Cybersecurity services · secure engineering · incident response
Security work you can verify.
Testing, engineering and response — scoped under signed authorization, delivered with findings a specialist proved by hand, and reports anyone can check against a public signature.
What Solvex does
Eleven practice areas, one standard.
Every area below is a real section of the catalogue with a counted number of services behind it. The standard is the same in each: scoped, authorized, delivered with evidence.
Security
- Offensive / TestingFind the weaknesses before an attacker does.16
- Defense & MDRAround-the-clock detection and response.11
- SOC / DetectionThe operating model behind detection: SOC architecture, telemetry planning, detection-as-code, alert quality and the coverage assessment that tells you honestly what your monitoring can and cannot see..3
- DFIR & ForensicsUnder attack or already breached? 24/7 incident response, digital forensics, malware analysis, ransomware recovery and the readiness work that makes the next incident smaller..9
- Governance / ComplianceProve your security to auditors, customers and regulators.14
Engineering
- EngineeringSoftware built secure rather than tested afterwards.4
- Algorithmic SystemsTrading and quantitative infrastructure built like safety-critical software: execution engines, order state machines, risk gates and kill switches, with honest validation of what a strategy does and does not demonstrate..4
- Reverse EngineeringAuthorized analysis of software you own or are permitted to examine: binaries, firmware, mobile applications and malware.4
- Data RecoveryGetting data back, and proving you could.3
How an engagement runs
Six steps. Each one leaves something you can check.
The same model for every authorized engagement, from a first assessment to incident response.
- 01
Intake
Tell us the system, the goal and the constraints. If the work is not a good fit, we say so before anyone is invoiced.
Start a conversation - 02
Scope and authorization
Written scope and signed authorization before anything is touched. Security testing runs only against systems you own or are contractually entitled to have tested.
Responsible testing policy - 03
Investigation or build
Specialists matched to the work. Findings are proven by hand — scanner output is a lead, never a finding.
- 04
Evidence
Every finding ties to something observed. When a report is issued, its evidence is frozen in the same transaction, so what backed the report cannot change afterwards.
How evidence is handled - 05
Delivery
A signed report: an Ed25519 signature over both the content and the file, with a short verification reference you can read down a phone.
How signing works - 06
Verification and retest
Anyone holding the report can verify it publicly without seeing its contents. Fixes are retested as part of the engagement — “fixed” means we confirmed it.
Verify a report
Check where you stand first
39 free tools, no signup wall.
They run on assets you own or on public data, and every result says what it could not see. We would rather prove competence in your browser than claim it in a brochure.
Authorized, defensive use only: check assets you own or lawfully public data. Never another party's systems.
Why trust it
Specifics you can check, not adjectives.
Security is a trust purchase. Each of these is a property of the platform, not a claim about it.
Every finding manually verified
Scanner output is never forwarded as a finding. If it is in your report, a specialist proved it is real and exploitable — which is why the reports are short and every line matters.
Starting prices, published
Every service carries a visible starting point, so you can budget before you talk to anyone.
See itRetesting included, not upsold
A test that ends at the report leaves you unverified. Fixing and retesting is part of the engagement.
Our boundaries, in writing
Every service page publishes what we will not do — the exclusions, not just the pitch.
Reports you can verify
Each report is signed, and anyone holding it can check the signature publicly without seeing its contents.
See it
Representative engagements
The risk a team faced, what was done, and the result. Clients are confidential; the figures and quoted comments illustrate typical outcomes for the work described, and every engagement links to the real services behind it.
Trust, in writing
How the work is kept honest.
Methodology, authorization, evidence handling and the platform's own security posture — written down, and checkable.
What next
Start with the right conversation.
Scope an engagement
Describe the system and the goal. You get a written scope and a fixed quote, and a plain answer if the work is not a fit. Replies within one business day.
Talk to usUnder attack right now
A responder assesses severity and gives containment direction on a free triage call, before any commercial discussion.
Emergency responseBuilding a startup
Three stage-matched bundles composed from real services, with the starting price summed from the catalogue.
See the bundles