We look for the weaknesses an attacker would actually use on a connected product, across its hardware, firmware, radios, and cloud APIs. You get findings you can reproduce and the exact fixes to close them.
Every engagement is scoped to your device and goals, then runs in four steps:
Testing covers the whole attack surface of a connected product, not only the parts that are easy to reach.
You finish knowing what is exploitable and how to close it.
Do you need physical access?
Usually yes for hardware testing, a unit or two to instrument. Some firmware and network testing can run remotely.
Will testing damage my device?
Invasive tests are agreed in scope first, and anything destructive runs on spare units.
How long does it take?
Most engagements run two to four weeks, depending on scope.
Do you sign NDAs?
Yes. Send yours, or use ours before we get into specifics.