Security by design

Precision software. Extreme security. Uncompromised quality.

We build and operate critical platforms where failure is not an option. Full integration with your mission under strict confidentiality.

NDA
Signed before the first technical conversation
ES · EU
Spanish company, EU jurisdiction and GDPR
EN · ES
Working languages
100%
Of delivered code owned by the client

Services

Precision in Every Line. Excellence in Every Mission.

Strategic software engineered for resilience. We embed with your team to deliver end-to-end: architecture, build, testing, deployment and secure operations. The work falls into three practices, and most engagements combine at least two.

Build

End-to-End Development & Precision Architecture

Bespoke systems aligned to your processes and objectives, on stable, scalable and secure platforms. Modular design, explicit contracts and test coverage from the first commit. Threat modeling, layered security, segmentation and first-class observability from the first diagram.

What you get

  • Architecture and threat model, documented and versioned
  • Source code in your repositories, with tests and CI from day one
  • Signed builds, SBOM and a dependency policy
  • Runbooks and handover documentation

Harden

Assessment & Optimization

Technical audits, attack surface reduction, debt elimination and performance tuning without compromising security. We start from what is exposed today and leave it measurably smaller.

What you get

  • Exposure inventory: services, ports, identities and secrets
  • Findings ranked by exploitability and business impact, with fix-by dates
  • Hardening baseline per host and service class
  • Re-test report confirming each fix

Respond

Incident Response & Secure Operations

Playbooks, containment, eradication and recovery, plus the operational discipline that shortens the next incident: on-call, observability and post-mortems that change something.

What you get

  • Incident playbooks and escalation paths
  • Containment and remediation plan
  • Post-mortem with owners and dates for every action
  • On-call model with agreed SLAs, when required
Real Seniority
Engineers with decades in mission-critical environments. Discipline, judgment and verifiable deliveries.
Quality Built-In
CI/CD, automated testing, peer review, SAST/DAST and full traceability. Quality is the baseline, not an extra.
Partnership
We work shoulder-to-shoulder with your team, aligned with your vision and accountable for outcomes.

Core capabilities

Core capabilities

Quiet execution. Measurable results. Security before, during and after deployment. Each capability ends in evidence you keep, not in a slide.

Capability What it covers Evidence you receive Build Harden Respond
Hardening

Hardening & Attack Surface

Inventory, segmentation, service control, OS hardening, encryption in transit and at rest, secret rotation and least privilege. Exposure inventory, hardening baseline, before-and-after attack surface report. Build Harden
DevSecOps

Operational DevSecOps

Pipeline guards: SAST/DAST, signing, SBOM, dependency scanning, merge and deploy policies and verified provenance. Pipeline policy as code, signed artifacts with provenance, an SBOM for every release. Build Harden
Crypto

Applied Cryptography

Key management, PKI, TLS/mTLS, modern ciphers, secret storage and auditable rotation. Key and certificate inventory, rotation policy, internal PKI design. Build Harden
IR

Incident Response

Playbooks, containment, eradication and recovery. Drills and actionable post-mortems. Playbooks, incident timeline, post-mortem with tracked actions. Respond
Observability

Observability & Traceability

Metrics, structured logs, distributed traces and retention aligned with policy. Dashboards and alerts tied to service objectives, log retention policy. Build Respond
Code Review

Secure Code Review

Static and dynamic review, secure patterns, protections against injection, CSRF, unsafe deserialization and more. Review report with reproducible findings and fix guidance; SAST/DAST rules tuned to your code. Build Harden

Methodology

Delivery methodology

Repeatable process, living documentation and strict change control. Every phase ends with an artifact you can inspect before the next one starts.

  1. Phase 01

    Discovery

    Requirements, assets, dependencies and assumptions. We define the “minimum defendable” and risk targets.

    OutputAsset and dependency inventory, risk register, agreed baseline.

  2. Phase 02

    Architecture

    Components, contracts, data flows and cross-cutting security. Diagrams and policies aligned to business goals.

    OutputArchitecture decision records, data-flow diagrams, threat model.

  3. Phase 03

    Secure Implementation

    Checklists, pair reviews and automated tests. No feature ships without controls.

    OutputReviewed code, passing security gates, signed artifacts.

  4. Phase 04

    Validation

    Functional, load and security testing; control verification and dry-runs.

    OutputTest and security reports, verified controls, dry-run results.

  5. Phase 05

    Operations

    Observability, runbooks, incident management and continuous improvement driven by metrics.

    OutputRunbooks, dashboards, incident process, improvement backlog.

Principles

Positions we don’t negotiate

Most security failures we are called in to fix come from a reasonable shortcut taken under deadline pressure. These are the shortcuts we don’t take, on any project.

Transport

mTLS on every internal call

Every service proves its identity to every other service, on every call, with short-lived certificates. “Internal only” is exactly where the trust assumption breaks.

Why mTLS is not optional

Delivery

No feature ships without controls

Security gates run in the same pipeline as the tests. A missing control fails the build, the same way a failing test does.

Ownership

You own the code, the keys and the docs

Everything we build lives in your repositories and accounts from day one. No lock-in and no knowledge that only we hold.

Identity

Short-lived credentials, rotated by machines

Secrets and certificates are issued and rotated automatically. Rotation by hand does not survive contact with more than a handful of services.

Evidence

Evidence over assertions

Every claim we make about your system comes with something you can verify yourself: signed builds, SBOMs, reports and logs.

Scope

We say no early

If something cannot be secured to the standard it needs within the time or budget available, we say so before we start.

Trust

Trust & compliance

We operate under strict confidentiality. We work with established industry frameworks (e.g., OWASP, NIST, ISO/IEC) when requested by the client, and with the European and Spanish regulations that apply to regulated sectors.

  • NDA

    Confidentiality

    Least-necessary access, private repos, access logs and rigorous handling of sensitive data.

  • Evidence

    Technical Evidence

    Signed artifacts, SBOM, security reports and auditable change logs.

  • Governance

    Policies & Controls

    Lifecycle policies, vulnerability management and agreed maintenance windows.

FrameworkHow we use it
OWASP ASVSApplication Security Verification StandardVerification levels for web and API security requirements, and the checklist behind our code reviews.
NIST SSDFSP 800-218Secure development practices across the lifecycle. Our delivery methodology maps onto it.
ISO/IEC 270012022, Annex AControl mapping and technical evidence for your ISMS audits.
ENSSpain, Royal Decree 311/2022Security requirements for systems that serve the Spanish public sector.
NIS2Directive (EU) 2022/2555Risk management and incident handling for essential and important entities.
DORARegulation (EU) 2022/2554ICT risk management and resilience testing for financial entities, insurers included.

We are not a certification body and don’t certify on your behalf. We build the technical controls and produce the evidence your auditors and compliance team need.

Sectors

Sectors we protect

Environments where an outage, a leak or a failed audit has consequences far beyond the IT department.

Defense & Security

Mission-critical environments, secure communications and hardened access control.

Critical Infrastructure

Operational resilience, network segmentation and continuity planning.

FinTech & Insurance

Transaction integrity, antifraud pipelines and sector compliance, including DORA.

Industrial

IT/OT boundaries, secure telemetry and downtime reduction.

Pharma & Life Sciences

Traceability and data integrity in systems that regulators audit line by line.

Aviation

Delivery pipelines and booking systems where availability and integrity are revenue.

Public Administration

Internal systems for process management and inventory, built to public-sector security requirements.

Technology

Large-scale platforms and startups preparing for scale, investment or acquisition.

Cases

Cases (details under NDA)

We never publish client names. These are profiles of work we have delivered: the sector, the market and the kind of problem we were trusted with.

Pharmaceutical

United States

Software for pharmaceutical companies operating in the US market, where traceability and data integrity are audited rather than assumed.

Secure developmentTraceability

Insurance

Global

Engineering work with leading global insurers, on platforms that hold sensitive customer data under close regulatory scrutiny.

ArchitectureData protection

Technology

FAANG & startups

Engineering for FAANG companies, and for startups through to successful acquisitions.

ArchitectureCode review

Aviation

Airlines

Custom DevSecOps pipelines for many companies across the aviation sector, and secure engineering of airline booking processes.

DevSecOpsCI/CD

Public administration

Public sector

Internal software for process management and inventory control.

Secure developmentOperations

About

Why Metadynamics

In a hyperconnected world, security is an ethical responsibility. Software must be efficient, reliable and transparent. We respect data and the people who rely on it.

Built for a world where the dynamics themselves keep changing.

J.A.N., CEO · @NacheDev

Dynamics is what happens when a system is in motion. Meta is what sits above that motion: the forces that decide how the motion itself keeps changing. The name describes the world we build software into, and the posture we think that world now demands.

The rules-based order is openly contested, AI is accelerating change of every order, and most of the baselines we grew up planning around are no longer guaranteed. We don’t claim to predict what comes next. We build systems, and an organization, that stay adaptive when the ground moves.

Read the full essay: Why We Called It Metadynamics

Vision
Build a landscape where trust is the baseline and each line of code strengthens security and progress.
Mission
Deliver precise, secure solutions rooted in a deep understanding of their impact on organizations and users.

FAQ

FAQ

If your question isn’t here, ask us directly.

Do you work under NDAs?

Yes. Every engagement starts with confidentiality and access controls proportional to risk.

Where is the team based?

Senior, distributed team, contracting through a Spanish company under EU jurisdiction. We adapt to time zones and availability requirements as per contract.

Who owns the code?

The client owns the delivered code under the signed agreement. We provide full traceability and clear licenses.

Do you offer 24/7 support?

On-call models available with SLAs and runbooks defined for incidents.

How are engagements structured?

Around what you need. Common shapes are a fixed-scope assessment, a team embedded in your organization, or ongoing operations and on-call. Scope, pricing and reporting are agreed with each client.

Can you share client references?

We don’t publish client names, and we give every client the same discretion. The cases above describe the sectors and kinds of work involved.

Do you work inside our infrastructure?

Yes. We work in your repositories, CI/CD and cloud accounts, under your access policies, with least-necessary privileges and logged access.

Which languages do you work in?

English and Spanish.

How do I send you something sensitive?

Encrypt it with our PGP key (the fingerprint is in the contact section) and send it to [email protected]. Please don’t put credentials or sensitive details in an unencrypted first email.

Contact

Contact

We select clients carefully. If your mission demands security and precision, let’s talk.

What to include in a first email

  • Your organization and your role
  • What you need: build, harden, respond, or not sure yet
  • Timeline and hard constraints: regulation, deadlines, environments
  • No credentials or confidential details. Use PGP for those.

PGP key · [email protected]

C240 53A5 A5F7 200C 4772DDE5 8EBD B4BC C144 98D2