Defence & Aerospace

Verify what your suppliers shipped. Before it lands in a deployable system.

Defence prime contractors and research labs receive crypto-bearing code from many suppliers. Some is in-house, some is contractor-built, some is open-source-derived. The procurement chain assumes the labelling is accurate. Often, nobody verifies that "AES" really is AES, or that the constant-time variant the spec called for is actually constant-time-structured in the delivered code.

Event Horizon gives a defence engineering team a fast structural conformance check (seconds to minutes) on every C/C++ file in a delivered codebase. It tells you what's crypto, what family it fingerprints as, and which files diverge from documented references — before the code goes into a system that's expensive to recall.

"If you can't see the structural geography of the crypto in your codebase, you can't tell whether what the supplier delivered matches what the spec required. AI-driven adversary tooling makes that visibility non-optional." — positioning anchor for defence-research conversations

Defence use cases

  • Supplier-delivered code verification — does the delivered C/C++ match the algorithm family in the spec?
  • Cross-implementation consistency checks across HSM, server, mobile, embedded targets
  • Pre-deployment crypto inventory for MoD procurement packages
  • Post-acquisition technical due diligence (M&A of defence-tech companies)
  • NATO PQC migration readiness assessment
  • Independent verification for tier-2 / tier-3 contractor deliverables

UK-based; Sandhurst office is 10 minutes from Farnborough. Tier-1 prospect engagements include conversations with research-lab security teams in the Thames Valley defence corridor.

Telecom · PQC Migration

Map the crypto you have today. Before you can plan the migration.

NIST published the post-quantum standards in August 2024 (FIPS 203, 204, 205). NSA's CNSA 2.0 transition timeline targets 2030-2035 for full PQC migration across national-security systems. Network operators with millions of lines of C/C++ in their core network stack, SIM/eSIM authentication, customer security infrastructure — all face the same first step: an accurate inventory.

You can't migrate what you don't know you have. Keyword-based inventory programmes for telco-scale codebases miss forked libraries, vendor-modified middleware, and helper files where crypto lives without saying so. Event Horizon recognises crypto by structural shape — independent of labels — and produces inventory that the CBOM tool of your choice (SandboxAQ, PQCA CBOMkit, others) can render accurately.

"PQC migration is a board-level concern for every major telco. The discovery sub-project — knowing exactly which crypto code is where — is the first six months of any serious migration programme. Event Horizon is what makes that discovery accurate at telco scale: structural recognition of the forks, hand-rolls, and helper-file crypto that keyword-based inventory tools miss." — positioning anchor for telco-CTO conversations

Telecom use cases

  • Pre-migration crypto inventory across network-stack C/C++ codebases
  • Hybrid TLS deployment verification (X25519 + ML-KEM-768 combinations)
  • SIM / eSIM authentication-stack PQC readiness
  • Vendor-supplied middleware crypto-conformance audits
  • CycloneDX-compliant CBOM output for procurement pipelines (SandboxAQ, PQCA CBOMkit, Sectigo, Keyfactor)
  • Repeatable scans for longitudinal migration tracking, with drift comparison between scans for quarter-on-quarter change reporting
  • Reproducible evidence packages structured to support audit conversations with NCSC, ENISA, and equivalent national bodies

Vodafone's HQ is in Newbury, 25 miles from our Sandhurst office. Thames Valley has the highest density of UK telco-engineering presence outside London.

Financial Services · DORA

Produce audit-supporting crypto-conformance evidence. On demand.

DORA (Digital Operational Resilience Act) went live in the EU on 17 January 2025. UK regulators (FCA, PRA) are converging on equivalent expectations. The regulation requires regulated financial entities to manage and document ICT third-party risk — including cryptographic dependencies. "We trust the vendor's labelling" is no longer a defensible audit answer.

Event Horizon produces structured, reproducible evidence: every file in scope, classified by crypto-structure family. The same report a CISO needs for internal risk management is the report DORA-aligned auditors want to see. Drift comparison between scans is included for tracking change over time.

"Banks aren't trying to find the bug. They're trying to prove to their regulator that they know where their crypto is and have a defensible process around it. Event Horizon is the structural-recognition layer underneath that process — the evidence that turns 'we trust the vendor's label' into 'we can demonstrate the shape of the code matches the algorithm specification.'" — positioning anchor for bank-CISO conversations

Financial-services use cases

  • DORA Article 5 — ICT third-party risk management evidence (CycloneDX CBOM output feeds your existing inventory pipeline)
  • Quarterly crypto-conformance reports for internal audit
  • Vendor-library upgrade verification (e.g. wolfSSL or OpenSSL version bumps)
  • Custody-platform and payment-system crypto inventory
  • M&A due-diligence on acquired fintech codebases
  • Cross-border data-flow crypto compliance (UK / EU regulatory split)

UK fintech corridor (London Wall, Canary Wharf) is 50 minutes by Elizabeth Line. Tier-2 banks and fintechs are the most-receptive segment for structured-evidence Sprint engagements.

Your industry isn't on the list?

Critical-infrastructure operators, cybersecurity vendors, OSS maintainers, and government agencies all have crypto in C/C++. If your codebase has crypto, the conversation starts here.

Tell us about your codebase →