FOUNDER / TECHNICAL DIRECTION

Dr. Ewan Fleischmann

Founder · Product Security & Cryptography

Dr. Ewan Fleischmann leads the technical direction of Redlings, combining a background in cryptography, offensive security and security research with product-security work across embedded systems, software, protocols and backend components.

22+ years IT security PhD cryptography 25+ scientific publications OSCP · OSCE · CISSP
Dr. Ewan Fleischmann
BACKGROUND

Cryptography, offensive security and product systems.

Cryptography

An academic background and its relevance to product trust: signing, identity, key handling and protocols, from architecture down to implementation.

Offensive security

Penetration testing, exploitability and attacker-path reasoning, the question is always what an attacker gains in the concrete product.

Product security

Where both disciplines meet: devices, firmware, protocols, applications and cloud/backend trust.

OFFENSIVE SECURITY EMBEDDED / REVERSE ENGINEERING CRYPTOGRAPHY
The overlap is not declared a USP, the factual combination speaks for itself.
TECHNICAL FOCUS

Current technical focus

  • Embedded and connected product security
  • Firmware, boot and update trust
  • Device identity and key lifecycle
  • Protocol and wireless security
  • Product penetration testing
  • Cryptographic architecture and implementation
  • Vulnerability reproduction and exploitability
  • Cross-layer attack paths
RESEARCH & PUBLICATIONS

Original technical work.

25+ scientific publications from cryptographic research; current technical work is published as Redlings research, teardowns, vulnerability research, reverse engineering, tooling.

View research →   Security Notes →

AT REDLINGS

Technical direction stays close to the work.

Redlings is intentionally built around senior technical work rather than a high-volume delivery model. Ewan is responsible for the company’s technical direction and remains close to assessment design, difficult technical questions and review.

Engagements are scoped around the product and the specialist work required, while technical direction and review remain close to the project.

PRINCIPLE

No pyramid delivery. Whoever talks to you runs the tests. Whoever runs the tests writes the report.

ACROSS DISCIPLINES

Product security rarely stays inside one discipline.

DEVICE FIRMWARE PROTOCOL IDENTITY / CRYPTO APPLICATION / API BACKEND

A weakness in one layer often becomes important because of what the next layer trusts. The work therefore moves between implementation details and the larger product trust model.

Working on a technically difficult product-security problem?

Tell us what the product is, where you are in the development lifecycle and what you need to understand or verify.

NDA first if required.