Closed Systems & Reverse Engineering
Undocumented protocols, binary formats, legacy with no sources.
You own hardware or software that works, but nobody has the documentation, the vendor is gone or unwilling, and replacing it is not an option. I recover how it actually works, write the specification that never existed, and prove the result by execution rather than by assertion.
Starting point
Send what you have. Within a couple of days you get a written verdict on what can realistically be recovered — before either of us commits to a build.
Who it is for
- Technical leads who own a system nobody can document any more
- Owners of installed equipment whose vendor withdrew, raised prices or refuses to open a protocol
- Integrators who inherited an undocumented interface inside someone else's project
You need this when
- A vendor left, raised its price or refuses to open a protocol — and the equipment is already paid for
- Your system has to talk to someone else's, and that one speaks an undocumented format
- A working binary exists, the sources do not, and the behaviour has to be carried forward
- Your own data is locked inside a closed file format
- A previous contractor said it was impossible, or took the money and never delivered
What is included, end to end
- Intake of whatever artefacts exist: binaries, firmware, traffic captures, sample files, a live unit, fragments of documentation
- Feasibility assessment with a written verdict — what can realistically be recovered, what cannot, and what it costs
- Contract and NDA, with the result assigned to you
- Analysis: frame structure, byte order, timings, command tables, edge cases
- Specification of the recovered protocol or format — the document you never had
- A compatibility harness that verifies the result against the real counterpart, automatically
- Implementation: parser, library, gateway service or restored module
- Verification against your real hardware or real data
- Handover: sources, specification, harness, run instructions
- Optional support for when the other side changes
What you get
- A written specification of the protocol or format, handable to any future developer
- Working code: parser, library or gateway
- A harness you can re-run after every update to the other system
- An honest statement of what could not be recovered, and why
Evidence
Work actually shipped. Client names and domain details are under NDA; the engineering is described without them.
Recovered a vendor's undocumented synchronisation protocol from tablet sources, and built a harness that compiles the vendor's real serialiser into a JAR with kotlinc — no Android SDK — then verifies outgoing packets through it. 28 written analyses backing it.
That harness caught a defect nothing else would: one label carried lat/lon while map signs carried latitude/longitude, the third-party app dereferenced non-null, threw, swallowed its own exception — and silently discarded the entire situation update, lines and zones included.
Caught a relay substituting a literal sender identity, which collapsed five distinct units into one record with another unit's position and battery state.
Wrote a native parser for a closed binary vector-map format, replacing a 176 MB vendored library, and removed a Qt dependency from the service around it.
Produced the conclusion the client had never calculated: 200 KB of payload equals 55 frames at 250 ms — fourteen seconds of continuously held transmit.
How it works commercially
Two steps. A fixed price for the feasibility assessment, then a fixed price for analysis and implementation — quoted once it is known what is actually inside. Priced against the cost of the alternative: rewriting the system, buying a closed integration, or standing still.
Not included
- Breaking protection, circumventing licensing or DRM, removing hardware locks
- Work on systems you do not lawfully control