Security is not a feature.
It's the foundation.
MilesGuard finds vulnerabilities and stays on until they're fixed. Offensive security and compliance for Swiss SMEs, from St. Gallen.
Why MilesGuard
First-Hand Security
MilesGuard was founded in 2024 in St. Gallen, with a simple conviction: whoever finds vulnerabilities should also know how to fix them. That's why the same team finds, fixes and verifies, so nothing ends up as a report in a drawer.
The result: a security boutique that combines offensive and defensive security. The same engineers who attack your systems subsequently build the defence on request. No overhead, no handover losses.
The impetus came from embedded development: systems running in production without anyone having seriously tested their security. That's why MilesGuard relies on open-source tools and lean processes, so that SMEs with limited budgets also receive professional security, not just enterprises with their own security department.
St. Gallen
Headquarters, Switzerland
OWASP · NIST · PTES
Methodology
CH/EU Infrastructure
Hosting
Offensive + Defensive
One team, no handoff
Who's Behind MilesGuard
Core Team and Network
MilesGuard combines a core team with a network of experienced specialists. Depending on project requirements, we bring in targeted expertise from cloud security, forensics or red teaming.
Miles Strässle
Founder & Security Engineer
Offensive security, security research, embedded background. Lecturer in Linux and Cybersecurity (HF). ETH Zurich · OST.
Tim Renggli
Software Engineer & Business Solutions
Combines analytical thinking with solid engineering. Develops well-founded solutions where theory and practice come together.
Specialised Network
Cloud Security · Digital Forensics · Red Teaming
For projects that go beyond our core team, we work with vetted specialists from cloud security, digital forensics and red teaming. All external experts work under our methodology. Project and quality responsibility stays with MilesGuard, and so does your point of contact.
Principles
How We Work
Four rules that shape every engagement.
Prove or Discard
Every finding comes with a working proof-of-exploit. If it's in the report, we can reproduce it.
From Finding to Fix
We don't deliver problems without solutions. Every finding comes with actionable remediation guidance, architecture recommendations or configuration fixes.
Swiss Infrastructure
Client data stays in Switzerland. Our SIEM runs on Swiss servers. Our compliance starts with Swiss law.
Build to Hand Over
Our goal is to enable your team to operate without us. We document everything, train your people and create playbooks.
References
Selected Projects
All projects are anonymised for confidentiality reasons.
Industrial manufacturer
>1,000 employees, 6 locations (CH/EU)
Active Directory security assessment and NIS2 gap analysis
Domain takeover demonstrated within 2–4 hours, prioritised action plan delivered to management.
Insurance / Financial Services
Large enterprise
Forensic investigation of an insider threat scenario
Access chain fully reconstructed, evidence forensically preserved and documented for legal use.
IT / Cloud Services
SME, 15 to around 200 employees
External penetration tests of cloud infrastructure
Critical perimeter security vulnerabilities identified, retest completed after remediation.
Reference contacts available on request. Most of our clients are bound by confidentiality agreements.
Partners
Who We Work With
Selected partners who help us protect clients.
What Sets Us Apart
Transparency
Clear cost overview. Binding timelines. Honest severity ratings. You see exactly what we find and what remediation costs.
Depth Over Breadth
Five services. No 20-service catalogue. If you need something outside our scope, we'll tell you openly.
No Vendor Lock-in
We rely on open-source tools and open standards. Your data, your reports, your infrastructure. You can switch at any time.
