Skip to content
About

One team on both sides of the problem.

Caldmere Technologies is the risk, engineering, and offensive security arm of Caldmere Holdings. We assess systems, build them, and attack them — and we are deliberate about which of that we discuss in public.

Security work goes wrong in a predictable way: one firm writes the assessment, another argues with it, and a third eventually builds something. By the time anything is fixed, the estate has moved and the findings are stale.

We built Caldmere Technologies to close that loop inside one team. The engineers who develop your platform are the operators who try to break it, and the intelligence work that decides where to aim comes from the same people who will be on the keyboard. Nothing is handed across a gap between vendors, because there is no gap.

As part of Caldmere Holdings, we work with organizations that carry real consequence if they are wrong — and we take applications from engineers and operators who want to do this work properly.

Principles

Four things we hold to.

P1

Adversary first

We plan backward from what an attacker wants, not forward from a control framework. Frameworks tell you what you are supposed to have. Adversaries tell you what actually matters.

P2

Evidence over assertion

Every finding in a Caldmere report is reproducible from the steps written in it. If we cannot demonstrate it, it does not ship as a finding — it ships as an observation, labeled as one.

P3

Built in the United States

Engineering and operations are US-based, with no offshore development and no subcontracted delivery. Provenance is never a question you have to chase.

P4

Quiet professionals

We do not name clients, publish engagement detail, or put your logo in a pitch deck. The discretion you are buying is the discretion every one of our clients is buying.

Work with us

Work with us, or join us.

Clients and partners can reach us directly. Engineers and operators can apply; we read every application ourselves.