AereA GmbH
Discuss your project

Services

Security & cryptography

Security is not a checkpoint at the end. It is a property of the design — or it is absent.

When we are the right fit — and when we are not

Where we carry weight — and where we do not.

A fit when …

  • Machine or system communication has to be secured end to end.
  • Certificate lifecycle and PKI should be set up properly rather than improvised by script.
  • Identity and access management in a microservice landscape is on the agenda.
  • Cyber security requirements from a regulated setting have to be implemented.

Not a fit when …

  • You need a penetration test as a seal of approval — there are specialist providers for that.
  • This is about classic IT security in the office network, not about software.
  • You are looking for ISO 27001 certification support for your company.
  • Below 10 person-days our ramp-up effort does not pay off for you.

What we actually do

  • Secure communication protocols — design and implementation for machine, plant and system communication, including securing the network border.
  • Encryption and certificates — symmetric and asymmetric methods, PKI, X.509, TLS and TLS client certificates, plus the full certificate lifecycle.
  • Authentication and authorisation — OAuth2, OpenID Connect and Keycloak, including role and permission models and integration with existing identity landscapes.
  • Threat modeling and audits — structured analysis along system boundaries, security audits of existing architectures, hardening of network and application components.
  • Regulated environments — implementation of cyber security requirements, among others for safety-critical updates to a medical laser system.

On certificates

We hold neither ISO 27001 nor TISAX, and neither is currently planned. We consider it more honest to say so and instead document how we work: Security & compliance describes development location, handling of client data, sub-processors, hosting options and how we use AI tooling on client code — in a form usable as a template for supplier questionnaires.

Approach & collaboration models

The most common entry point is a security review of an existing architecture with prioritised measures. After that, either implementation by us or support for your team.

Technologies

  • TLS
  • PKI/X.509
  • OAuth2
  • OpenID Connect
  • Keycloak
  • SRTP
  • ZRTP
  • Threat Modeling
  • Hardening
  • EMQX

Typical project size

What a project costs with us.

Day rate €480–960 depending on the type of engagement

A security review of an existing architecture is deliberately short and the usual entry point.

Frequently asked questions

Are you certified to ISO 27001 or TISAX?

No, and we do not claim to be. We document our processes to ISO 27001 logic and disclose them for supplier questionnaires. If your procurement mandates a certificate, we are the wrong supplier at that point — we prefer to say so upfront.

What does threat modeling mean here in practice?

A structured look along the system boundaries: where information leaves the trust zone, who may do what, which assumption breaks first. The output is a prioritised list of concrete measures, not a risk matrix for filing.

Do you also handle certificate management in operations?

Yes, under maintenance agreements. Issuance, distribution, rotation and revocation are where PKI projects fail in operations — not the initial setup.

Contact

Your contact

Sören Sprenger
Software architecture & technical project management

Wüstenstein 18, 91346 Wiesenttal · Mon–Fri 9:00–18:00 CET