Scope and ship
We agree the models, firmware versions and radio protocols in scope, and you send us units we may dismantle.
A test of the device itself and everything around it — firmware, debug interfaces, radio, the cloud it calls home and the app that controls it — carried out on physical units in our lab.
A connected device is shipped into an environment you do not control, and anyone who buys one can take it apart. If secrets live in firmware, or an update can be replaced, one device becomes every device.
We test physical units end to end: what the board exposes, what the firmware holds, what the radio says and whether the cloud trusts the device more than it should.
Typically two to four weeks, depending on the device and protocols involved.
We agree the models, firmware versions and radio protocols in scope, and you send us units we may dismantle.
We identify components, find debug interfaces and recover firmware from the board where possible.
We unpack and review the firmware for secrets, weak cryptography, exposed services and update handling.
We watch and manipulate what the device says to the cloud, to its app and over the air.
Findings come with photographs, captures and reproduction steps, followed by a readout and a retest.
Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.
A live debug interface with an unauthenticated root shell
One signing or API key shared across an entire product line
Firmware updates accepted without verified signatures
Cloud APIs that trust a device identifier the device itself supplies
Pairing and provisioning flows that a nearby attacker can take over
Missing something on this list? Bring it to the call — we scope around what you have.
Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.