Company
Team
Cybersecurity is to a large extent a craft, too. It can be supported, accelerated and in part automated — but in the end somebody sits in front of a screen and decides whether an anomaly is an incident. Who does that, and how we work, is what this page is about.
The founding
Management
The most common sentence after a security project is: “Thank you, very insightful.” The second most common arrives eighteen months later and goes: “We never quite got round to it.” In between sits a report that was right the whole time, and an attacker who does not care.
That pattern is what neonotu grew out of, in Munich in 2016 — not from a resolve to write better reports, but from a more uncomfortable question: why are we writing down things a machine could do? A finding that ends as a sentence costs the customer twice: once for the analysis, and once for the implementation that then stalls anyway.
Since then the company has run on two tracks, which is unusual in this industry: we work inside the customer's network — in testing, in forensics, in an emergency — and out of what recurs there we build our own tools. Whatever holds us up at the screen at night is on the development list the next morning. The ambition behind it is immodest and fits in one sentence: whatever we have done by hand twice, a tool should do the third time.
The approach
How we work
- 01
We say in advance what cannot be done. We do not make promises that depend on the device generation or the licence tier without checking first.
- 02
We measure instead of assuming. A finding without evidence goes into the report as a presumption — labelled as one.
- 03
We advise against it when it does not pay off. Roughly every third initial conversation ends with a smaller recommendation than the customer expected.
- 04
We hand over. A state only we can maintain is not a result but a dependency.
- 05
The human decides. Tools remove noise; assessing an incident and deciding on a countermeasure stay with analysts.
Whoever only operates tools finds only what the tool knows.
The team
Spread across two continents
Our people sit in Europe and in South America. That is not a cost calculation: hiring beyond your own market gets you people you would never otherwise have met — and perspectives your own building does not hold.
What that does not replace is being reachable in an emergency. That is organised, not improvised: who reports, who takes over, who escalates — all of it settled before the phone rings. An incident at two in the morning does not ask where anyone lives.
Headquarters are in Munich, with further locations in Tarifa and Tallinn. More about the company and our product approach is under About.
Joining us
Who we are looking for
We are not looking for people who can operate tools — that can be learned. We are looking for people who carry on when the tool stops finding anything, and who write a finding down even when it is inconvenient.
Open positions are under Careers. If nothing fits, a speculative application is expressly welcome — half of our hires came about that way.
Contact
Reputation takes years. Destruction takes seconds.
Talk to us before somebody else does. The first conversation is free and we reply the same business day.