Services
Four practice areas
Judicial forensics, AI auditing, pentest and post-quantum. Each with its own methodology, documented and verifiable.
Judicial Digital Forensics
We produce digital forensic expert reports with full procedural validity, following recognized chain-of-custody protocols (ISO/IEC 27037, 27042) so digital evidence holds up under cross-examination.
We cover forensic extraction from phones and computers, deleted data recovery, metadata and log analysis, communication authenticity verification (WhatsApp, email), and incident timeline reconstruction.
We act as court-appointed or party expert witnesses, appearing in court when the proceeding requires it. Reports are written to be understood by a court, not only by a technician.
AI Audit
We audit AI systems in production — not the model in the abstract, but the real infrastructure around it: how API calls are authenticated, what data the model might leak in its responses, and what controls exist against prompt injection.
We evaluate exposure under the EU AI Act (Regulation (EU) 2024/1689) for high-risk systems, required technical documentation, and traceability of automated decisions.
We deliver a report with findings prioritized by real severity (not generic scoring) and a technical remediation plan — not just an abstract checklist.
Pentest
We perform real penetration testing: controlled exploitation of real vulnerabilities, not an automated scan with a generic template. Every finding comes with a reproducible proof of concept.
We cover web applications, APIs, internal networks, containerized infrastructure and external exposure surfaces. We always work under explicit written authorization and defined scope.
The report clearly separates critical from cosmetic, prioritized by real business impact — not by a tool's automated score.
Post-Quantum
We assess your real exposure to 'harvest now, decrypt later' risk: data encrypted today with classical algorithms (RSA, ECC) that an adversary may already be storing, waiting for quantum computing to break it.
We design and implement migration paths to post-quantum cryptography (Kyber for key exchange, Dilithium for signatures), following NIST FIPS 203/204/205 standards.
This isn't about replacing everything at once: we prioritize which data needs long-term protection and which systems are feasible to migrate first without breaking compatibility.