TechEntangleGet in touch

Security and resilience products for regulated institutions

Proof, not posture.

Four products that turn what an institution currently asserts into something it can hand to a board, an auditor, or a regulator who wants evidence rather than assurance.

0dq

2m 33s

to inventory the cryptography in 5,255 source files

Our own timed scan of hashicorp/vault, 5,255 source filesMeasured by us

Aegix

100%

completion at 50 concurrent participants, against production

Our own load testing, 16 November 2025Measured by us

RX9

8×

the recovery bill when the backups went down with everything else — $3m against $375,000

Sophos, State of Ransomware 2025Third-party, published

CipherScan

85–98

where every established asset scores, so a single threshold flags all of them or none

CipherScan scoring across six categories, sourced from CertiKMeasured by us

The portfolio

Four products, one job.

0dq

Post-quantum readiness

You cannot migrate cryptography you cannot see.

Every institution knows it will have to move to post-quantum cryptography. Almost none can answer the first question a regulator will ask. That inventory does not exist, because no scanner has ever produced it — they look for vulnerabilities, not for cryptography.

0dq scores six pillars as one number with the arithmetic shown: quantum readiness at 30%, then code, dependencies, secrets, infrastructure and licences. Five of those you already have from other tools. The first one you do not, and it is the one a post-quantum programme starts with.

Findings carry a reachability verdict — called, not called, dead code, dev only — so the list is ordered by what can actually run rather than by severity alone. Where a fix is mechanical, it opens the pull request. Point it at a repository and it answers in minutes: no agent, no integration project.

  • NIST published ML-KEM, ML-DSA and SLH-DSA in August 2024. What to migrate to is no longer an open question — only what to migrate, and in what order.

    NISTThird-party, published
  • Cryptography and key management are already named control domains under the CBUAE Information Security Regulation and Operational Risk Standard.

    CBUAEThird-party, published
  • Six pillars, weighted into one score: quantum readiness 30%, code 18%, dependencies 17%, secrets 13%, infrastructure 12%, licences 10%.

    0dq scoring modelProduct behaviour
  • Static analysis runs 2,452 rules across OWASP Top Ten and CWE Top 25. Secrets are found in commit history, not only the working tree.

    0dq scannerProduct behaviour
  • Every finding carries a reachability verdict — called, not called, dead code, dev only — so the queue is ordered by what can run, not by severity alone.

    0dq findings viewProduct behaviour
  • Runs in the browser, on the command line, as a pipeline gate, and as a pre-commit hook that stops a credential locally in under a second.

    0dq surfacesProduct behaviour
More on 0dq

Aegix

Resilience assurance

The board will ask if your team is crisis-ready. Will you have proof?

Traditional tabletop exercises leave nothing measurable behind. A facilitated discussion around a conference table produces no timestamped decisions, no response quality data, and nothing an auditor can reference.

Aegix replaces it with a live, AI-generated simulation where participants face timed, role-based decisions under pressure. Every choice is captured, every response graded, and every outcome mapped to the frameworks that ask for evidence of operational resilience testing.

What comes out is not a lessons-learned note. It is a readiness grade, a timestamped decision log, and an incident response playbook with role assignments, escalation paths and communication templates — internal, external and regulatory — generated from what your team actually did, and mapped to NIST SP 800-61, ISO 27035 and SANS.

  • Designed for 100–150 participants. An extrapolation from the 50-participant run, not a measured figure.

    Our own load testing notes, extrapolated from the 16 November 2025 runProjected, not measured
  • A full scenario is generated in usually two to five minutes.

    Stated on the Aegix generation screenProduct behaviour
  • Participants join by QR code. No app, no login.

    The Aegix participant join flowProduct behaviour
  • Each session generates an incident response playbook: role assignments, escalation paths, timelines, and communication templates for internal, external and regulatory audiences.

    Aegix playbook generatorProduct behaviour
  • Findings are mapped to NIST SP 800-61, ISO 27035 and SANS for the response plan, and to NIST CSF, DORA, ISO 22301 and CBUAE for the compliance record.

    Aegix framework mappingProduct behaviour
More on Aegix

RX9

Pre-releaseRansomware defence

Assume the ransomware gets administrator.

Attackers take administrator before they encrypt anything, because at that level most security tools can be switched off and most copies can be deleted. Backups are hunted first, for the same reason: a customer who can restore does not pay.

RX9 is built for that move specifically. Files are preserved before they are damaged, and releasing them takes an approval from your console — which nobody sitting at the compromised machine can grant, and nothing running on it can either, including whatever the attacker brought with them.

  • Attackers went after the backups of 94% of ransomware victims, and succeeded against more than half.

    Sophos, State of Ransomware 2025Third-party, published
  • Median time from initial access to the domain controller: 3.4 hours.

    Sophos, Active Adversary Report 2026Third-party, published
More on RX9

CipherScan

Portfolio surveillance

A security score tells you where an asset stands. Not that it just moved.

Security assessments for digital assets exist, and they are good. But they are a snapshot you go and look up, one asset at a time, when somebody remembers to check. Posture decays quietly — development stalls, governance concentrates, liquidity thins, an audit goes stale — and by the time it shows in the price it is late.

CipherScan scores every listed asset hourly across six categories, evaluates it against thresholds you set, and raises one alert per condition, held open while it persists. No custody, no wallet connection, no keys. Analysis only.

It also answers the question that arrives months later: why was this asset listed, and on what basis. A decision record reconstructs the evidence as it stood on the listing date — and says plainly whether that is a snapshot taken at the time, a reconstruction from surviving data, or not establishable at all. Anyone listing assets has to answer that eventually; most cannot.

  • No custody, no wallet connection, no keys, no signatures, and no holdings recorded. Analysis only.

    CipherScan product behaviourProduct behaviour
  • One alert per condition, held open while it persists — rather than one per evaluation. An inbox you still read in month six.

    CipherScan alerting behaviourProduct behaviour
  • A listing decision record states the evidence as at the listing date, and labels its own basis: a snapshot recorded at the time, a reconstruction from surviving data, or unavailable. The three are never presented as one.

    CipherScan listing decisionsProduct behaviour
More on CipherScan

What connects them

One spine.

Four products for four buyers, doing one thing in common: each turns something an institution currently asserts into something it can hand over.

0dq

Your source code

A scored posture across six pillars

Aegix

A live exercise

A playbook, an audit trail and compliance evidence

RX9

Every write to disk

An approval trail

CipherScan

Every listed asset, hourly

A dated evidence record

A document somebody else has to accept.

Nothing here is a dashboard that makes you feel better.

  • NIST CSF
  • NIST SP 800-61
  • ISO 22301
  • ISO 27035
  • DORA
  • CBUAE Information Security Regulation
  • CBUAE Operational Risk Standard
  • NESA

Who we are

A product company.

Engineers who build and sell software. We do not sell our time, we have no consulting arm, and there is no services utilisation to defend when we decide what to build next.

We work from first principles because the alternative — inheriting how a category has always been done — is what produced a generation of scanners that hunt vulnerabilities and never once ask which cryptography is running, and crisis exercises that leave no record of what anybody decided.

No legacy platform to protect. No roadmap shaped by one customer we cannot afford to lose. What that buys is the willingness to build the unglamorous thing the category skipped — which is, in every case, the part the buyer actually needed.

How we write about our products

We publish the sources.

Security marketing runs on numbers nobody can check. Every figure on this site carries where it came from and what kind of claim it is.

Third-party, published

Somebody else’s research, named where it appears, with the year. Sophos, CrowdStrike, NIST, the CBUAE.

Measured by us

Our own run, with the conditions stated — how many files, how many participants, on what date.

Product behaviour

What the product does, which you can check by using it. Not a performance claim.

Where we have not measured something, we do not have a figure for it.

UAE authorities are widely expected to require a post-quantum migration roadmap. They have not yet, and our collateral does not claim they have — because a regulatory claim a compliance officer can falsify in an afternoon costs more than it wins.

All 23 claims on this site, with their sources

Contact

Start with the question you need answered.

Tell us which of the four it is and we will show you the product against your own environment — a repository, a portfolio, a scenario, a test machine.

  • Which cryptography are we running, in which systems, protecting what?
  • Is the crisis team ready — and where is the evidence?
  • When the attacker has administrator, do the files come back?
  • When we listed this asset, what did we know — and what have we watched since?