Architecture reviews, security reviews, and bring-up triage for teams shipping Android on custom hardware. We review the code, configuration, logs, and build artifacts behind the issue, then write a report with prioritised findings, reproduction steps, and references.
Architecture reviews covering the full stack — bootloader, kernel, HAL, framework, and app layer — with prioritised findings, reproduction steps, and references to the AOSP commits and vendor docs behind each recommendation.
Security reviews: SELinux policy, verified-boot chain, keystore and attestation behaviour, OTA/update paths, and third-party SDK exposure — scoped to platform risks rather than CTS/VTS pass-fail alone.
Bring-up triage on stuck hardware — kernel, init sequence, HAL, or first-boot regressions — delivered as a short, targeted engagement rather than an open-ended retainer.
Technical due diligence for vendor, SDK, or codebase evaluation: repo reads, risk summaries, and references you can hand to stakeholders.
A 45-minute scoping call. When you can share it, we review the architecture doc, repo README, or specific ticket before the call. If the work is not a fit, we say that before proposing a scope.
Within two to three business days: objectives, deliverables, hourly estimate, and a fixed ceiling. You approve or adjust the scope before work starts.
We read, test, and reproduce. You get short updates every two to three days with current findings, affected files or components, and open questions.
A written report with prioritised findings, reproduction steps, and references to AOSP, CVE, and vendor documentation. One hour of follow-up Q&A included; remediation is optional and scoped separately.
Before an AOSP device ships we read the security posture — SELinux policy, verified-boot chain, keystore, attestation — plus the OTA pipeline. You get a written report with prioritised findings and reproduction steps.
When a new board or SoC is blocking a release, we do focused triage: kernel config, init, HAL, first-boot. Written findings with reproduction steps, not an open-ended retainer.
Device-owner posture, verified boot, attestation chain, and third-party SDK triage across a deployed fleet. Output is a prioritised findings list with remediation notes.
Tell us what you're building and where you're stuck. We reply with the scope we think fits, including when a smaller engagement or a different path is better.