Security engineering & assurance
We test, audit and defend financial infrastructure — exchanges, trading platforms, custody flows, smart contracts and the cloud they run on.
Offensive testing, on-chain and custody review, incident response and audit readiness, delivered by engineers who have built the systems being assessed.
Four practices. Engagements are usually drawn from more than one — a contract review that reaches into custody, or a penetration test that ends in audit evidence.
Grey- and black-box assessment of web applications, APIs, internal networks and trading interfaces. Business-logic led, not scanner output.
Objective-based, assumed-breach exercises against your real detection and response. Scoped to an outcome — reach the signing infrastructure, move funds, exfiltrate the customer table — rather than a vulnerability list.
Manual source review of backend services and trading logic in .NET, Node, Java, Rust and Python — concurrency, state machines, money handling and trust boundaries.
Solidity and EVM review with executable invariants. Every finding ships with a proof of concept that fails before the fix and passes after it.
Assessment of key management and signing paths end to end — HSM and MPC configuration, quorum and policy design, key ceremony procedure, withdrawal approval flows, and the integration code around third-party custodians.
AWS and GCP configuration review — IAM and privilege-escalation paths, network exposure, secrets handling, logging coverage, container and workload posture.
Pipeline and dependency risk: CI/CD privilege and artefact integrity, secrets in build systems, infrastructure-as-code review, base image and dependency exposure, SBOM and signing.
Design-stage review before code exists — trust boundaries, failure modes and the invariants the system must hold. The cheapest point at which to fix an architecture.
Honeypots, canary tokens and tripwires placed where a real intruder would step, wired into alerting you actually read. High-signal detection without another dashboard.
Response and forensics when something has already happened. Timeline reconstruction from logs and on-chain data, scope of compromise, containment, and a root-cause write-up that survives scrutiny.
Runbooks, escalation paths and decision authority agreed before you need them, then exercised against a realistic scenario. Most incidents go badly because nobody knew who could halt withdrawals.
ITGC review across access management, change control, segregation of duties and operational monitoring — with the evidence an auditor will actually accept.
Control design, gap analysis and evidence preparation. We prepare you for the audit and sit with you through it. Certification and attestation are issued by accredited bodies — not by us.
Fractional security leadership on retainer: roadmap, risk register, vendor and third-party review, board reporting, and ownership of the programme between audits.
We stand up your programme and run the inbound: scope and policy drafting, safe-harbour terms, severity and reward tables, then day-to-day triage — reproducing submissions, de-duplicating, rejecting noise, and handing your engineers only what is real, with a proof of concept attached.
The highest-severity defects in trading and financial systems are rarely injection or memory safety. They are broken invariants in code that reviews cleanly: a cancel path that refunds the original locked amount instead of the remaining one, a balance check that two concurrent orders both pass, a maker rebate that exceeds the taker fee, a cliff boundary off by one second.
Finding those requires knowing how matching engines, order lifecycles, settlement and custody are actually implemented — not a checklist.
Sector experience: centralised and decentralised exchanges, brokerage and copy-trading platforms, high-frequency trading infrastructure, token sales and tokenisation, payments and ERP.
Prasanta Sahoo
Principal
Builds and operates the systems this practice assesses. Work spans exchange and trading infrastructure — matching engines, order management, ledger and settlement — and the security and compliance programmes around them.
Engineering work spans centralised exchange infrastructure — matching engine, order management, ledger and settlement — across a large microservice estate; institutional FX market-making systems in Rust, including FIX and ITCH protocol handling and colocated execution; custody integration over MPC and HSM-backed signing with major third-party providers; token issuance and vesting contracts; brokerage and copy-trading platforms; and an ISO 27001 programme across a multi-service production estate.
Client names are withheld. References can be provided under NDA for qualified engagements.
Assessments map to recognised methodology, so findings are defensible to your auditors, your board and your customers.
OWASP ASVSOWASP WSTG OWASP API Top 10PTES NIST CSFNIST SP 800-115 ISO/IEC 27001SOC 2 CIS BenchmarksMITRE ATT&CK CCSSSCSVS
We deliver readiness, control design and evidence for ISO 27001 and SOC 2. Certification and attestation are issued by accredited bodies and auditors, not by us.
Testing is carried out only under written authorisation, within agreed scope. We do not accept work against systems a client does not own or control.