what we build
Products
Every product below is custom-engineered software we build and run — each card lists what it does and the capabilities it ships.
FinSage
FeaturedAI-Powered Financial Intelligence
Our flagship financial-intelligence platform. FinSage uses AI modules to turn complex financial data into practical, actionable insight, built on a custom, security-first architecture.
- AI
- Fintech
- Analytics
- Security
Custom-Engineered Architecture
Built from the ground up with a security-first design rather than assembled from off-the-shelf parts.
AI-Powered Analytics
AI modules transform complex financial data into practical, actionable insight.
Real-Time Intelligence
Automated reporting and anomaly detection surface what matters as it happens.
Enterprise-Grade Security
Security is a foundation of the architecture, not an afterthought bolted on later.
TradegenX
FeaturedClaude-Driven Trading Orchestration
A Claude-driven orchestration layer that runs disciplined, small-capital ($100–500) multi-strategy automated crypto trading on Binance Futures through an existing execution engine — observed, overridden, and managed from the Claude Code CLI or a Telegram bot, with hard safety rails. The goal is a positive-expected-value, drawdown-controlled, auditable system, not hype.
- AI
- Trading
- Automation
- Crypto
Claude-in-the-Loop Strategy Generation
Claude proposes and refines trading strategies that stay under human review.
Multi-Strategy on One Account
Several strategies run together on a single account, coordinated rather than competing.
CLI + Telegram Control
Observe, override, and manage the system from the Claude Code CLI or a Telegram bot.
Hard Safety Rails
A leverage cap of 3x and triple-confirmation on live actions keep real-money operations bounded.
Sitragenx
PlatformAutomated Futures Trading Engine
The execution backbone: a Binance Futures automated trading engine that performs technical-analysis-based execution. An async Python (FastAPI) and PostgreSQL architecture built for reliability and performance.
- Trading
- Engine
- Python
- Automation
Technical-Analysis Automated Execution
Executes trades automatically from technical-analysis signals on Binance Futures.
Async High-Performance Backend
An async Python (FastAPI) and PostgreSQL stack tuned for reliability and throughput.
REST-Driven, Integrable Engine
A REST-driven engine designed to integrate cleanly with the products that orchestrate it.
Production-Grade Deployment
Built and operated as a production engine rather than a one-off script.
PyramidOS
PlatformThe Operating System for Pentest Firms
A multi-tenant B2B SaaS platform that consolidates the complete operational lifecycle of boutique pentest firms — from lead capture, scoping, and proposal generation through project execution, findings management, branded report delivery, client portal, compliance tracking, and subscription billing. Built on Django 6 + DRF with a Next.js 16 front end.
- Security
- SaaS
- Pentest
- Platform
End-to-End Project Lifecycle
Drives every engagement through an 11-state finite-state machine, from lead to delivery.
Findings Library & QA Workflow
A reusable findings library mapped to CWE/OWASP/CVSS with a draft → reviewed → approved → delivered QA flow.
Branded PDF Report Builder
Generates branded reports with WeasyPrint from per-tenant templates.
Secure Client Portal
A client portal with signed-URL sharing and self-service retest requests.
Compliance Tracking
Tracks ISO 27001, IASME, and Cyber Essentials engagements and evidence.
Multi-Tenant Billing & Security
Multi-tenant Stripe billing on PostgreSQL row-level security, with SSO/2FA and tool imports.
Fin-On
PlatformCompliant B2B Onboarding Workflow
A fintech B2B customer onboarding workflow system built for EU AML and Lithuanian regulatory compliance. Fin-On guides every application from an anonymous Wolfsberg CBDDQ form through automated risk scoring, KYC verification, multi-role approval, and a PDF wet-signature close — with a full immutable audit trail.
- Compliance
- AML
- KYC
- Onboarding
- Fintech
Wolfsberg CBDDQ Application Form
Captures onboarding data through the Wolfsberg CBDDQ V1.4 form — 34 sections and 405 fields.
Parallel Enrichment & KYC
Runs JARS and JADIS enrichment alongside iDenfy KYC verification in parallel.
Rule-Based Risk Scoring
A rule-based 1–100 risk score drives five-level routing of each application.
Four-Eyes CDD Approval
Multi-role CDD checklists enforce four-eyes review before an application is approved.
PDF Wet-Signature Close
Generates the onboarding PDF and closes the file through a wet-signature flow.
Immutable Audit Trail
An immutable audit trail with 7-year retention satisfies EU AML and GDPR obligations.
Fin-Score
PlatformAutomated SME Loan Decisioning
An end-to-end automated credit decisioning platform for regulated lenders. From a minimal web form, Fin-Score enriches the applicant's data from external registries, runs configurable knockout rules and a 3-category weighted score, and delivers a fully automatic approve or reject decision — with digital signature capture and an immutable audit trail.
- Credit Scoring
- Fintech
- Automation
- Compliance
- Decisioning
Minimum-Input Application Form
Starts from a minimal web form, asking only for the inputs the decision actually needs.
Parallel Registry Enrichment
Enriches the application in parallel from Registry Center, Credit Info, Scorify, and Sodra.
Configurable Knockout Rules
Applies 12+ configurable knockout rules before any score is computed.
Weighted Credit Score
A 3-category weighted score — Owner 30%, Behavioral 30%, Financial 40% — drives the decision.
Digital Signature Capture
Captures the applicant's digital signature via Smart-ID or Mobile-ID.
Compliance-Anchored Audit Trail
An immutable, compliance-anchored audit trail records every decision for review.
SalesGenX
Agentic sales engineYour Outbound Sales Team, Run by AI Agents
An autonomous B2B outbound engine that runs go-to-market end to end. SalesGenX sources and researches prospects, writes genuinely human, on-brand cold emails, and passes every message through deterministic anti-spam and quality guards plus an adversarial reviewer before a single human persona sends — then it triages replies and books meetings, all under hard, human-set guardrails.
- AI agents
- Sales automation
- B2B outreach
- Agentic AI
- Go-to-market
Autonomous Lead Sourcing & Research
Agents source target accounts and decision-makers, then research each one so every message is specific — not a mail-merge blast.
Human-Reading AI Copywriting
Short, on-brand cold emails written by AI that read like a person wrote them — every personalization fact cited from real source data, never invented.
Anti-AI-Tell & Deliverability Guards
Deterministic guards strip the tells that get AI email flagged, and a blind, fail-closed adversarial reviewer rejects anything off — so messages land in the inbox, not spam.
Compliance Built In
Per-region rules (CAN-SPAM, GDPR legitimate-interest, UK PECR, the Gulf) and a suppression list are enforced in code, never left to the model.
Reply Triage & Auto-Booking
Agents classify inbound replies and, on genuine interest, send your booking link — turning a reply into a meeting without a human watching the inbox.
Deterministic Brain & Kill-Switch
A deterministic orchestrator plans each day within hard, non-bypassable caps, with a human persona on every send and an always-on kill-switch. The model proposes; your rules decide.
CoreX
Agentic security operationsAI Security Engineers That Give Your SOC a Force Multiplier
A team of AI security agents that work like tireless internal security engineers alongside your existing SOC. CoreX watches your SIEM around the clock, surfaces the anomalies that matter, opens and enriches incident tickets in your own workflow, and delivers board-ready monthly reports. It doesn't replace your analysts — it multiplies them, so your team responds faster while your sensitive data never leaves your perimeter unmasked.
- AI agents
- Security operations
- SOC automation
- Anomaly detection
- Agentic AI
Always-On SIEM Watch
Your security console is monitored 24/7 by AI agents. Instead of a wall of alerts, your analysts wake up to a triaged, ranked shortlist of what actually needs a human.
Anomaly Detection & Triage
Agents flag the unusual, rank it by severity, and cut the false-positive noise — so real threats surface early instead of being buried in the queue.
Tickets on Autopilot
CoreX opens, enriches, and routes incident tickets straight into your existing workflow — no rip-and-replace, no new console for your team to learn.
Board-Ready Monthly Reports
Executive summaries and analyst detail, generated automatically each month — the reporting that usually eats your team's time, off their plate.
Your Data Never Leaves Unmasked
Sensitive identifiers are masked before anything reaches an external model, and if that protection is ever off, the system simply makes no external call. Data-sovereign by design.
Faster Response, Humans in Command
CoreX augments your team, it doesn't take it over. Consequential actions stay behind human approval, with an always-on kill-switch — the agents propose, your people decide.
PLDrop
Security appliancePenetration Testing Through a Box You Post, Not a Person You Fly
A sealed appliance you plug into your own network, which then becomes the single audited channel for penetration testing — internal, web, external, API and Wi-Fi. Every session opens only on the customer's approval, lasts exactly as long as they allow, can be cut mid-session, and leaves a per-command record in the customer's own storage.
- Penetration testing
- Security appliance
- Zero retention
- Audit trail
- On-device AI
Nothing Opens Without Approval
Access is granted per session by the customer, for a lifetime they set — and a live session can be revoked mid-command. There is no standing access to leave lying around.
The Unit Only Dials Out
No port on the device faces the internet, so there is no inbound path for anyone else to find. The audited channel is the only way in.
The Tester Works Inside a Sealed Workspace
The consultant gets one Linux workspace and the tools — and that is the whole of what they can reach. The uplink, the keys and the record sit outside it.
On-Device Supervision
A purpose-trained model on the device watches that workspace for an attempt to leave it, for work outside the agreed scope, and for data moving by volume or by class. Findings leave the unit; the traffic does not.
Records to the Customer's Own Storage
Every command and transfer is bound into a tamper-evident record written to the customer's own bucket. Remove a line and the record stops verifying.
Wireless Testing On Board
The hardware unit carries its own radio for Wi-Fi work — the one thing a software-only deployment cannot do. A virtual build covers everything that does not need a radio.