What we build

Identity and security, engineered end to end.

The authentication, authorization, and cryptographic plumbing that regulated systems depend on. Designed, built, and hardened for production and audit.

PKI & Certificate Lifecycle

Certificate authorities, issuance, and automated lifecycle for systems that can't afford an expired cert.

  • Private & public CAs
  • mTLS
  • Certificate lifecycle automation
  • HSMs & key management
  • Code signing

Passwordless & Strong Authentication

FIDO2, passkeys, and smart-card auth that retire the password without hurting the user experience.

  • FIDO2 / WebAuthn
  • Passkeys
  • PIV / CAC & smart cards
  • MFA & step-up
  • Biometrics

SSO, Federation & OAuth

Single sign-on and federation that works across your org, your partners, and your acquisitions.

  • OAuth2
  • OpenID Connect
  • SAML
  • Identity brokering
  • Token services

ICAM & Access Management

Identity, credential, and access management aligned to how regulated and federal-adjacent programs are actually evaluated.

  • ICAM / FICAM-aligned
  • RBAC & ABAC
  • Authorization & policy
  • Directory & IdP integration
  • Identity governance

Zero Trust & Workload Identity

Service-to-service trust built on verifiable identity, not network position.

  • mTLS everywhere
  • Workload & service identity
  • Secrets & key management
  • Policy enforcement
  • Continuous verification

Secure Data Flows & Integration

Encrypted, auditable data movement between systems that were never designed to talk to each other.

  • End-to-end encryption
  • Secure APIs
  • Key management
  • HIPAA / PCI-aware
  • Audit & logging

Why trust us with this

We've built this exact class of system before.

Our founders spent 20+ years on mission-critical systems at IKEA, Sony Mobile, Ericsson, and Handelsbanken. The identity depth isn't theoretical. It comes from hands-on PKI and certificate-management work at Sony Mobile and Ericsson, where a mistake in the crypto plumbing isn't a bug, it's an outage.

Doquima · Proof of capability

TernaID: passwordless identity platform

A production passwordless identity system we architected end to end: PKI-backed credentials, mTLS between services, OAuth2/OIDC flows, and encrypted data paths. The clearest evidence of what we can build for you.

PKImTLSOAuth2 / OIDCFIDO2Cryptography
Sony Mobile · Ericsson

PKI & certificate management at device scale

Founder background building and operating the certificate and trust infrastructure behind consumer devices and telecom systems: certificate lifecycle, key management, and the hard parts of cryptographic identity.

PKICertificate lifecycleHSMKey management
IKEA

Global availability API at peak scale

Migrated and optimized the backend for Customer Item Availability during a global cloud transition (OpenShift to GCP), redesigning API endpoints and monitoring to prevent outages at peak seasonal traffic, handling 1,000+ requests per second.

JavaSpring BootGCPKubernetesAPI Management
PNL

National digital lottery platform (Sweden)

Engineering delivery on a national digital lottery platform, with the reliability, security, and regulatory compliance such systems demand.

High availabilityComplianceCloud
IKEA

Self-service order management

Led the technical architecture for a global self-service Order Management portal, with real-time data sync between web interfaces and backend ERPs, reducing manual support intervention.

Node.jsJavaScript (ES6+)GCPMicroservices

Who we work with

Two kinds of teams call us.

Prime contractors & systems integrators

You've won, or are bidding on, work that needs serious identity, PKI, or ICAM depth, and you need a senior subcontractor who can carry that scope. We slot into your team and deliver the hard identity pieces, on your timeline.

Regulated commercial teams

You're in healthcare, finance, or another regulated space, and authentication, access, and data protection have to be right. We design and build identity and security systems that hold up to your auditors.

How we typically start

We focus on understanding before acting.

We earn trust step by step. A typical engagement starts small and low-risk, then scales as we deliver.

  1. 1

    Discovery or assessment

    A short discovery to understand your systems, constraints, and goals.

  2. 2

    Scope and priorities

    We define what matters most and where to focus first.

  3. 3

    Execution plan

    A clear plan with milestones, owners, and success criteria.

  4. 4

    A low-risk first step

    We start with a contained piece of work to build mutual trust.

  5. 5

    Execute and adapt

    Transparent collaboration, open to feedback, and flexible when needs change.

Industries

Federal & Public Sector Healthcare Financial Services Systems Integrators Regulated Enterprises

Let's talk about your identity and security work.

Whether you're a prime that needs a senior identity subcontractor, or a regulated team that needs authentication and access done right, tell us what you're building. We'll come back with a clear, low-risk first step.

Start a conversation