Security Consulting Open Source R&D R&D

Security is
not optional.

For organizations that can't afford to get security wrong. We embed with your team and go deep on the architecture, code, and systems you depend on.

$400B+
Secured by systems we helped design or built Assets secured
100+
Companies supported on critical security Companies supported
20+
Open source security tools Open source tools Open tools
Distrust stood out from the very first conversation. Their depth of knowledge went far beyond our expectations, and they immediately identified ways we could strengthen our systems before we had even formally engaged them. I'm genuinely glad we chose to work with them.
Alex Kiriakides Co-founder, Trusted Stake
Where we
go deep

The hard parts that few firms can do.

Across the systems we design, build, and review, one method holds: eliminate single points of failure and tailor the architecture to the threat model, from insider risk to state-backed attackers.

01

Confidential computing

Sensitive workloads on hosts you don't fully trust: remote attestation, enclave boundaries, TEE flows, and end-to-end verification.

  • Enclaves
  • Attestation
  • TEEs
02

Supply-chain security

Reproducible builds, provenance, and signed release workflows so critical artifacts can be verified before they run.

  • Reproducible builds
  • Provenance
  • Multi-sig review
03

Custody & secrets architecture

Bespoke hot, cold, and air-gapped systems for digital assets and secrets: quorum controls, signing workflows, recovery ceremonies, and operational safeguards.

  • Quorum
  • Air-gap
  • Ceremony design
04

Low-level & systems engineering

Linux, firmware, boot chains, and kernel-level hardening where security depends on details most teams rarely touch.

  • Kernel
  • Bootloader
  • Firmware
How we work

Not another rubber stamp audit.

Work directly with security engineers who review, design, and build alongside your team. Practical security work, not a report that leaves the hard decisions to you.

Security assessments

2-8 weeks

We use first-principles threat modeling, system architecture review, code and dependency review, penetration testing, and smart contract reviews to eliminate risks at their source.

Security engineering

1-6 months

Design the system and help build the security-critical parts. Confidential compute platforms, signing ceremonies, hardened build pipelines.

Security retainer

Ongoing

We support your team wherever security judgment is needed: design reviews, release signoff, security program development, candidate interviews, and hands-on support as your infrastructure evolves.

Selected work

Work we can talk about.

Public examples from teams building systems where security failure is not an option.

Open source

Security tools, open to you.

The same tools we rely on to secure high-stakes systems, open-sourced and free for any team that needs them.

Hermetic, deterministic, reproducible, multi-signed OCI-based build toolchain.

AirgapOS

View repo

Minimal, immutable, offline-first swiss-army knife for secret management.

Keyfork

View repo

Derive keys from a single entropy source to simplify their management.

Icepick

View repo

Framework for offline cryptographic signing operations.

Documentation for managing secrets you can't afford to lose.

EnclaveOS

Coming soon
View repo

Immutable OS for powering verifiable confidential compute on untrusted hosts.

Engineers

Who you'll work with.

Decades of low-level security depth, working directly with your team on the decisions that matter.

Get in touch

Bring us your hardest
security problem.

Book a 30-minute call with a security engineer, or send a note about what you're working on. The first conversation is on us.