Barb

Overview
When Swarm Labs turned its application security work into a service called Barb (an “authorised break-in” at barb.swarmlabs.io), Spotlight was asked to design the brand and run the infrastructure. The audit methodology and application are Swarm Labs’ own; our brief was a visual identity built around severity, and a website platform hardened enough to belong to a security company. The result is a site built to pass the kind of scrutiny the service itself applies.
Client Intro
Challenges
A service whose pitch is “not a scan, an authorised break-in” sets a very high bar for its own website:
- Credibility on sight: automated scanners flood teams with false alarms and no proof; Barb’s page had to read instantly as serious security engineering, not fear-marketing.
- A language for severity: findings run from Critical down to Info, and needed one instantly legible visual scale that could carry through the site and the reports.
- Practise what it preaches: a security firm’s own site is an obvious target, so it had to survive the same scrutiny Barb applies to clients.
- Secrets in the sign-up path: the enquiry form asks prospects for test login details, which must never travel or be stored unprotected.
- Reports that cannot leak: an audit report is the most sensitive document of all, so delivery couldn’t rely on ordinary links, which end up recorded in logs and forwarded in emails.
Solution
Spotlight designed Barb’s severity-first identity and built the site to security-company standards:
- A severity-first design system: near-black surfaces and gold with a signature red “sting”, plus a five-step colour scale from Critical red to Info grey that carries from the website into every report.
- A hero that defends the gate: the homepage opens with a playable moment, a swarm of gold particles defending a hexagonal gate, while an animated walkthrough explains the six-phase method from scoping to free retest.
- Nothing worth attacking: the site is prepared in advance and served from Cloudflare’s worldwide network with no traditional server behind it, which leaves an attacker very little to aim at.
- Protected sign-up details: test login details are encrypted in the visitor’s browser before they’re sent, so they never travel or sit anywhere in a readable form.
- Report links that never leak: reports open with special access links that never appear in server records and can be revoked at any time.
Results
Barb launched with a site that demonstrates its own product: every part of barb.swarmlabs.io is built to withstand the methods it sells, down to enquiry details that are encrypted before they leave the visitor’s browser. The severity scale gives the service a visual language you can read at a glance, extending naturally into reports where each finding is scored, double-checked and flipped to “fixed” after the free retest. And because there’s no traditional server behind the site, it stays fast, inexpensive to run and hard to attack, with the client dashboard to follow on the same foundations.
Support
Spotlight continues to run everything behind barb.swarmlabs.io, from the domain and hosting to the security policy, alongside Managed Website Hosting and support across the wider Swarm Labs product fleet. Design and infrastructure by Spotlight Studios; application by Swarm Labs.