Infrastructure security · regulated environments · in your boundary
Security engineering for the infrastructure your business runs on.
When a customer review, an audit, or a mandate puts your systems under a bar your team can't clear, FEDLIN builds the controls it requires inside your own environment, so the deal moves forward.
Partners & Verifications Anthropic Cyber Verification · Vanta MSP · Google Cloud Partner · Red Hat Partner
What we engineer
Secure the estate your business runs on.
One practice across your whole estate: identity, edge, workloads, and the cryptography beneath them, on the cloud, on-premises, and hybrid infrastructure you run. Most engagements start with a PQC readiness assessment, then open into the program.
Start here
PQC Readiness
A free scan of what you run, then a CBOM and migration roadmap mapped to the mandate you answer to. The door most engagements enter.
See the assessment →Running AI workloads?
Secure the AI you run
Assess and harden the agents, MCP servers, and cryptography already in your environment.
Harden your AI →Behind the door, one practice across the estate, entered at the rung your risk sits on:
Foundation
Post-Quantum ReadinessThe cryptographic base your estate stands on. OMB M-26-15 Phase 1 readiness, plus commercial crypto-agility.
Evidence & closure
GRC Engineering Vulnerability RemediationFindings to closed, mapped to your framework.
Every engagement is a fixed-fee build. Start at the control blocking you and scale to the full program.
Pilot Build
One fix that unblocks the deal, with the evidence.
Enterprise-Readiness Build
Measure, engineer the fixes, clear the review.
Build & Run
The full control set, kept audit-ready.
Mandate Engineering
Flowdown controls for defense and critical-infrastructure mandates.
What the Build leaves you holding
The Risk Register, yours to keep.
The Build's deliverable is a client-owned Risk Register: every finding ranked, costed, and mapped to the frameworks you answer to, produced by the controls running in your own environment. One remediation clears every framework it maps to, and each finding scopes what comes next. The action plan stays yours whether or not the work continues with us.
Every row: finding, surface, severity, business impact, frameworks satisfied, remediation and effort, the program it routes to, and status.
Let's build your security program.
It starts with a scoping call. We map the review in front of you and scope the build from there.
Book a Scoping CallAdvisor, MSP, or agency? You keep the client and the relationship. We're the engineering arm, findings to you first. See the partner program →
Don't take our word for it
Point it at your own domain.
Run it on your own site and see your TLS and post-quantum posture the way we see ours. No signup. The scanner is open source and runs as an agent-callable tool on our MCP server.
Unable to scan
Email these results to yourself
FEDLIN receives a copy and may follow up.
Check your inbox.
This scan covers your public TLS surface only. In-boundary endpoints, firmware, code dependencies, and your full cryptographic inventory require a dedicated assessment.
scan_post_quantum at https://mcp.fedlin.com/mcp From the Blog
Latest field notes
How the 2026 Water-Utility Attacks Worked
The July attacks on water systems turned on internet-exposed controllers reachable with no novel exploit. An account of the compromise, how the access worked, and what closes it.
Before the Algorithm: Where a Post-Quantum Plan Really Starts
The deadline lands and the instinct is to pick an algorithm. The plan actually starts a few phases earlier, and the hard part is the calls you make in the middle.
SPIFFE/SPIRE on OpenShift: Building the Workload Identity Plane Your Zero-Trust Model Is Missing
After locking down human and device access, pod-to-pod communication was still trust-the-network. SPIFFE/SPIRE closes that gap. Short-lived cryptographic identities, attested per-workload, chained under your existing Root CA.
Frequently Asked Questions
What does working with FEDLIN look like?
Engagements start with a scoping call about your architecture and the review in front of you: a SOC 2, a HIPAA audit, an enterprise security review, or investor diligence. From there the work is a build. We measure what your buyer requires, engineer the fixes, and hand you the evidence that clears it.
Does FEDLIN do architecture or engineering?
Both, by design. Every engagement starts with the architecture decision (which controls, where, and why) before anything is built. The design and the build are complementary and can be delivered on their own or together.
We don't have a security team. Can FEDLIN run the whole program?
That's a common place to be as you grow. FEDLIN embeds as your security function: it builds the controls, wires the evidence, stands up or works within your GRC platform, and runs the program that clears the review, then keeps it clear. You get a security architect without making the hire.
What's the difference between FEDLIN and a GRC platform like Vanta?
A GRC platform monitors and collects evidence from controls that already exist. FEDLIN builds those controls: IAM configurations, pipeline gates, secrets management, infrastructure hardening, and the NIST AI RMF layer for agentic systems. When a GRC platform is in the picture, FEDLIN wires the controls so it has something real to monitor. When there's no platform yet, FEDLIN can stand one up in your environment as part of the build.
Do you work with companies building with LLMs or agentic systems?
Yes, and it is a core capability. LLM integrations, MCP servers, and agentic pipelines open a security surface standard assessments are not designed to reach. If your team ships AI features on infrastructure you run yourself, FEDLIN builds the NIST AI RMF control layer those systems need, mapped to the frameworks your build operates under.
What does OMB M-26-15 require of your infrastructure?
OMB M-26-15 Phase 1 (2026–2027) requires agencies and their contractors to complete a cryptographic inventory (a bill of materials covering every algorithm, certificate, and key across their infrastructure) and begin sequencing migration to NIST-standardized post-quantum algorithms: ML-KEM, ML-DSA, and SLH-DSA. It reaches the whole estate: TLS endpoints, certificates, key stores, dependencies, and any signing infrastructure, on cloud, on-premises, and hybrid systems. FEDLIN produces that inventory as a CycloneDX CBOM and sequences the migration from it.
How does NIST AI RMF implementation work for self-hosted AI?
NIST AI RMF defines the functions (govern, map, measure, manage) but doesn't prescribe how to implement them on infrastructure you run yourself. FEDLIN builds those controls at the infrastructure layer: context boundaries, access scoping for MCP servers and agentic pipelines, prompt injection coverage, and audit logging mapped to the govern and manage functions. Every control is built into your own environment and produces evidence you hold.
What's the relationship between NIST CSF and NIST 800-53?
NIST CSF is the framework designed for communication. It gives founders, executives, and non-technical stakeholders a clear language for security posture across five functions: Identify, Protect, Detect, Respond, Recover. NIST 800-53 is the technical control catalog underneath it, the specific controls that implement what CSF describes. FEDLIN assesses and builds to both. Every major framework, from SOC 2 to HIPAA to PCI-DSS, maps back to this foundation.
What does principal-led mean in practice?
You work directly with the principal security architect, the person who owns the architecture, the engagement, and the build. Delivery draws on a vetted partner network where scope requires it: penetration testing, specialized infrastructure work, or govtech contracting.
Do you work with fractional advisors, agencies, or MSPs?
Fractional advisors, MSPs, and agencies bring FEDLIN in for the specialist work their clients need and can't keep on staff: cryptographic readiness and crypto-agility, edge and identity hardening, NIST 800-53 engineering, and self-hosted AI security. You keep the client, the relationship, and the advisory lead. FEDLIN does the engineering, findings to you first. See the partner program for how this works.