Cryptography

Cryptography engineered correctly, not just switched on

Design, review and implement cryptographic systems — key management, protocols, signing and secure storage.

The problem

Why this matters

Cryptographic failures rarely come from broken algorithms. They come from implementation details: hard-coded keys, nonce reuse, weak randomness, unauthenticated encryption, poor key rotation and certificates nobody tracks.

Common challenges

  • Keys embedded in source code, configuration or container images
  • Inconsistent algorithm and library choices across teams
  • No complete inventory of certificates, keys and their owners
  • Custom cryptographic code without expert review

Our approach

How we work

  1. Inventory

    Build a cryptographic bill of materials: algorithms, keys, certificates and libraries.

  2. Review

    Assess designs and implementations against current standards and known pitfalls.

  3. Remediate

    Replace weak primitives and centralise key management behind well-tested libraries.

  4. Prepare for change

    Build crypto-agility so algorithms can be replaced without application rewrites.

Capabilities

What our cryptography work covers

  • 01

    Cryptographic design review

    Protocol and scheme review for confidentiality, integrity and authenticity guarantees.

  • 02

    Key management architecture

    HSM and KMS design, key hierarchies, rotation and access policy.

  • 03

    PKI & certificate lifecycle

    Certificate inventory, automation and private CA design.

  • 04

    Code signing & integrity

    Signing pipelines for software artefacts, documents and models.

  • 05

    Cryptographic implementation review

    Source-level review of cryptographic code and library usage.

  • 06

    Cryptographic inventory (CBOM)

    Automated discovery of cryptographic assets across code and infrastructure.

Engagement

Deliverables and benefits

What you receive

  • Cryptographic inventory and risk assessment
  • Key management architecture
  • Approved algorithm and library standards
  • Implementation review report

What it changes

  • Confidence that encryption actually protects what it claims to
  • Centralised, auditable key management
  • A foundation for post-quantum migration

Standards & technology

  • AES-GCM
  • TLS 1.3
  • PKCS#11
  • X.509
  • Sigstore
  • NIST FIPS 140-3

FAQ

Frequently asked questions

Should we write our own cryptographic code?

Almost never. We recommend well-reviewed libraries and focus custom work on correct composition, key management and protocol design.

Discuss your cryptography requirements

Let’s discuss it. Tell us what you are working on and an engineer — not a sales script — will respond.