Operating structure
One company. One assurance brand. Multiple laboratories.
TVK Labs & Technologies Ltd. is the legal operator, employer, asset owner and future accreditation applicant. Preflight Audit is its security-assurance, testing and verification brand and department. The laboratory programme below operates within that structure.
Software, Web & API Security
Operational commercialSource, architecture, business-logic, authentication, API and application security testing.
Web3, Smart Contract & Protocol Security
Operational commercialSmart contracts, wallets, L1/L2, rollups, bridges, cross-chain, oracle and protocol security.
Wallet, Custody & Signing Security
Operational commercialMobile, browser and desktop wallets, signing flows, recovery, MPC, multisig, HSM and secure-element integrations.
Formal Verification, Symbolic Execution & Fuzzing
Operational commercialExecutable security properties, invariants, stateful fuzzing, model checking and differential testing.
Applied Cryptography & Protocol Security
Operational commercialCryptographic implementation, key lifecycle, protocols, ZK, MPC, threshold systems and crypto agility.
Automated Cryptographic Algorithm Validation
Validation readinessPreflight ACVP client, IUT adapters, vectors and evidence workflows for ACVTS Demo proficiency and future accredited use.
FIPS 140-3 Cryptographic Module Testing
Validation readinessModule boundary, interfaces, roles/services, SSP lifecycle, self-tests, operational environment and physical-security readiness.
Entropy, Randomness & DRBG
Validation readinessEntropy acquisition, restart data, IID/non-IID analysis, health tests, conditioning and DRBG evidence.
Post-Quantum Cryptography
Operational commercialML-KEM, ML-DSA, SLH-DSA, hybrid migration, interoperability and implementation security.
Hardware Physical Security
Validation readinessTamper controls, enclosures, coatings, debug interfaces, secure storage and hardware roots of trust.
Side-Channel & Fault Analysis
Validation readinessTiming, power, EM leakage, clock/voltage fault injection and controlled EM fault-injection research/testing.
TEE, HSM, TPM & Secure Elements
Operational commercialTrusted execution, attestation, secure boot, HSM, TPM, secure element and hardware-wallet security.
Embedded, Firmware & IoT Security
Operational commercialFirmware, secure updates, debug interfaces, radio/network protocols, lifecycle and connected-product security.
Mobile & Device Security
Operational commercialAndroid/iOS application, platform-keystore, entitlement, deep-link and device security testing.
AI, ML & Agentic Security
Operational commercialPrompt and RAG attacks, tool permissions, autonomous action, model supply chain and agent isolation.
Cloud, Infrastructure & Software Supply Chain
Operational commercialCloud/IAM, containers, Kubernetes, IaC, CI/CD, SBOM, provenance, secrets and deployment security.
Digital Identity, PIV, FIDO & Authentication
Validation readinessPIV, passkeys, WebAuthn/FIDO, credential lifecycle, attestation, biometric and document-authentication readiness.
Payment Security
Validation readinessPCI/EMV-related readiness, payment devices, software-based payment, HSM and mobile payment security.
Product Security & Common Criteria Readiness
Validation readinessProduct evaluation, vulnerability analysis, Common Criteria, SESIP and PSA-related readiness pathways.
OT/ICS & Cyber-Resilience
Validation readinessIsolated industrial-system research, product resilience and future recognised cyber-resilience testing pathways.
Build sequence
Capability before claims
01
Commercial security firm
02
Repeatable methodology
03
ISO/IEC 17025-oriented QMS
04
Cryptographic validation capability
05
Hardware and side-channel capability
06
Formal accreditation for approved scopes
Need a security assessment or validation-readiness engagement?
Commercial security testing can be scoped now. Services that depend on an external laboratory accreditation or scheme recognition are clearly identified as readiness or accreditation targets until the relevant approval is formally held.
