Talk to us →
Home / Research / Cybersecurity

Security as a first-class concern.

LENS engineers, audits and ships under ISO 27001 - with OWASP, MITRE ATT&CK and ONVIF S/G/T/M baked in. Our products are zero-trust by default, edge-native, and crypto-agile for the post-quantum era. LENS Shield extends the same posture to your stack.

ISO27001
Certified information security
Zero
Trust model, by default
6
Certifications & conformances
7d
High-severity patch target
PQC
NIST-standardized, ready now
100%
On-prem inference available
How we secure LENS

Six layers, continuously audited.

Compliance is the floor - not the ceiling. We test against MITRE ATT&CK, run OWASP-aligned security testing on every release, and remediate what we find. The latest test report is available to customers under NDA.

01 · Identity & access

Zero-trust, by default.

Every service-to-service call is mTLS-authenticated. Every operator action is signed and logged. No implicit trust at the network boundary.

  • SSO · SAML 2.0 + OIDC
  • SCIM provisioning
  • Hardware-key MFA enforced
  • Just-in-time elevation
02 · Data & cryptography

Crypto-agile, PQC-ready.

AES-256 at rest, TLS 1.3 in transit, hybrid PQC-classical key exchange available now. Algorithms are swappable without redesigning the platform.

  • ML-KEM-1024 (KEM)
  • ML-DSA-65 (signatures)
  • SLH-DSA-256 (hash-based)
  • FIPS-standardised algorithms
03 · Audit & observability

Every action, immutable.

Append-only, hash-chained audit trails for sensitive operations: evidence-grade chain of custody for forensics, court submissions and regulatory requests.

  • Tamper-evident logs
  • SIEM-native exports
  • STIX/TAXII threat intel
  • SOAR-ready webhooks
04 · Software supply chain

Signed at every step.

An SBOM is produced for every release and available to customers on request. Builds are signed and dependency scanning runs on every commit.

  • SBOM · CycloneDX
  • Signed build artefacts
  • Reproducible release pipeline
  • Automated dependency scanning
05 · Edge & deployment

On-prem when it must be.

Air-gapped deployments supported for defence, healthcare and critical infrastructure. Models run locally; only telemetry leaves the perimeter, and only when allowed.

  • Air-gap installers
  • Sovereign cloud regions
  • BYOK / HSM integration
  • Hardened OS images
06 · Continuous adversarial testing

Red-team, always-on.

Independent penetration testing on a recurring schedule, internal red-team and purple-team exercises against current builds, and a published vulnerability-disclosure policy.

  • Independent VAPT · recurring
  • Internal red team
  • Coordinated disclosure
Certifications & standards
ISO 27001
Certified
ISO 9001
Certified
OWASP
ASVS aligned
ONVIF
S / G / T / M
MITRE
ATT&CK aligned
NIST
CSF 2.0 mapped
Post-quantum cryptography · ready today

The quantum era won’t wait.
Neither do we.

“Harvest now, decrypt later” is a real threat. Sensitive surveillance footage, biometric templates and audit trails captured today must remain confidential when fault-tolerant quantum hardware arrives. LENS supports the NIST post-quantum standards in hybrid mode today - with crypto-agility to swap algorithms as the standards evolve.

Post-quantum algorithms in LENS
ML-KEM-1024 Lattice-based key encapsulation, standardised from Kyber. Hybrid with X25519 for transport. FIPS 203
ML-DSA-65 Lattice-based signatures, standardised from Dilithium. Module signing, audit trail anchoring. FIPS 204
SLH-DSA-256 Hash-based stateless signatures, standardised from SPHINCS+. Long-term archival integrity. FIPS 205
AES-256-GCM Symmetric encryption. Retains a 128-bit security margin against Grover search. FIPS 197
01
Hybrid by default.

Classical + PQC ciphers run side-by-side. If either family is broken tomorrow, the other still protects the channel.

02
No quantum hardware required.

All PQC algorithms run on classical CPUs, including edge devices already in the field. Software upgrade path, not a forklift.

03
Crypto-agile architecture.

Algorithms are configuration, not code. Swap, upgrade or rotate without redeploying the platform.

04
Quantum-safe chain-of-custody.

Evidence captured today - surveillance footage, biometric matches, command logs - remains tamper-evident in 2040 and beyond.

LENS Shield · Posture-as-a-service

The same posture, extended to your stack.

For governments, critical infrastructure operators and regulated enterprises that need to harden their existing systems - not replace them. Audit, uplift, and migrate, with the same engineers who built LENS.

Tier 01

Audit & gap report

Two-week structured engagement. We map your stack against ISO 27001, NIST CSF and your sector regulator, then produce a prioritised remediation roadmap.

  • Architecture review
  • VAPT (accredited methodology)
  • SBOM & supply-chain audit
  • Threat-model workshop
  • Board-ready gap report
Start an audit
Tier 02 · Most common

Harden & uplift

Eight-to-twelve-week engagement. We embed engineers into your team to ship the fixes: zero-trust rollout, observability uplift, identity hardening, secure-by-design refactors.

  • Everything in Tier 01
  • Embedded engineering pod
  • Identity/SSO/SCIM rollout
  • SIEM + SOAR integration
  • Runbooks & tabletop drills
  • 30-day post-engagement support
Start a hardening
Tier 03

PQC migration

For organisations where data has to remain confidential for decades. We migrate cryptographic primitives, key management and certificate issuance to post-quantum standards, in stages, with rollback at every step.

  • Crypto-inventory of your stack
  • Hybrid PQC pilot deployment
  • Certificate-issuance migration
  • HSM & KMS modernisation
  • Long-tail rotation plan
Plan a PQC migration
Where Shield is built to operate

Engineers who’ve shipped at scale.

LENS Shield draws on the same team that runs production for national-scale public safety, biometric systems and steel-floor analytics. We don’t outsource. We don’t resell. We do the work.

Government

Sovereign deployments

Police, smart-city and defence procurements with sovereign security audits as the floor. Air-gapped where required.

Critical infrastructure

Steel, energy, ports

OT/IT segmentation. ICS-aware monitoring. Zero-trust rollout for plant-floor networks already in production.

Regulated enterprise

Banking & healthcare

HIPAA, DPDPA, PCI-DSS readiness. PQC migration roadmaps for institutions on multi-decade data-retention obligations.

Civic tech

Identity & benefits

Hardening identity stacks where the threat model includes nation-state adversaries. Biometric template protection.

Reference material

Read the small print - we publish it.

Security disclosures, our vulnerability-reporting protocol and our responsible-AI principles are public. Audit reports are available to customers under NDA. Trust starts with paper trails.