Independent British software company

Some problems come with
a date attached.

The EU Cyber Resilience Act starts its clock on 11 September 2026, and it runs for 24 hours from the moment you become aware. We build the tooling that gets you to the date with evidence, not assurances.

Free, nothing to install, nothing stored. Detection, evidence and drafts. It does not make you compliant.

Article 14 Signal · an OSPulse module

The clock starts the moment you become aware, not when you confirm.

If you place on-prem, desktop or embedded software on the EU market, an actively exploited dependency puts you on a 24-hour reporting deadline. Most teams find out from a customer. Article 14 Signal tells you first, and keeps the record that proves when you knew.

Exploitation in the wild, not just CVEs

Article 14 triggers on active exploitation. The fastest trigger, a hijacked or abandoned upstream package, produces no CVE at the moment it matters, so a CVE-only feed never flags it in time.

The clock starts at awareness

A timestamped record of when each signal arrived is the one fact that determines liability, and the signal is pushed to you, not left waiting for you to log in. A 24-hour clock can start at 3am on a Sunday.

It reaches you out of band

When a package you depend on enters CISA KEV, your administrators are emailed within about an hour: package, advisory, severity, affected repositories. On by default. Lower-severity findings collapse into one daily digest, so the urgent channel stays worth reading.

Honest about the filing

ENISA provides no API, so submission to the Single Reporting Platform is manual. We say so plainly and hand you a pre-drafted payload in the platform's own field order, rather than promising an automation that does not exist.

Start with your own exposure

Paste a dependency manifest and see which of your packages are exploited or abandoned, what that would put you on the hook to report, and what the submission would say. Ninety seconds, free, nothing to install and nothing stored.

Founding cohort · 25 places

£2,988 /year plus VAT

Locked for life. List pricing from £3,600/yr at launch.

Prices exclude VAT; a UK customer at 20% pays £3,585.60 a year.

£0 charged today. Your card is charged once, at launch, and you can cancel any time before then.

Reserve a founding place

Reporting duties under Article 14 apply from 11 September 2026 to products with digital elements placed on the EU market, including those already on it: 24 hours to early warning, 72 hours to notification, 14 days to the final report. The penalty ceiling is €15M or 2.5% of worldwide annual turnover. Article 14 Signal provides detection, evidence and drafts. You remain the one who reports, and this does not make you compliant.

The platform underneath

Article 14 Signal runs on OSPulse.

The regulation is the deadline; this is the machinery that meets it. OSPulse has been watching dependency estates for compromise and abandonment since before the Act had a date, which is precisely why it can tell you the clock has started.

One plan · £2,988/year + VAT

OSPulse

Dependency health and supply-chain compromise intelligence.

Traditional scanners wait for a CVE to exist. By then the package has been abandoned for months, or the maintainer account was taken over last week. OSPulse watches the things that happen before a CVE, and tells you which of your applications are in the blast radius.

Compromise intelligence

Breach feeds across eight-plus sources (advisories, malware reports, threat intelligence, CISA KEV) cross-referenced against your dependency tree. Maintainer takeover, typosquatting, and dependency confusion included.

Drift detection

Commit-velocity collapse, maintainer activity across 90- and 365-day windows, bus-factor risk, release-cadence decay. Abandonment caught while you still have time to move.

Exposure alerting

A new advisory against a version you actually run, or a package entering CISA KEV, emails your administrators within one detection cycle. On by default, deduplicated so hourly re-detection never re-alerts, and routable to Slack, Teams or a webhook.

Health scoring, with the evidence

A 0–100 score across ten weighted dimensions, each one carrying a full evidence trail and a confidence rating that flags where the evidence is thin. Weights are configurable per policy.

How the reporting pack is built

SBOM, exploit watch, evidence trail.

One scan produces the CycloneDX SBOM, the exploitation-intelligence watch across your tree, and submission-ready report packs for products already on the EU market, wired into the CI you already run. This is the engineering behind Article 14 Signal.

How OSPulse builds it

Post-quantum readiness

Do you know where all your RSA is?

Google has committed to completing its own post-quantum migration by 2029; NIST deprecates RSA and ECC in 2030 and disallows them in 2035. The quantum proofing scanner finds every legacy certificate and outdated crypto library across your codebase and dependency tree.

See the scanner

Consultancy, now taking engagements

AI-driven development,
delivered by practitioners.

Most organisations have adopted AI tooling. Far fewer have changed how their teams are organised around it, and that is where the return on investment is won or lost. Fortitude Omnis Group advises engineering leaders on embedding AI into the software lifecycle and restructuring delivery teams to compound the gains.

We are not a reseller and we do not arrive with a slide deck and a licence agreement. Our guidance comes from running these practices daily across our own product portfolio, the same methods that let a small group ship enterprise security, compliance tooling, and consumer software side by side.

AI-driven delivery

Embedding coding agents into the development lifecycle with the guardrails that make them trustworthy: specification discipline, automated review, test strategy, and CI gates. Pilots that survive contact with production, not demos.

Team & operating model

Restructuring teams for an AI-augmented workflow: how roles shift, where review effort moves, what to measure once lines of code stop being a signal, and how to keep senior judgement in the loop as throughput rises.

Governance & assurance

Tooling policy, data and IP boundaries, dependency and supply-chain risk, and an audit trail that satisfies your security function. Informed by the same research behind OSPulse.

How we engage

01

Assess

A short, focused review of your delivery pipeline, team structure, and current AI adoption. You receive a written findings report with prioritised recommendations.

02

Pilot

One team, one real workstream, defined success measures. We work alongside your engineers rather than observing from the outside.

03

Scale

Roll the proven pattern out across the organisation, with the playbooks, training, and governance needed for it to hold once we step away.

Discuss an engagement

An introductory conversation, no obligation. UK-based; available remotely or on site.

Email contact@fortitude-omnis.group or see all contact routes.

Start a conversation

Also from Fortitude Omnis

Everything else we build.

Free tools and consumer apps, built and maintained by the same team, to the same standard.

Free · Open source Strata Point it at a stripped binary and it tells you which open-source libraries are inside, which versions, and what's vulnerable. No source required. Watch it work in the browser. See Strata Free OSA scope checker Seven questions and a clear verdict on whether the UK Online Safety Act applies to your service, every duty linked to its Ofcom or GOV.UK source. Guidance, not legal advice. Check your service Free · NVDA & Narrator verified Accessible Claude Agentic coding rebuilt for developers who are partially sighted, low-vision or legally blind. The agent does the looking and narrates it back. Windows, code-signed. Download for Windows Free · Open source WhatThreeGits Three memorable words for any commit hash, and back again, deterministic, reversible and entirely offline. Say your commit instead of spelling out forty hex characters. Try WhatThreeGits Free · Open source OmnisRouter A drop-in proxy that sends each LLM request to the cheapest model that can handle it, across the Anthropic, OpenAI and Gemini formats, with a receipt explaining every decision. Self-hosted, bring your own keys. See OmnisRouter Free · Open benchmark OmnisBench An open, reproducible benchmark for LLM routing. On fresh problems the models can't have memorised, ideal routing beats the frontier model's quality at about 60% lower cost, and a perturbation probe measures how much each model's score rode on wording it had seen before. Every number re-grades offline. It is the data behind OmnisRouter. Explore OmnisBench Early access · Agent-fleet cost OmnisVigil Agent-fleet cost intelligence built on OmnisRouter receipts. It shows AI coding spend by commit, repo and team, caps the budget, and catches the looping agent that runs up your bill before the invoice does. Team-level, never a per-developer scoreboard. See OmnisVigil Consumer Quizly Trivia that is quick to learn and hard to put down, with a Travel Quiz spanning 197 countries. Played by over a million people. Play Quizly Consumer Forever Yours A DIY wedding planner that carries couples from the proposal to the big day: guest lists, budgets, suppliers, and the hundred small decisions in between. Visit Forever Yours Consumer Forever Paws Photo albums, milestones and the little moments that matter, gently preserved for the people who love them. Visit Forever Paws

In development: Forever Claws (pet care for cats), Home Budget, and Insurance Vault.

See everything we build

How we work

“We don't ask you to take our word for it.
Every verdict ships with its evidence.”

A risk score you cannot interrogate is an opinion. A duty without a citation is a guess. An accessible interface that was never tested with a screen reader is a claim. Whether it is a security team defending a supply chain, an operator working out where the law lands, or a family keeping a pet's memories, we ship the working, not just the answer.

About us

A small team, deliberately pointed at hard problems.

Fortitude Omnis Group is an independent software company based in England, operating three subsidiaries: Fortitude Business, Fortitude Gaming, and Fortitude Home, each focused on a distinct market, each held to the same standard of quality and craft.

We don't chase market trends. We identify problems that matter, increasingly the ones that arrive with a regulatory deadline attached, and build the right tool to solve them. Then we maintain it, improve it, and support the people who depend on it.

Our principles

Quality over quantity

We'd rather build one excellent product than five mediocre ones. Every product we release is built with care and tested thoroughly.

Respect for users

No dark patterns. No manipulative monetisation. No selling data. We build software people can trust, and trust is earned, every day.

Evidence over opinions

Whether it's a quiz question, a risk score, or a policy decision, we ground everything in evidence. We don't invent things we can't prove.

Build it properly

Half-finished is worse than not started. We ship complete products: well-tested, well-documented, observable, and recoverable.