Before we begin.
Practical answers about software-focused firmware work. Hardware testing and full IoT ecosystem assessments are outside Kedloc’s scope.
What makes a good first engagement?
One accessible, customer-supplied firmware image or a specific question about a software component within it. The initial discussion establishes what can be examined, which inputs are needed and whether the request fits my demonstrated capabilities.
Do you provide hardware or full IoT security testing?
No. Kedloc focuses on software analysis of supplied firmware images and components. Physical extraction, device teardown, hardware interfaces, radio testing and hardware attacks are not offered. Cloud, companion-app, network and full IoT ecosystem testing are also excluded. If a conclusion requires device testing, the report identifies it as unverified; that work needs a separate provider.
How are fees and timelines determined?
After the inputs and scope are understood. Image accessibility, target complexity, validation needs and reporting depth affect effort. The proposal defines the fee, delivery date, exclusions and any retest terms before paid work starts.
Can you work with another consultancy?
I welcome bounded firmware research or subcontract work that fits my demonstrated skills. Responsibilities, customer permissions, deliverables and supervision where needed should be clear before the engagement begins.
Does an assessment establish CRA compliance?
Technical work may contribute evidence to a wider compliance programme. Kedloc does not offer CRA certification, legal advice or a guarantee of conformity. Any requested evidence needs a defined role within the customer’s broader process.
How should sensitive material be shared?
Start with a non-confidential description by email, LinkedIn or X. Before sending proprietary firmware, source code or sensitive findings, agree authorization, confidentiality requirements, the transfer method and data-handling terms. This site does not collect firmware uploads.