Event Horizon's C-DNA recognition (Crypto-DNA structural signature matching) maps to specific commercial pressure in three sectors. Different buyer, different urgency, same product underneath.
Defence prime contractors and research labs receive crypto-bearing code from many suppliers. Some is in-house, some is contractor-built, some is open-source-derived. The procurement chain assumes the labelling is accurate. Often, nobody verifies that "AES" really is AES, or that the constant-time variant the spec called for is actually constant-time-structured in the delivered code.
Event Horizon gives a defence engineering team a fast structural conformance check (seconds to minutes) on every C/C++ file in a delivered codebase. It tells you what's crypto, what family it fingerprints as, and which files diverge from documented references — before the code goes into a system that's expensive to recall.
UK-based; Sandhurst office is 10 minutes from Farnborough. Tier-1 prospect engagements include conversations with research-lab security teams in the Thames Valley defence corridor.
NIST published the post-quantum standards in August 2024 (FIPS 203, 204, 205). NSA's CNSA 2.0 transition timeline targets 2030-2035 for full PQC migration across national-security systems. Network operators with millions of lines of C/C++ in their core network stack, SIM/eSIM authentication, customer security infrastructure — all face the same first step: an accurate inventory.
You can't migrate what you don't know you have. Keyword-based inventory programmes for telco-scale codebases miss forked libraries, vendor-modified middleware, and helper files where crypto lives without saying so. Event Horizon recognises crypto by structural shape — independent of labels — and produces inventory that the CBOM tool of your choice (SandboxAQ, PQCA CBOMkit, others) can render accurately.
Vodafone's HQ is in Newbury, 25 miles from our Sandhurst office. Thames Valley has the highest density of UK telco-engineering presence outside London.
DORA (Digital Operational Resilience Act) went live in the EU on 17 January 2025. UK regulators (FCA, PRA) are converging on equivalent expectations. The regulation requires regulated financial entities to manage and document ICT third-party risk — including cryptographic dependencies. "We trust the vendor's labelling" is no longer a defensible audit answer.
Event Horizon produces structured, reproducible evidence: every file in scope, classified by crypto-structure family. The same report a CISO needs for internal risk management is the report DORA-aligned auditors want to see. Drift comparison between scans is included for tracking change over time.
UK fintech corridor (London Wall, Canary Wharf) is 50 minutes by Elizabeth Line. Tier-2 banks and fintechs are the most-receptive segment for structured-evidence Sprint engagements.
Critical-infrastructure operators, cybersecurity vendors, OSS maintainers, and government agencies all have crypto in C/C++. If your codebase has crypto, the conversation starts here.
Tell us about your codebase →