Data security is a contest. Most programs are not built to fight one.
We do data security research and consulting, and we build the software that comes out of it — a cybernetics practice as much as a security one. Programs that treat security as a checklist build with care, deploy with discipline, audit with rigor — and lose anyway. We help you build one that measures whether it is actually winning.
Three practices, one standard of care
Data security technologies, studied properly
We take things apart to find out how they actually fail — then write it up so someone else can act on it. Findings are published with method and evidence, not marketing.
Assessment, strategy, and governance
Programme design and advisory work. Findings ranked by what an adversary reaches for first, each with an owner, a date, and the cost to fix.
Tooling that removes the manual floor
Manual operation has a speed limit. We build the automation that lifts it — scanners, pipelines, and platforms, in production, in house.
Three ideas that run underneath everything we do
The better-informed side wins
Security is a contest between two parties, and the one holding better information dominates it. That is not a metaphor borrowed from economics — it is a measurable property of a system, and it can be moved deliberately in your favour.
Machines for scale, people for judgement
The useful question is not whether AI replaces analysts. It is which parts of the work are volume problems and which are judgement problems. Give the first to a model and the second stays human — better informed, and no longer buried.
Capability should not need a budget
Automation is what makes serious capability affordable to organisations that were never going to hire a forty-person team. The same holds outside security — the tools we build for a farm or a classroom come from exactly this idea.
These are the threads that connect a DLP scanner to a courseware platform to a recipe app. Not the subject matter — the conviction that a well-built tool moves capability to the person who needs it.
Inside the Adversary's Loop
A 444-page doctrine for building, measuring, and operating modern data security programs. It contributes three things that did not exist before it: ACEE, a composite measure of whether a security service is actually performing; an eight-step constructive pipeline that builds every service the same way; and the integration of both with Boyd's OODA loop and information-asymmetry economics.
It is not for sale — it is how we work, written down.
Applied knowledge, in the shape of something you can use
Polygon Cyber is a cyber security company and a cybernetics company — the study of how a system and the people in it steer each other. So we build tools that extend what a person can do, rather than tools that do it for them. A finding in a report is knowledge nobody can act on; the same knowledge built into software becomes something a person uses on a Tuesday afternoon.
Polygon Glass is in pilot at glass.polygoncyber.ca while Polygon Siphon and BloomKeeper are in beta. The other two are in active development. Two are security tools; three apply the same standard of care to somebody else's domain entirely.
Polygon Siphon
A data-loss-prevention scanner in Rust — 561 patterns, 126 categories, 72 checksum validators, and a normalisation pipeline that undoes the tricks used to slip data past a regex.
Polygon Trace
Incident timeline reconstruction: the sequence of what happened, rebuilt from the evidence that survived.
Polygon Glass
An education platform in pilot — HTML courseware built for university students to work through, not watch.
BloomKeeper
Management software for flower farms: beds, successions, harvest windows, orders.
Mise
A recipe app. No findings table, no severity scale — the same care, a smaller problem.
A small practice, deliberately
Polygon Cyber is a data security research and consulting practice. We take a small number of engagements at a time because the diagnostic work that starts each one does not scale by adding people to it.
Most of what we publish and most of what we build comes out of that work. If something here is useful to you, take it — the ideas are not the product.