CarbonylR&D

Platform · Security assurance

Security assurance platform

Continuous assessment of what an organization exposes, tested the way an adversary would test it, with every finding backed by evidence, ranked by the risk it poses to the business, and carried through to a specific fix and to the evidence that controls are working.

DisciplineSecurity engineering
IssuePublic extract
AccessBy engagement

The premise

Proof, not noise.

A scanner with a dashboard produces lists. What an organization needs is to know what is actually wrong, how much it matters to the business, and what to do about it, in that order. Every finding here carries its evidence, every fix is specific, and every compliance check points to the control it supports.

Tested as it would be attacked

The attack surface is discovered and tested with the same kinds of techniques a capable adversary would use, within an agreed scope, so the results describe real exposure rather than theoretical exposure.

Ranked by what matters

Two findings of the same technical severity are not equal when one sits in an experiment and the other in a system that holds customer data or moves money.

Evidence for every claim

No vague warnings. Each finding states what is wrong, where, how it was established and how to fix it.

Assessment

The surface mapped, tested and kept current.

codedependenciescontainersnetworkconfigurationsecrets one finding:evidence, place riskscore orderedremediation controlevidence verified
FIG. 1Results from every source are normalized into one structured finding with its evidence and location, scored for business risk, and carried both into an ordered remediation plan and into evidence for the controls they bear on, until a re-test verifies the fix.
A-1

A living inventory of the surface

Every known point of exposure, from access control and interfaces to secrets, supply chain, infrastructure, privacy and payment integrations, classified by risk, mapped to the checks that cover it and tracked as monitored, unmonitored, remediated or accepted. New services register their surface as they deploy, so the gaps are visible.

A-2

Established tooling, integrated properly

The analysis tools professional testers rely on, for code, dependencies, containers, networks and known weaknesses, with every result parsed into the same structured finding rather than passed through as raw output.

A-3

Checks of our own

Exposed credentials in code and its history, access control and sandbox boundaries, configuration and service exposure, dependencies checked against advisories of compromised packages, and the integrity of audit logs.

A-4

One findings record

Every finding, whatever produced it, has a severity, evidence, a location and a remediation, in one record where findings from different sources can be correlated.

Risk

Fix first what an adversary would use first.

FIG. 2Findings placed by how likely they are to be exploited (left to right) and how critical the affected system is (bottom to top), larger where reachable from the internet. The shaded region is where to start. The dashed chain shows two lesser findings that together lead to a serious one. Invented data.
R-1

Asset criticality

Where the affected component sits, from an experimental sandbox through internal tooling and revenue systems to customer-facing systems and the assets the business cannot lose.

R-2

Exposure

Whether the weakness is reachable only from inside or from the public internet.

R-3

Exploit maturity

From a theoretical weakness to a published proof of concept, a working exploit and active use in the wild, with known vulnerabilities scored by the published probability that they will be exploited soon, not only by their theoretical severity.

R-4

Business impact

Exposure of revenue and customer data, and the regulatory consequences that follow.

R-5

Cost to fix

A configuration change and an architectural change are weighed differently when deciding what comes first.

R-6

One composite score

The dimensions combine into a single ranking of what to fix first against the organization's actual threat landscape, not an alphabetical list of identifiers.

Triage

The layer between findings and fixes.

T-1

Chains no single check sees

Findings are read together, with their evidence, location and the criticality of what they affect, to find combinations of minor weaknesses that add up to a serious one.

T-2

An ordered plan

Remediation is sequenced with its dependencies in mind, so that fixing one problem does not open another, and the most consequential path is closed first.

T-3

Impact in business terms

Each priority is explained by what it puts at risk, not only by a severity number.

T-4

Guidance for the actual system

Remediation is written for the specific component and the way it is deployed, ready to act on.

Foundations

Hardening the parts everything else relies on.

F-1

One authentication library

A single source of truth for sessions, passwords and keys across every service: memory-hard password hashing, signing keys that rotate with a grace period for tokens in flight, verified keys rather than random strings, and hardware security keys for passwordless sign-in.

F-2

Code that proves it is unaltered

Source files are signed at the level of their syntax, so tampering is detected even when the change is made to look harmless.

F-3

Service to service, mutually verified

An internal certificate authority issues identities to services, which verify each other on every connection, with role-based access enforced by cryptographically verified tokens.

F-4

A guarded supply chain

Every package is checked against advisories of known-malicious releases before it is installed and verified against pinned content hashes afterwards, while the health of upstream registries is watched continuously.

Monitoring

Exact evidence of what changed, where and when.

FIG. 3Security posture over time: the score falls when a new finding appears (marked) and recovers as fixes land (ticked below). Invented data.
M-1

Sensitive files watched

Changes to configuration, credentials, security-critical code and model checkpoints are detected as they happen.

M-2

Logs that cannot be quietly edited

Audit logs are checked for truncation, deletion and tampering.

M-3

Early signs of intrusion

Changes to permissions on sensitive files and sudden rises in refused access, an early sign of credential stuffing or attempts to escalate privilege.

M-4

Re-tested on a schedule

Assessments repeat automatically, and every alert arrives in the same structured form as a finding: severity, evidence, location and remediation.

Compliance evidence

Evidence mapped to controls, not a questionnaire.

Findings are mapped to the control identifiers of the major frameworks for security and availability, for the privacy of children's data, and for payment card data. Each control is assessed against what the scans actually found. Formal attestation remains the role of an independent licensed auditor; what this produces is the evidence an auditor asks for.

C-1

Assessed, not asserted

Each control is marked as passing, failing or partial on the strength of real findings, with the evidence attached and the findings linked.

C-2

Gaps with their remedies

Every failing or partial control comes with the remediation that would close it.

C-3

Packages for the auditor

Evidence is assembled control by control into a package an auditor can review directly.

C-4

Continuous, not annual

Because the evidence comes from continuous assessment, it describes the state of the controls now, not on the day of the last review.

Services

Three ways to engage.

Testing is carried out only on systems the client owns or is authorized to test, under a written scope agreed before any work begins.

Penetration testing

An end-to-end assessment of the agreed scope, delivered as an executive summary, detailed findings with evidence, a prioritized remediation plan and a verification re-test after the fixes.

Continuous monitoring

Ongoing automated assessment with prompt alerting, a daily posture score, trend reporting and tracking of every remediation to closure.

Compliance readiness

Automated evidence collection and gap analysis against the frameworks that apply, prepared for review by the client's auditor.

Connections

The same ideas, elsewhere in our work.

X-1

Agent runtime & orchestration

The same zero-trust stance applied to software agents: nothing inherits permission, every refusal is recorded, and the record shows it if anyone tries to change it.

X-2

Trading & research platform

Systems that move money sit at the top of any ranking of what an organization cannot lose, and are assessed and watched accordingly.

X-3

Accounting & tax system

Every finding carries its evidence the way every figure in a ledger traces to its source document. A claim without its evidence is not accepted in either.

X-4

Robotics & learning lab

A learning lab used by children is held to the rules that protect children's data, and the same controls that are checked for clients are checked there.

Engage

By engagement.

Every engagement begins with a conversation and is scoped before work begins.

Assessment

A penetration test of an agreed scope, with evidence, a ranked plan and a re-test.

Subject: Audit

Monitoring

Continuous assessment, alerting and posture reporting.

Subject: Access

Partnerships

Firms and platforms that serve many organizations.

Subject: Partnership

Investment

Briefings and a demonstration, under confidentiality.

Subject: Funding
contact@carbonyl.org