Lilly Systems – tooling for work people don't talk about.
Lilly Systems reviews and hardens other companies' systems: audits against recognised baselines, authorised technical security assessments, and infrastructure hardening. We build tooling for that environment. What exactly those tools do is deliberately not on this page – security work does not go well with a publicly documented toolbox.
- Cybersecurity
- Internal tooling
- Confidential
- Multilingual

The field
What the tooling is built for
What follows describes the field of work, not the tools themselves. It is a field where care counts for more than speed, and where every result has to stand up to someone re-checking it later.
Security audits
An audit is not an opinion, it is a structured comparison: what does a recognised baseline require, and what do the systems actually do? The result has to be written down so that next year someone else can repeat it and arrive at the same answer.
Security assessments
Authorised, tightly scoped technical testing of applications, APIs, cloud environments and networks. What matters is not the number of findings but how they are rated against real business impact.
Infrastructure hardening
Turning findings into an enforced baseline: least privilege, segmented networks, properly managed secrets, discipline around patching and backups, logging that is actually usable – expressed as code rather than as good intentions.
Verifiability
Everything in this field depends on claims staying provable. Tooling therefore has to deliver not just results but also the path to them – reproducible, documented, with no magic in between.
How we work here
Three steps, a lot of alignment
Understand first
Before anything gets built we settle the environment, the constraints and the failure modes. In this area, a scope drawn too generously is a risk in itself.
Build in small steps
Short, reviewable increments instead of grand gestures. Every increment is something you can actually run – not a status report.
Hand over, don't tie in
Source code, infrastructure definitions and documentation go to the client. They have to be able to run the tooling without us; anything else would be one dependency too many in this field.
Four languages
Precise in every language
The site explains audits, assessments and hardening in English, German, French and Italian. Keeping the terminology consistent across all four is the actual work.

Confidentiality
Why there are no specifics here
For most projects on this site we are allowed to show what we built. Not here – and that is not an oversight, it is part of the assignment.
Tooling used during security work always reveals something about the systems under review, about methods, and about the order in which things get examined. What would make a nice reference for us would be a map for someone else. So we name neither the tools, nor their functions, nor their technical building blocks.
What we can say: there are several tools, they are built for daily use in security work, they are developed further continuously, and they are handed over so that our client runs them independently. That reticence applies to all our engagements, by the way – on the other projects we simply have permission to show more.
The platform is operated by Lilly Systems. We are the development partner there, not the provider of the services.
See it live
Evidence, not assumptions.
Our client's website explains the field in more detail than we are allowed to here.