About
A team that came from offensive security and works on product security, while preparing, in parallel, to become a manufacturer subject to the same regulation it advises on.
Where we come from
Folhas Etéreas was born on the offensive side of security: years of pentesting and red teaming, with OffSec certifications as the trade's yardstick. That origin fixed the criterion that guides everything else: a recommendation is worth the attack it prevents, not the requirement it ticks off a list.
Today the team is multidisciplinary: offensive security, software and firmware engineering, regulation. The angle stays the same throughout, real risk, with a concrete attack path behind it. The market already has paper audits in abundance.
The work has run through critical telecommunications infrastructure, through banking and fintech under DORA, and through product security in the automotive sector, under UNECE R155/R156 and ISO/SAE 21434. It was the first sector obliged to treat security as a property of the product across its life cycle, which makes it the best preview of what the CRA will ask of everyone else.
The product
Alongside the consultancy, Aeromate is in development: our own IoT product for drying and maturation in the agri-food sector, expected to reach the market between 2027 and 2028. It is at the prototype stage, with a field trial in Coruche.
When it is placed on the market, that product will be subject to the CRA. That forces us to walk the same path we advise on, and it is what gives rise to the logbook: a public record of the preparation decisions, with a level of detail no client case study could ever have.
The hardware is the vehicle and the case study. What we sell is the path to conformity and to secure operation, on our product and on our clients'.
Independence
In the consultancy work, the technical recommendation carries no margin on the other side: we take no commissions from tool vendors and we do not resell the platforms we assess. We have a product of our own, Aeromate, and we hold it to the same rule: it is declared openly, it serves as the public case study in the logbook, and it is never recommended as a solution to a consulting client.
Scopes of work, findings, vulnerabilities and client architectures are never published. When a problem needs illustrating, the example is abstract or built from scratch, and identified as such.