Custom Reverse Engineering
& Automotive Development
Deep-level firmware research, hardware design and bespoke software engineering for clients who need work that no off-the-shelf tool can deliver. Built at Envyous Customs in Australia, trusted by serious projects worldwide.
Capabilities built over years of hands-on work
Every supported vehicle on our store represents months of low-level research. We bring that same depth to private engagements across any make, model or platform.
ECU Binary Reverse Engineering
Static and dynamic analysis of factory ECU firmware. Identification of calibration tables, control logic, memory layouts, bootloaders and proprietary structures across multiple architectures.
Security Unlock Algorithms
Recovery and reconstruction of seed-key algorithms, manufacturer-specific access levels, signature validation routines and protected memory regions across UDS, KWP2000 and proprietary stacks.
UDS & Dispatch Routine Mapping
Full identification and documentation of diagnostic services, routine control identifiers, dispatch tables and undocumented OEM commands — the foundation for any custom scantool or service workflow.
Custom OS & Firmware Patches
Binary patching of factory operating systems — from small calibration overrides through to substantial functional changes, custom diagnostic services and entirely new control routines compiled into existing firmware.
Software & PCB Development
Full turn-key hardware products — PCB design, manufacturing, embedded firmware and the supporting Windows software delivered as one finished solution. Custom CAN converter boxes, scantools, programming interfaces and bespoke diagnostic hardware, ready to use out of the box.
Fault Injection & Glitching
Practical experience with voltage and clock glitching techniques to bypass read-protection, recover locked firmware and characterise security boundaries on locked-down microcontrollers and SoCs.
Built for the work that has no playbook.
We don’t take on volume work. We take on the projects where the answer doesn’t exist yet — where it has to be discovered, designed, and built. That’s the work we’ve spent years getting good at.
Confidentiality on your terms.
Every engagement starts with a clear conversation about how the work can be used and whether anyone else may ever access it. You choose the model that fits your commercial situation — we document it in writing, and we honour it without exception.
You choose the model
At quote time you pick Exclusive (sold once, to you only) or Non-Exclusive (discounted, may be sold on to others). The choice is yours, agreed in writing, and honoured throughout.
NDAs welcomed
We are happy to sign your non-disclosure agreement before any sensitive material is shared, or to provide one of our own if you would prefer.
Secure handling
Binaries, dumps and supplied materials are stored on isolated, access-controlled systems and treated as strictly confidential throughout the engagement and beyond.
A clear path from idea to delivery
Discovery
A confidential conversation about your objective, target platform, timeline and constraints. NDAs welcomed and signed.
Scoping & Quote
A written breakdown of approach, deliverables, risks and pricing — with clear fixed-price or hourly options chosen to suit the work.
Execution
Iterative progress with regular checkpoints. You stay informed at the level of detail that suits you — from weekly summaries through to deep technical reviews.
Delivery & Support
Final artefacts, documentation and a handover that lets your team build on what we’ve delivered. Ongoing support available where wanted.
Two ways to engage
Some work has a defined shape — some doesn’t. We choose the pricing model that fits the job, never the other way around.
Fixed-Price Project
For well-defined deliverables where scope and outcome can be agreed up front. You get certainty on cost and timeline.
Best suited to:
- Targeted feature additions to known firmware
- PCB design with a defined functional spec
- Specific algorithm extraction or analysis
- Tooling development with a documented scope
Hourly Engagement
For exploratory or open-ended work where the path can’t be fully predicted in advance. You pay only for what’s done.
Best suited to:
- Deep reverse engineering of unknown platforms
- Glitching & security research engagements
- R&D where outcomes inform next steps
- Ongoing advisory and technical consulting
Every quote includes a written scope, the chosen pricing model and the rationale for it — so you always know what you’re agreeing to before work begins.
Questions we hear often
A few of the enquiries we field most often — have a read first, then send through anything we haven’t already covered.
How much does it cost to recover an algorithm or checksum?
It depends entirely on the platform. Without specific details we can’t provide an exact quote — factors such as whether you can supply the module binary, whether the algorithm is rolling or static, and the level of protection on the target all play a significant role in the time required. Send us the platform details and we’ll come back with a meaningful estimate.
Can you build a custom PCB or CAN box to control specific inputs and outputs?
Yes — custom CAN boxes are a core part of what we do. To scope and quote a build accurately we typically need either CAN bus logs captured from the vehicle, or the relevant parts shipped to us so we can analyse the signals directly. Once we understand the target system, we design a turn-key unit tailored exactly to what you need.
When ordering a custom PCB or CAN box, do I receive the schematics and source code?
No. Our PCB and CAN box work is delivered exclusively as a complete turn-key product — you receive a finished unit ready to plug in and use. Schematics, board files and firmware source code are not part of the deliverable.
Who owns the reverse engineering work, PCB, firmware and software produced?
Envyous Customs retains ownership of the intellectual property we create — the reverse engineering findings, firmware, PCB designs and any custom software. What you purchase is the finished product itself, together with the information you need to use it effectively. This is the standard commercial model for premium engineering work: clients receive a complete, working solution rather than the underlying design assets. Whether the same work is ever made available to anyone else is determined by the exclusivity model you choose at quote time — see the next question for the detail.
What happens if another client later wants the same algorithm or work you have already done for me?
This is decided at the very start of every engagement. During discovery and quoting we present two clear options and you choose the one that suits your commercial situation:
1. Exclusive
The work is sold once, to you alone. We do not offer it to any other client. If a future enquiry comes in for the same algorithm we contact you first — you can decline outright, or agree to allow the sale on terms that include a commission paid back to you. Best suited where the algorithm itself is the core commercial value of your project.
2. Non-Exclusive
You receive the same work at a meaningfully discounted rate and we retain the right to sell it on to other clients in future. Best suited where the algorithm is only one piece of a larger build and exclusivity carries no commercial benefit to you.
Whichever model you choose is documented in writing as part of the engagement and is honoured without exception. Under Exclusive, you are always contacted before any subsequent sale could occur. The decision to approve or decline the sale rests with you; the commission terms are set by us and presented as part of the offer.
What does the Exclusive option actually cover — including hardware and similar work for other vehicles?
Exclusivity protects the specific capability we develop for your exact vehicle, module and operating system combination — the firmware, algorithm research and integration logic that makes your build work on your particular target platform. It does not reserve the underlying hardware, generic functional patterns, or information that is already publicly available.
As a worked example: if you commission Exclusive work to decode a specific CAN message and trigger a relay on a particular Holden ECU, that exact implementation on that exact platform is reserved to you. A later request from another customer for similar behaviour on a Ford or BMW module is a separate piece of work and is not blocked by your exclusivity — different vehicle, different module, fresh research. Likewise, generic CAN-controlled actions built on publicly documented frame definitions are not exclusive material in the first place.
Many of our CAN box, programming interface and scantool products are built on refined base PCB designs that we have developed over years and that are reused across many different customer projects. What makes your build distinctly yours is the firmware and configuration we develop on top of that hardware, not the board layout beneath it.
If your project specifically requires a hardware platform designed from scratch rather than based on any of our existing ones, that is also possible — flag it during discovery and we will scope and quote it accordingly.
Can you build standalone ECU or module flashing hardware?
Yes — purpose-built flashing tools are well within our scope. There are a couple of commercial details worth being clear about up front.
As with all of our hardware, the deliverable is a complete, ready-to-use unit only. Schematics, board files and firmware source code are not provided; the finished tool is purchased directly from us.
To make dedicated flashing hardware economically viable for both parties, a minimum annual order quantity is agreed with you during scoping. Up-front engineering investment in tools of this kind is substantial, and the MOQ ensures both your unit cost and our development time are properly amortised across the production run.
On the user interface side, both approaches are available: control via a companion phone app, or a standalone unit with an integrated screen. Either can be quoted — let us know which suits your workflow during discovery, or we can help you decide between them.
Tell us about your project
The more detail you can share — target platform, objective, constraints, timeline — the faster we can come back with a meaningful response. All enquiries are treated as strictly confidential.