Application security
Testing at the end of a release cycle finds bugs. Sitting with the team while the design is still soft prevents whole classes of them.
- duration
- Retained, or 3-week blocks
- team
- 1–2 embedded engineers
- retest
- Included, 90 days
design
We join the RFC review and argue about trust boundaries while changing them is still cheap.
code
Source-assisted review of authentication, authorisation, tenancy, and anything handling money.
dependencies
Provenance, transitive risk, and a realistic view of which advisories actually apply to you.
handover
The goal is that you need us less each quarter. We consider a shrinking retainer a success.
everything below, on every engagement
Yes, under your access controls, with our commits signed and clearly attributed.
penetration testing
Time-boxed, scoped testing of a system you already have, graded against exploitability rather than a scanner's opinion.
red teaming
An objective-led simulation of a real adversary, run against your detection and response rather than against a checklist.
cloud security review
A read of your AWS, Azure or GCP estate as an attacker reads it: identity first, blast radius second, compliance a distant third.
scope a application security
Tell us what the system does and who relies on it. We will come back with a scope, a price and a date, usually within two working days.
