Bullet Proof Software provides secure software engineering to clients across the United States and internationally. Security work is delivered remotely through hardened collaboration channels, with onsite assessment available for environments that require it.
How Remote Delivery Works
Projects run on a clear cadence: a shared plan, milestone demos, and written status you can forward to anyone. All work lives in source control with documented setup, so you own the code and the knowledge – not just the deliverable. Sensitive engagements can run entirely within your infrastructure: your repositories, your tooling, your access controls – we adapt to your security model, not the other way around.
Secure Collaboration
Access is scoped per project: least-privilege credentials, agreed data-handling rules, and communication over the channels your organization approves. We work in your systems where policy requires it.
Time Zones and Communication
We overlap working hours with your team for standups and reviews, and keep decisions in writing so progress never blocks on a meeting. Communication cadence – daily, twice-weekly, or milestone-based – is agreed at kickoff and kept.
Onsite Options
Onsite work is arranged for air-gapped or restricted environments and for security workshops your policies require in person.
International Engagements
International clients are onboarded with clear contracting: jurisdiction, invoicing currency, IP assignment, and data-protection terms agreed up front. Support-hour arrangements are set to your business day.
Tell us where your team works and what the project needs – we will propose a delivery model that fits.
How the Work Is Actually Delivered
This page is about the delivery model rather than territory, so it is worth being clear about what that model is. Most of the work is remote: code, cloud, pipelines and the analysis half of an assessment travel fine over a connection. Where a project needs somebody physically present, it becomes a hybrid engagement, and the on-site visits are scoped, scheduled and priced as part of the statement of work instead of assumed into it. Clients are in the United States and internationally.
We do not publish a coverage map or a list of served regions, because a map implies presence we would then have to invent, and a service page is the wrong place to invent anything. Whether we can take on work where you are comes down to two answerable questions: who has to sign the authorization, and how much of the job needs hands on equipment. Both can be settled in one conversation before anyone writes a proposal.
What Remote Delivery Cannot Cover
Remote work does not cover physical inspection. Verifying that a panel is locked, that a network closet is not also being used for storage, that a door controller is wired the way the drawing claims, or that a segment described as air-gapped actually is, requires somebody standing in the room. Control system walkdowns fall into the same category, since the difference between the documented network and the installed one is frequently visible only on site. Where those questions sit at the center of an engagement, we say so during scoping and arrange the visit.
Where the Data Lives Changes the Setup
Security work generates sensitive material: packet captures, log extracts, credentials, source code, and findings that describe precisely how to compromise you. Deciding where that material is permitted to live is a scoping question with legal weight in some jurisdictions and contractual weight in most. An engagement can be structured to run inside your environment, with analysis performed on infrastructure you control and artifact handling written into the agreement, which changes the tooling and usually the pace of the work. Retention and destruction of evidence after the engagement closes belongs in that same agreement, settled while nobody is under pressure.
Authorization Is a Contract Question First
Any testing engagement needs written authorization from a party entitled to grant it, and that is not always the person sitting across the table. Shared hosting providers, cloud platforms with their own testing policies, landlord-owned building systems, a managed service provider operating the network, or a parent company that formally owns the assets can each need to appear in the paperwork. Cross-border work adds jurisdiction and, for certain tooling and destinations, export considerations that belong with your counsel. Getting the authorization chain right is part of scoping on our penetration testing and security assessment and OT and ICS security assessment engagements, and work does not begin before it is settled.
Working Hours and Response Expectations
Overlapping hours matter for design discussions and anything interactive. Most other work runs asynchronously, with decisions written down so that one question waiting on a calendar does not stall everything behind it. Incident work is a different case and deserves to be explicit: availability, contact paths and escalation exist only where they have been agreed in the engagement terms, and we do not imply coverage that has not been contracted. An out-of-hours arrangement is a specific thing to put in writing before you need it, which is the retainer discussion on our incident response page.
When a Local Firm Is the Better Answer
If the work requires frequent physical presence, if regulation requires a provider established in your country, or if the environment requires personnel cleared under a national scheme, a local provider is the right call and we will tell you so during scoping. Distributed delivery suits engineering and assessment work with defined deliverables and a written trail. It suits an environment needing hands on equipment every week considerably less, and pretending otherwise would waste your budget and our time.