About Us

About CQRE

CQRE.NET is the business name of CZ Expert, s.r.o., a Czech limited-liability company founded around 2000, operating from Prague. We work with organisations across Central Europe and the UK.

Who We Are

We help organisations close the gap between their security investments and their actual security posture. In practice, this means auditing what exists honestly — not what the policies say should exist — maximising value from tools already paid for, and building retained capability inside client organisations rather than dependencies on us.

We operate under the Brownhat brand when engaging with clients — a name that reflects our core philosophy: we work in brownfield environments (built up, lived in, carrying the weight of past decisions) and our job is to recultivate what exists before recommending anything new.

We also build open-source tools — PULSAR and ASTRAL — used by M365 administrators and security teams who need continuous audit log retention and configuration governance without vendor lock-in. AURORA, our commercial intelligence layer, sits above both.

How We Think

Five principles shape every recommendation we make:

PrincipleWhat it means in practice
Structural DecouplingIdentify and remove hidden dependencies before they become fatal. Do not add complexity that creates new ones.
Optionality PreservationSpend your budget on things that preserve your ability to change direction. Every unnecessary tool purchase reduces strategic flexibility.
Stress-to-Signal ConversionEvery incident, failure, and near-miss is intelligence. Build systems that learn from disruption rather than merely surviving it.
Sovereign IntelligenceYour proprietary data should improve your own capability, not a vendor’s model. Own the tools and systems you depend on.
Asymmetric Payoff DesignSmall, targeted investments on existential risks yield disproportionate protection. Concentrate effort where failure is fatal.

What We Do Not Do

We do not run a 24/7 SOC. We deploy, configure, and commission monitoring tools. For continuous managed response, we work with commercial partners or help clients build internal capability.

We do not sign off on compliance audits. We prepare clients for audits — mapping controls, building evidence packages, closing gaps. The audit opinion belongs to a qualified auditor.

We do not replace your IT team. We work alongside your people, transfer knowledge as a matter of course, and leave when the engagement closes. When we leave, your team can operate what we built.

We disclose our commercial relationships. We have partnerships with Huntress, Tailscale, Thinkst Canary, and Tenable. If we recommend one of these tools, we say so and explain why the open-source alternative does not meet your specific need.

Contact

The best way to start is to send us a message describing your situation. We will respond with an honest assessment of whether and how we can help.

Emailhello@cqre.net
Webcqre.net
LanguagesEnglish, Czech
GeographyCzech Republic, Slovakia, UK; remote engagements across the EU
Response timeInitial reply within 1 business day

For open-source tool questions, issues, and contributions, please use the GitHub repositories directly: