031 and IEC 62443.
Product Security Regulation →Field notes on
product security.
Technical analysis, engineering lessons and regulatory context for teams building security-critical products.
Secure boot is not a checkbox: where trust chains fail in real products
A practical look at the gaps between “secure boot enabled” and a boot chain that actually resists an attacker.
Read note →EN 18031, CRA and IEC 62443: where technical testing fits
How regulation and standards create real technical validation needs for product teams.
Read note →Why device key management becomes painful at scale
Provisioning, storage, rotation and recovery patterns worth designing before production.
Read note →Building a product that needs serious security testing?
Tell us what you're building, the current development stage and what you want tested. We’ll define the scope with your engineering team.