Cybersecurity consultancy · products

security starts here.

SECURIX is a cybersecurity consultancy — advisory first, with audit and offensive testing, compliance across ISO 27001, SOC 2, GDPR, the EU AI Act and DORA, and incident response. We also build the tools we run for our own clients: Nightprill and Scrytide. Everything we report is measured, and we say plainly what we couldn't test.

What we do

Engagements, run by people who build the tooling

Consulting work, scoped to your perimeter and your regulator — carried out by the same team that writes the engines behind our products.

01

Cybersecurity advisory

Our core work: security strategy, risk and defensive architecture — where to invest, what to fix first, how to build and operate so you stay secure. An ongoing security partnership, not a one-off report.

02

Audit & offensive testing

Security assessments, penetration testing, red-team and social-engineering — scoped and authorised in writing. We prove access where it exists, and stop at the line where a third party would be harmed.

03

Compliance & regulatory

Preparation and evidence for ISO 27001, SOC 2, GDPR, the EU AI Act and DORA. We build the evidence your auditors accept — we don't sell the certificate.

04

Incident response & support

When something is already wrong: containment, evidence, and a written account your team and auditors can rely on — plus ongoing security support between engagements.

Our products

The tools we run — available to you

We didn't buy our stack; we built it, and we use it in our own engagements every day. Two are in production today, priced in the open on their own sites.

How we work

Fewer claims. Every one true.

The rule that governs our products governs our engagements: a test that didn't happen is not a negative result.

We show our work

Every finding carries its evidence and a way to reproduce it. If we couldn't test something, the report says so — we don't dress a gap as a clean result.

We don't claim exhaustiveness

No tool and no team sees everything. We tell you what our scope covered and where its edges are, so you can decide what to do about the rest.

Your data stays in Europe

Processing runs in the EU, on named sub-processors, never sent to a consumer AI service — with a GDPR Article 27 representative in the EU.

We measure — we don't damage

We go far enough to be sure, and stop before harm. Anything beyond a proof of access happens only under written authorisation, scoped per perimeter.

Built to survive a DPO's questions, not just a demo.

Your data is processed within the EU or Switzerland, each provider bound by a data-processing agreement and named to you on request. Nothing is sent to a consumer AI service.

For frameworks like ISO 27001, SOC 2, GDPR, the EU AI Act and DORA, we produce the technical evidence and help you prepare — we don't issue the certification. For the GDPR itself, we act as your processor under contract during engagements, and as controller only for our own products, described in our privacy policy.

ISO 27001 SOC 2 GDPR EU AI Act DORA EU / CH processing

Tell us your perimeter.

An engagement, a product trial, or a question about scope — we'll tell you what we can prove, and what we can't, before anything is signed.

hello@securix.hk