Skip to main content
QuantLab Logo

Custom Software Development & Cybersecurity in Detroit, MI

Detroit is the center of the auto and mobility world, and the software demand that comes with it is enormous — supplier portals, manufacturing operations, fleet and telematics tooling, and the integration layer that holds the supply chain together.

QUANT LAB USA pairs custom software engineering with hands-on penetration testing rooted in the MITRE ATT&CK framework — not just selling development hours. For an automotive supply chain where OEM security requirements are non-negotiable, that combination fits unusually well.

Why Detroit organizations choose QUANT LAB USA

Detroit's economy still runs on the automobile, but the software story is bigger than the Big Three. General Motors, Ford, and Stellantis anchor a supply chain that runs thousands of Tier-1 and Tier-2 suppliers deep across Wayne, Oakland, and Macomb counties — and every one of them runs on EDI, MES, PLM, and quality-tracking systems that have to talk to the OEMs and to each other. The mobility shift has layered new demand on top: autonomous and connected-vehicle work, telematics and fleet platforms, and a research corridor anchored by the University of Michigan in Ann Arbor and the American Center for Mobility. Detroit's downtown resurgence, led by Rocket Companies and a growing tech and fintech base, adds yet another layer of software demand. Across all of it, operations tooling, supplier portals, and integration work are constant needs.

Detroit has plenty of staffing firms and enterprise consultancies. What is harder to find is a founder-led shop that ships modern web applications, builds the integration layer between legacy MES or PLM systems and new tooling, and runs credible offensive security engagements — all under one roof. That is what we offer. Active Directory abuse paths, lateral movement, ADCS certificate abuse, Kerberoasting, web app exploitation — that is in-house capability, not a subcontracted line item. And every line of software we ship is reviewed against the same threat models we use on offensive engagements.

What we ship for Detroit clients

Supplier Portals & Tier-1 Tooling

Custom portals, EDI workflows, and quality-tracking tools for automotive suppliers and the OEM supply chain. Typical: $25k–$100k.

Manufacturing Ops Dashboards

Real-time visibility into production lines, jobs, inventory, and machine data for Metro Detroit plants. Typical: $25k–$90k.

Mobility & Logistics Software

Fleet, telematics integration, and operations tooling for the mobility and logistics ecosystem. Typical: $25k–$100k.

Penetration Testing (Web, Network, AD)

Full-scope engagements with formal reports for TISAX, SOC 2, and OEM supplier security reviews. Typical: $10k–$35k.

ERP & Systems Integration

Connecting legacy MES, ERP, and PLM systems with modern web apps through hardened, documented APIs. Typical: $15k–$60k.

Stripe & Subscription Billing

Subscription products, metered usage, and licensing for local SaaS and mobility-tech founders. Typical: $8k–$28k.

Portfolio note

QUANT LAB USA is a founder-led shop with a track record of shipping production software and running full-scope security engagements. Our pen testing work includes an end-to-end internal Active Directory assessment for a regional financial-services firm — eleven attack modules, every finding mapped to a MITRE ATT&CK technique, the full attack chain from standard user to Domain Admin documented with screenshots and timestamps. The client passed their compliance audit on the first attempt. That is the same methodology we apply to every Detroit-region engagement, whether the buyer is an automotive supplier, a mobility-tech company, or a Metro Detroit SaaS founder.

  • Founder-led — you work directly with the engineer building your system
  • Supplier portals and EDI workflows for the OEM supply chain
  • In-house offensive security (AD abuse paths, web app, network)
  • Reports formatted for OEM and TISAX supplier-security reviews
  • Modern Next.js / TypeScript / PostgreSQL / Docker stack

How we work remotely with Detroit teams

Detroit runs on Eastern Time, the same as our Macon, Georgia headquarters, so we share the entire business day — no awkward windows for standups, reviews, or same-day questions. Most engagements start with a 60-minute scope by video. For engagements above roughly $25k we travel to Detroit for an on-site kickoff and for internal pen tests that require physical network access. Build cycles run weekly with a Friday staging URL, written notes, and the next-week plan. Pen test reports are delivered in two formats: a technical deliverable with reproduction steps and remediation detail for the security team, and a board-readable executive summary with a prioritized remediation roadmap. Fixed-scope, fixed-price proposals on most engagements; full code, database, and infrastructure handover at acceptance.

FAQ

Do you build software for automotive suppliers?

Yes — supplier portals, EDI workflows, and quality-tracking tools for the Tier-1 and Tier-2 supply chain are core work for us. We integrate with the EDI, MES, and PLM systems the OEMs require rather than replacing them.

Can you produce a pen test report for an OEM or TISAX security review?

Yes — our reports are formatted to drop straight into audit binders and supplier-security questionnaires, with technical reproduction steps for engineers and an executive summary with a prioritized remediation roadmap for leadership. Every finding is mapped to a MITRE ATT&CK technique.

Do you build mobility and fleet software?

Yes — Detroit is the center of the mobility industry, and fleet operations, telematics integration, and logistics dashboards are recurring work for us. We build the operational layer and integrate with the telematics and vehicle-data providers you already use.

Are you local to Detroit, or remote?

We are headquartered in Macon, Georgia and work remote-first across the United States. For engagements above roughly $25k we travel to Detroit for an on-site kickoff and for internal pen tests that require physical network access — downtown, Dearborn, the Troy and Auburn Hills corridor, and Ann Arbor are all easy from DTW.

What pen testing methodology do you use?

Our framework is MITRE ATT&CK end-to-end. Every finding is mapped to a technique ID. We run eleven attack modules covering recon, credential spraying, Kerberoasting, ADCS abuse, lateral movement, and command-and-control infrastructure.

What is your timezone overlap with Detroit?

Detroit runs on Eastern Time, the same as our Georgia headquarters, so we share the full business day — complete overlap for standups, reviews, and same-day responses.

What is a typical timeline for a Detroit engagement?

A standalone external pen test runs two to three weeks including reporting. A supplier portal or manufacturing tool typically runs eight to fourteen weeks depending on integrations. We give a fixed scope and fixed price before any work begins.

Do you follow up after remediation?

Yes — most pen testing engagements include one round of retest on remediated findings within 60 days of the initial report at no additional charge.

Talk Detroit projects.

Call (770) 652-1282 or email beltz@quantlabusa.dev to discuss Detroit engagements.

Start a Project