Company

We exist because we proved the problem firsthand.

Covenant Engine Ltd is an IP attribution and security company incorporated in England and Wales — building tools for organisations that cannot afford to find out about a leak the hard way.


About

Intellectual property is the most valuable asset most organisations will ever create. A single undetected leak — a research dataset, a trading algorithm, a product design — can transfer years of competitive advantage to a competitor with no evidence, no attribution, and no recourse.

Covenant Engine builds the infrastructure that closes that gap. Our platform embeds invisible attribution signals into source code, research documents, design files, and AI model artefacts. If anything leaks, you know whose export it was, when it happened, and through which channel — with cryptographically signed evidence ready to act on.

We are a product company. Not a consultancy. Everything we build is self-serve, deploys in under thirty minutes, and produces a clear answer when you need one most.

Leadership & Founder Transparency

Covenant Engine Ltd is led by experienced technical founders with deep expertise in enterprise auditing, cybersecurity, and applied artificial intelligence.

Costin Glejaru

Founder & Chief Executive Officer
costinglejaru@getcovenantengine.com

Pioneered the empirical auditing methodology behind Covenant Engine after discovering undisclosed proprietary AI model architectures in enterprise ERP audits. Leads core architecture, post-quantum cryptography integration, and strategic partnerships.


Founding Insight

The company was founded after a direct empirical observation — not a theoretical threat model.

"While auditing closed-source enterprise systems, we observed commercial AI models possessing specific product architecture and defect details that had never been publicly disclosed. This was direct empirical proof that critical IP was leaking out of enterprise environments completely undetected — leaving no digital footprint, no alert, and no way to identify the source."

The audit revealed something the industry had underestimated: sensitive intellectual property was leaving controlled environments through channels that existing DLP tools were architecturally incapable of monitoring — model training pipelines, semantic caches, vector stores, and compressed embedding spaces.

The consequence was not just a data breach. It was a transfer of institutional knowledge — the kind that takes years to build and can be extracted invisibly in minutes. We built Covenant Engine because no credible solution existed.

The gap we identified

Existing DLP tools monitor file transfers and network egress. They cannot detect when proprietary knowledge is encoded into an AI model's weights through training data exposure.

What we built instead

Attribution that travels with the asset — not with the network packet. Whether a file is copied, photographed, or embedded into a model, the signal persists and can be recovered.


Careers

Hiring soon — roles opening shortly

We are a small, technical team. We hire people who want to work on hard problems at the intersection of cryptography, machine learning forensics, and enterprise security. We move fast, ship real products, and take attribution seriously at every layer — including in who we hire.

Roles will be based in London (hybrid) or fully remote for the right candidates. We will not require disclosure of your current salary, and we will be specific about compensation from the first conversation.

Engineering

ML & Forensic Research

Signal design, extraction pipelines, super-resolution, steganographic robustness.

Engineering

Cryptography & Security

Post-quantum schemes, key management, ZK proofs, WASM sandboxing.

Engineering

Backend & Platform

FastAPI, distributed systems, real-time alerting, SIEM integrations.

Engineering

Frontend & Product

React, TypeScript, data-dense dashboards, developer tooling, CLI design.

Go-to-Market

Enterprise Sales

Pharma, fintech, and defence verticals. Technical fluency valued as much as pipeline experience.

Go-to-Market

Solutions Engineering

Proofs of concept, integration support, and technical storytelling for enterprise buyers.

Legal & Policy

IP & Data Law Counsel

UK / EU IP litigation experience, GDPR, AI Act, and evidentiary standards for digital forensics.

Operations

Trust & Safety

DMCA process, platform abuse, and policy — particularly for the B2C creator tier.

Research

Adversarial ML

Robustness against removal attacks, evasion, and adversarial perturbation of attribution signals.

We don't have a formal careers page yet. If a domain above resonates, send a note introducing yourself — what you've built, what you're thinking about, and what kind of problem you want to work on next.

careers@covenantengine.com

Security

Every tier of Covenant Engine is designed on a single principle: your IP stays within your control. We process metadata, never content.

No file content leaves your perimeter

Attribution markers are computed and embedded locally. No file content is transmitted to Covenant servers in any tier — not even for forensic analysis.

Encryption at rest and in transit

AES-256-GCM for stored assets. TLS 1.3 for all API communication. Post-quantum key encapsulation available in the Dedicated tier via liboqs Kyber-1024.

Cryptographic audit log

Every access, export, and alert is recorded in an append-only, hash-chained log. Tamper-evident and exportable to Splunk, CEF, and JSON-L.

On-premise available

The Dedicated tier deploys entirely within your own infrastructure. No external network calls. Hardware HSM key storage supported. Suitable for air-gapped environments.

To report a security vulnerability, contact security@covenantengine.com. We aim to acknowledge all valid reports within 48 hours.


Compliance

Designed from the ground up to operate within applicable data protection, AI, and financial regulation.

GDPR Article 25 — Privacy by Design

All biometric features require explicit per-seat written consent. Processing is local. No personal data is retained beyond its declared purpose.

SOC 2 Alignment

Audit log format, role-based access control model, and SIEM export are aligned with SOC 2 Trust Service Criteria for Security and Availability.

EU AI Act

Biometric and computer vision features are built with explainability, human-in-the-loop overrides, and data subject access rights as first-class requirements.

Legal evidence standards

Forensic reports carry cryptographic signatures and chain-of-custody metadata designed for use in civil IP proceedings under UK and EU law.



Contact

We respond to all enquiries within one business day.