ABOUT REDLINGS

Industrial Product Security.

Redlings performs security testing and technical review for security-critical B2B products and platforms, across hardware, firmware, software, protocols, cloud backends and cryptography.

The work starts from the product architecture and follows the attack paths that matter, rather than treating each component as an isolated test target.

Discuss your product →

PHYSICAL PRODUCTHARDWARE / DEBUGFIRMWARE / BOOT / UPDATEWIRELESS / PROTOCOLAPPLICATION / APIBACKEND / CLOUDIDENTITY / CRYPTOGRAPHIC TRUST
PRODUCT ENVIRONMENT

Products are systems, not single interfaces.

The scope of an assessment follows the product architecture, not a service catalog. Pure software and cloud work belongs where it is part of a product or platform; generic corporate IT is not what we do.

  • Industrial & automation products
  • Network & security products
  • Embedded platforms and modules
  • Connected infrastructure
  • Cloud-managed products
  • Security-critical B2B software platforms
DEVICE ── PROTOCOL ── API ── BACKEND      TRUST / IDENTITY ── jede Schicht
TECHNICAL SCOPE

Follow the attack path across the product.

The exact scope follows architecture and threat model, the six services are building blocks, not compartments:

Some engagements stay inside one layer. Others need to follow an attack path from physical access or firmware through protocols, applications and backend services.

Explore services →

Hardware & Debug

Physical interfaces, debug authentication, flash protection, lifecycle configuration.

Firmware & Boot

Extraction, boot chain, secure boot, recovery paths, rollback protection, update mechanisms.

Protocols & Wireless

Proprietary protocols, RF, pairing, authentication, protocol reverse engineering.

Software & Cloud

Applications, APIs, cloud backends, Kubernetes, management interfaces, network services.

Identity & Secrets

Device identity, key management, provisioning, rotation, revocation.

Cryptography

Crypto architecture, PKI, signing, secure boot trust, protocol cryptography.

HOW WE THINK

The important security properties sit at trust boundaries.

A device may verify signed firmware correctly but still allow rollback through recovery. A backend may authenticate a device correctly but trust a credential that can be cloned. A wireless protocol may encrypt traffic while pairing the wrong peer. These failures appear when a mechanism is tested in the context of the product around it.

ATTACKER COMPONENT A TRUST DECISION COMPONENT B PRIVILEGED PRODUCT BEHAVIOR
TECHNICAL DIRECTION

Dr. Ewan Fleischmann

Dr. Ewan Fleischmann

Founder · Product Security & Cryptography

Redlings is technically led by Dr. Ewan Fleischmann, with a background spanning offensive security, cryptography, security research and technically demanding product assessments.

22+ years IT security PhD cryptography 25+ publications OSCP · OSCE · CISSP
OPERATING MODEL

You work with the person whose name is on the report.

Redlings is a senior-led boutique, founded and led by Dr. Ewan Fleischmann. Every assessment is led by an experienced senior consultant, from the first scoping call to the final review. Whoever you talk to also tests: no intermediate layer, no junior staffing, no pyramid delivery.

For specific domains we bring in vetted specialists, protocol reverse engineering, side-channel analysis, compliance mapping. Specialist involvement is defined in the scope and coordinated with you.

100% of assessments are led by a senior
0 layers between you and the tester

We are growing. View open positions →

THE LAB

A lab of our own.

Product security happens at the device, not on the datasheet. Our lab combines firmware and hardware analysis tooling with wireless protocol capture and side-channel equipment. The same testing grid we apply to client devices drives our research into product trust chains.

Equipment: logic analyzer · SPI/JTAG programmers · BLE/Thread sniffers · ChipWhisperer for side-channel and glitching analysis · dedicated bench for device runs. Depending on scope, we add: EM fault injection, high-bandwidth oscilloscopy, near-field EM analysis; decapsulation and X-ray in cooperation with specialised partners.

View the research programme →

RESEARCH

Technical work should be visible in the work itself.

Research contains original technical analysis, vulnerability research, reverse engineering, product teardowns and tooling published by Redlings. Security Notes explain and comment, research provides the original proof.

View research →   Security Notes →

Start with the product and the question.

Tell us what you are building, the current stage, the product architecture and what you want to understand or verify. We define the technical scope with your engineering team.