
Evaluating software architectures against security risks and creating mitigation advice in an agile and interactive fashion.

Get an initial attack tree with security controls for your product or architecture — fast, async, and coaching-style.

Threat modeling for agentic AI systems — tracing attack paths across input surfaces, reasoning, tools, memory, inter-agent communication, and the agent supply chain.

Ongoing security advisory retainer — regular check-ins, architecture reviews, ad-hoc questions, and priority booking for better security decisions.

Security review of software architectures and system designs, including zero trust architecture assessments — defining a roadmap for improvement and hardening.

DevSecOps coaching for AppSec build pipelines — security scan automation, AI-based code review, and false positive handling.

Expert assessment and evaluation of security findings from SAST, DAST, dependency scans, pentests, and threat modeling. Contextual analysis, realistic prioritization, and actionable remediation recommendations.
Low-volume newsletter to announce new trainings, services, and conference talks (about four mails per year)