Industrial Product Security.
Redlings performs security testing and technical review for security-critical B2B products and platforms, across hardware, firmware, software, protocols, cloud backends and cryptography.
The work starts from the product architecture and follows the attack paths that matter, rather than treating each component as an isolated test target.
Products are systems, not single interfaces.
The scope of an assessment follows the product architecture, not a service catalog. Pure software and cloud work belongs where it is part of a product or platform; generic corporate IT is not what we do.
- Industrial & automation products
- Network & security products
- Embedded platforms and modules
- Connected infrastructure
- Cloud-managed products
- Security-critical B2B software platforms
Follow the attack path across the product.
The exact scope follows architecture and threat model, the six services are building blocks, not compartments:
- 01Industrial Device & Firmware Security Assessment
- 02Product Penetration Testing
- 03Cryptography Review
- 04Wireless & Protocol Security
- 05Firmware & Source Code Review
- 06Vulnerability Response
Some engagements stay inside one layer. Others need to follow an attack path from physical access or firmware through protocols, applications and backend services.
Hardware & Debug
Physical interfaces, debug authentication, flash protection, lifecycle configuration.
Firmware & Boot
Extraction, boot chain, secure boot, recovery paths, rollback protection, update mechanisms.
Protocols & Wireless
Proprietary protocols, RF, pairing, authentication, protocol reverse engineering.
Software & Cloud
Applications, APIs, cloud backends, Kubernetes, management interfaces, network services.
Identity & Secrets
Device identity, key management, provisioning, rotation, revocation.
Cryptography
Crypto architecture, PKI, signing, secure boot trust, protocol cryptography.
The important security properties sit at trust boundaries.
A device may verify signed firmware correctly but still allow rollback through recovery. A backend may authenticate a device correctly but trust a credential that can be cloned. A wireless protocol may encrypt traffic while pairing the wrong peer. These failures appear when a mechanism is tested in the context of the product around it.
Dr. Ewan Fleischmann
Founder · Product Security & Cryptography
Redlings is technically led by Dr. Ewan Fleischmann, with a background spanning offensive security, cryptography, security research and technically demanding product assessments.
You work with the person whose name is on the report.
Redlings is a senior-led boutique, founded and led by Dr. Ewan Fleischmann. Every assessment is led by an experienced senior consultant, from the first scoping call to the final review. Whoever you talk to also tests: no intermediate layer, no junior staffing, no pyramid delivery.
For specific domains we bring in vetted specialists, protocol reverse engineering, side-channel analysis, compliance mapping. Specialist involvement is defined in the scope and coordinated with you.
We are growing. View open positions →
A lab of our own.
Product security happens at the device, not on the datasheet. Our lab combines firmware and hardware analysis tooling with wireless protocol capture and side-channel equipment. The same testing grid we apply to client devices drives our research into product trust chains.
Technical work should be visible in the work itself.
Research contains original technical analysis, vulnerability research, reverse engineering, product teardowns and tooling published by Redlings. Security Notes explain and comment, research provides the original proof.
Start with the product and the question.
Tell us what you are building, the current stage, the product architecture and what you want to understand or verify. We define the technical scope with your engineering team.