Secure development · applied research

Security is not a layer on top. It is a property of the architecture.

cybbrio is a small lab focused on cybersecurity and AI. We design secure applications and infrastructure, test and audit them, and introduce secure development wherever security is a priority - in banks, at technology vendors, in AI environments and in software companies with their own specific rules.

Four areas we specialise in

01 - 04

01

Security architecture review

Threat modeling, trust boundaries, identity, cryptography. We review the design before it becomes production - and you leave with a list of concrete changes, not a risk spreadsheet.

02

Secure development and DevSecOps

Security across the whole development lifecycle: SAST, DAST and SCA implementation, dependency and licence checks, secret management, vulnerability management and CI gates. Tuned so the team is not drowning in false positives.

03

IoT and smart building security

Network, embedded devices and the physical world in one. We analyse integration platforms, device communication and system behaviour at the edge - including anomaly detection locally, without the cloud.

04

AI and shadow AI security

Unsanctioned use of AI tools inside the company as well as AI security in your product: prompt injection, data leaking into models, and rules people can actually follow. We also secure AI agents in corporate environments - so they do not slow developers down.

+ web application penetration testing · risk analysis · threat modeling · oversight of outsourced development

For software companies

We understand teams that build software themselves

A software company does not need an audit that makes work impossible afterwards. It needs controls that pass code review, find and mitigate vulnerabilities fast, fit into the pipeline and do not stop a release. That is most of our work - security written in the language of developers, not compliance spreadsheets.

Security that does not block releases

CI gates tuned to catch what matters instead of blocking every merge.

AI agents in the development environment

Agents and assistants have access to code, secrets and infrastructure. We set their boundaries and oversight so they do not get in developers' way.

Local inference instead of the cloud

We work on running AI agents and models securely on premises - inference at your side, so code, secrets and client data never leave your infrastructure. Our automated security review builds on the same foundation.

Training for developers

Specialised security training written for developers, not for management - including safe use of AI tools and agents in development. On your code and your cases.

Your environment, not a template

Monorepo, in-house framework, legacy core or an embedded target - we work with what you have, not with the ideal case from a methodology.

Examples of what we solve

problem → our answer

Developers use AI tools and nobody knows what data goes in.

We map the real use of AI in the company, set rules for data and give agents boundaries and oversight - so nobody has a reason to work around them.

Dependencies have not been updated for years and everyone fears the upgrade.

A dependency inventory and SBOM, a step-by-step update plan and a CI gate that only guards what matters. No single jump across three major versions.

Anyone can slip a package into the build.

Supply chain security: version pinning, signing and verification of artefacts, isolated builds and a review of permissions in CI and registries.

Development runs on machines with SSH into production.

We separate environments and identities, introduce time-bound access through a bastion or just-in-time, and a traceable audit trail. Developers reach production when they have a reason to.

Secrets live in the repository and in .env files.

We introduce secret management, rotation and scanning of the repository history. The leak is then solved once, systematically, not again at every incident.

Security is dealt with a week before release.

Threat modeling over the design and security criteria in the definition of done. A fix in the design costs a fraction of a hotfix after a penetration test.

Nobody knows exactly what is exposed to the internet.

We map the surface: subdomains, forgotten test instances, unrestricted admin panels and APIs without authentication. Most incidents start with something forgotten.

There is no DevSecOps, security is a one-off exercise.

We build DevSecOps from the ground up: SAST and DAST in the pipeline, SCA over dependencies and licences, container and IaC scanning, secret detection in the repository and gates with sensible thresholds. Set up so the team can run it without us.

Security maturity levels are not defined.

We set the target security maturity according to what the company actually needs - one level for an internal tool, another for a product in a regulated environment - plus measurable steps to get there.

There is no threat catalogue or risk analysis.

We build a threat catalogue for your systems and a risk analysis that can actually support decisions - not a document filed away for the auditor.

Adopting AI without letting data leave the company.

We design and build local AI solutions on your own inference - models and agents run on your side and data stays inside. We use the same setup for automated security review of code.

What working with us looks like

pick a process and a step

Web application penetration test · step 01 / 05 · 1-3 days

Scope and rules

We agree the goals, boundaries, environment and communication channels. We define what is in scope, what must not be touched and what happens if we find something critical in the middle of the night.

Deliverable
Test plan and rules of engagement

Experience and track record

Security engagements cannot be displayed with the client's name. We list the type of environment and the role the founder held or holds there. Specific names on request and by agreement.

Research

We keep part of our capacity for applied research

We collaborate with academia - among others with the Faculty of Information Technology and the Faculty of Electrical Engineering at Brno University of Technology - on machine learning, AI agents, security models and smart living. This is not marketing: it is how we know how new technology behaves before a client deploys it.

Who is behind it

A small team with a long track record

Mgr. Vojtěch Zavřel

founder · security architect

More than 25 years in the field - from similarity search research at Masaryk University through enterprise frameworks to the architecture of banking and military systems. Security has been his long-term focus: designing security architectures, leading threat modeling and vulnerability management in banking, testing web applications and introducing secure development into teams that build software. An architect who also reads code.

Ing. David Podzimek, DiS.

senior security engineer · AI platform architect

Builds systems from hardware and edge up to high-throughput cloud platforms with an AI/ML layer. Experience from specialised solutions for the military, security forces and e-commerce - environments where security and reliability are a precondition for deployment. Here he leads the design of AI platforms, agent systems and local inference.

Egor Koriakov

security project manager · security engineer

More than 15 years in an R&D company working on communication protection - from engineer of communication security systems to project manager. He led the delivery of high-precision complexes for monitoring communication channels (GSM, SHF, UHF) and contributed to an optical channel encryptor for satellite links. He then built his own cryptographically strong hardware-software solution for protecting classified communication.

Mgr. Jiří Mikulášek

architect · DevSec

Architect of highly available cloud services - years on a platform for universal data processing and analytics, and since 2023 on an AI agent built on top of it. Alongside that, integration and automation of smart home systems. He treats security as part of design and operations, not as a review at the end, and approaches new technology with an open mind.

Ing. et Mgr. Lukáš Matěna

IoT security specialist · system designer

Specialist in the security of IoT systems and smart buildings. He designs and delivers large installations, so he knows their weak points from practice: device protocols, integration platforms, remote access and what actually fails in operation.

More people on the team

network security · penetration testing · compliance

Besides the people above, the team includes further experienced colleagues working on network and infrastructure security, penetration testing, forensics and compliance (NIS2, ISO 27001, DORA). For each assignment we put together the team the problem requires - responsibility for the result always stays with us.

Thinking about the security of a system that does not exist yet? That is the cheapest moment.

Tell us what you are building. We reply within two business days and say straight away whether it is a fit for us - or who to ask instead.