Tainan · Remote-first engineering

Built to ship. Built to hold.

We build software and we break it. The same team that integrates your systems also runs the penetration test — so whatever we hand over has already survived us.

Founded in Tainan
2022
Two complementary crafts
Build × Break
Working anywhere in Taiwan
Remote-first

We do two things

Build the system, then prove it holds. We do both in-house.

Software engineering & integration

From a company site to cross-system integration, we break the work into milestones you can actually sign off on.

  • Websites and web applications
  • API design and systems integration
  • Cloud deployment and automation
  • Maintenance and refactoring of existing systems
Software services

Security testing & penetration testing

We look at your system the way an attacker would, find what is genuinely exploitable, and write the fix in language your engineers can act on.

  • Web and API penetration testing
  • Vulnerability assessment and asset discovery
  • Secure source code review
  • Security consulting and training
Security services

Why hire a team that does both?

Most projects split building and securing between two vendors. The report comes back, the dev team cannot read it, and none of it fits the schedule. We put both on the same table.

Problems stopped before they are written

When the people writing the code have run penetration tests, access control, input validation and secret handling are not patched in the week before launch.

Reports written for engineers

Every finding ships with reproduction steps and a concrete fix — not a PDF of severity labels nobody knows how to act on.

One point of contact

Discovery, build, testing and retest all sit with the same team. Nothing gets lost being relayed between vendors.

How we work

Four stages, each with a defined output and a checkpoint that is yours to approve.

  1. Discovery

    We work out the problem you actually need solved, rather than taking a feature list at face value.

  2. Proposal

    Scope, schedule and price in writing, with deliverables spelled out. Work starts once both sides agree.

  3. Build & test

    Staged delivery. You see something working at the end of every stage, not only at the end of the project.

  4. Handover & support

    Source code, deployment docs and a walkthrough, plus defect fixes and retesting through the warranty period.

Frequently asked questions

How large a project do you take on?

Anything from a single-page company site to cross-system integration. Small projects usually run two to four weeks, mid-sized ones one to three months. If we are not the right fit, we will say so and point you somewhere better.

What do I need to prepare for a penetration test?

A URL for the test environment, test accounts, and written authorisation. We hold a scoping call first to agree on the boundaries, the testing window and any prohibited actions, so your operations are not disrupted.

Could the test break my system?

Testing is non-destructive by default. Anything higher risk needs written consent in advance and runs off-peak, and we confirm your backups are restorable before touching production.

What does the report contain?

An executive summary for decision-makers, reproduction steps and request evidence for every finding, CVSS 3.1 scoring, and concrete remediation guidance — plus one free retest.

Can I hire you for only development, or only security?

Yes. Both service lines stand on their own. They are simply stronger together.

You are in Tainan — can we work together from elsewhere?

Yes. We are a remote-first team; video calls and version control are how we work day to day. On-site meetings can be arranged when they are genuinely needed.

Got an idea? Start with a conversation

A free fifteen-minute call to check the direction is right, before we talk scope or price.