Moen Tactical · Custom software development
Software that survives its own red team.
Moen Tactical builds custom software for businesses. A plan is written, attacked by agents briefed to break it, rewritten, and attacked again — then you approve it before anything is built. What gets built is verified and attacked the same way, round after round, until a round comes back clean.
Documentation fixes from this pipeline are merged upstream in util-linux — the record is below.
Custom software for businesses
-
Web applications your business runs its day on
Scheduling, dispatch, quoting: the operational core, built to your process instead of the other way around.
-
Internal tools that replace the spreadsheet nobody trusts
With an audit trail, access control, and numbers that reconcile.
-
Integrations that make two systems act like one
Inventory to invoicing, field data to the office, without the nightly copy-paste.
-
Automation with a human gate
The machine drafts, a person approves, and nothing irreversible happens on its own.
Every engagement starts the same way: a short note about the problem, a conversation to scope it, then a written plan — researched and attacked before you ever see it — and nothing is built until you read that plan and approve it. What you receive at the end is working software plus the complete written record of how it was made: the plan, every red-team finding, and how each one was resolved.
How the work actually runs
-
01
The plan
Before anything is built, agents research the problem and write the plan: what gets built, how, and what could go wrong. It is a document you can read — not a conversation somebody remembers.
-
02
The plan is attacked
A separate set of agents is briefed to break it, and every finding has to name a concrete way the thing fails. The plan is rewritten around what they find, then handed to a fresh red team that never saw the first round.
-
03
You open the gate
Nothing is built until you read the final plan and say the word go. The gate never opens on its own. An answer with conditions attached is feedback, not a go.
-
04
Built, verified, attacked
Agents build it. Different agents verify it against a checklist written before they were allowed to see the build. A third set attacks it — briefed from the plan, never shown the build — so they hunt for what should be wrong instead of confirming what is there. Everything they find goes back to the builder, and it goes around again.
There is no round limit and no schedule. It ends when a round comes back clean — or when a person decides the loop itself has become the risk. Once, on an unusually hard security project, that took fourteen consecutive rounds, and it was the owner who called the stop.
An agent claiming success is not evidence of success.
Verifiable, by strangers
Both stories are the same project.
During a security project, the pipeline’s agents had to read the source code of util-linux — software that ships with essentially every Linux system — and found that its official documentation described behavior the code doesn’t have. The practice filed three corrections upstream. The maintainer accepted all three exactly as written, on first submission. They are documentation fixes, not features — and every one is public.
Start a conversation
Engagements are taken by arrangement, so each gets the full pipeline. If you have a system that needs building — or one that needs rescuing — write:
Describe what the software must do and what it costs you when software is built badly. You’ll get a straight answer about whether this practice is the right fit.
No pitch on first contact.
The practice
Moen Tactical is Trevor Moen’s practice.
Every project leaves a complete written record — the plan, every red-team finding and how it was resolved, the verification checklist. You own the code and the record. Nothing lives only in anyone’s head.