FOR PUBLIC SECTOR AND DEFENSE PROGRAMS

Sovereign security testing, inside your own perimeter

FuzzForge brings sovereign security testing to the third-party code you have to approve but did not write. A French platform that deploys on-prem in your own environment, with an air-gapped option.

Shield icon for sovereign security testing on defense programs
Shield icon for sovereign security testing on defense programs

WHAT MAKES SOVEREIGN SECURITY TESTING HARD

And how FuzzForge runs inside your perimeter

01

You answer for code you did not write.

→Test the code you approve, without its source.

FuzzForge writes the fuzzing harness itself, then fuzzes, emulates and reverses the binary.

02

Nothing can leave your environment.

→Runs in your perimeter, air-gapped if needed.

Deployed on your own Kubernetes cluster, one isolated instance per program.

03

A black box will not get approved.

→Standard tools, reproducible findings.

Your researchers keep their own tools. Every campaign can be replayed and reviewed.

SOVEREIGNTY

Sovereignty is an engineering property, not a contractual promise

Four things decide it, and they are all verifiable before you sign.

A French company, with its teams in France.

FuzzForge is edited in France, by the people who build it there.

The knowledge you build stays yours.

The graph of what has been tested on your systems is built inside your own instance, and it does not leave it.

Models are interchangeable.

You choose where inference runs. A European chain is available, and open-weight models can be self-hosted for an air-gapped install.

Standard tools, so you can leave.

The platform drives the same industry tools your teams already use, so your corpus and your findings stay usable without it.

PROOF

Our Stats Speak For Us

Selected for the Cyber Defense Factory (DGA).
PWN2OWN
3 Pwn2Own wins.
1,500+ vulnerabilities found.
20+ CVEs published.

PROCUREMENT

How sovereign security testing is contracted on a public program

01
You contract through your channel.

FuzzForge is sold through your integrator or prime contractor, on standard public sector procurement.

02
One unit: an annual licence per instance.

The licence covers an instance, with tiers based on the number of targets. No per-seat billing, and no billing per test.

03
On-prem, with an air-gapped tier.

The air-gapped tier is priced above the standard on-prem licence.

04
Support is included, and can be extended.

A support level comes with the licence, and two higher levels are available.

FAQ

Questions from program offices and procurement teams

No, in an air-gapped configuration. FuzzForge deploys on-prem inside your perimeter, and in that configuration inference runs on local models with no external routing. In a connected deployment, you choose where inference runs.

FuzzingLabs, a French company. The platform is edited in France, by the people who build it there. Sovereign security testing starts with knowing who holds the code.

Through your integrator or prime contractor, on standard public sector procurement. The unit is an annual licence per instance, with tiers based on the number of targets.

Yes. Sovereign security testing is only worth anything if you can replay it. The platform drives the same industry tools your researchers already use, and every finding comes with reproducible proof of exploitability.

No. The air-gapped tier is priced above the standard on-prem licence.

Bring FuzzForge inside your own perimeter

A real campaign, on a target close to yours. Findings your engineers can pick up and verify.

MEET US

Meet our researchers at these upcoming events

3 – 6 November 2026
Paris Nord Villepinte

Book a meeting

16 – 19 November 2026
Rennes

Book a meeting

19 – 20 November 2026
Amsterdam

Book a meeting

9 – 10 December 2026
London

Book a meeting