Build — Security

We tell you what's exposed before someone else finds it.

Hardening for platforms handling payments, personal data, or high-stakes operations.

The problem

The platform was built to ship, and security was the thing you would get to once there was time. Now it handles payments or personal data, the dependency tree has not been audited since launch, the staging environment is on the public internet with last year's database in it, and nobody is certain which API keys are still valid or who has them.

What you get

  • Dependency audit with a prioritised, actually-fixable remediation list
  • Infrastructure review — network exposure, secrets handling, access control, backups
  • Application testing against the OWASP Top 10, focused on your real attack surface
  • Authentication and authorisation review, including the paths nobody documented
  • GDPR-relevant data mapping — what you hold, where it lives, how long it stays
  • A written report a non-specialist can act on, ranked by exploitability rather than by CVSS alone

How it works

We start with what is reachable from the outside, because that is what an attacker starts with. Then we work inward through authentication, data handling and infrastructure. Findings are ranked by what is genuinely exploitable in your context rather than by raw severity score — a critical in a dependency you do not call is not a critical for you. The report is written to be acted on: what to fix first, what can wait, and what is a design decision you should make consciously rather than a bug.

Technical detail

Scope

Application, dependencies, infrastructure and access. We agree scope and rules of engagement in writing before anything is touched, and we test against environments you authorise, never production without explicit consent.

Method

Automated scanning to establish a baseline, then manual testing where the logic lives — authorisation boundaries, multi-tenant isolation, payment flows. Scanners find the known; the interesting failures are in business logic and no tool finds those.

Reporting

Each finding gets a reproduction, an impact statement in business terms and a concrete fix. Ranked by exploitability in your context. No pages of unfiltered scanner output presented as a deliverable.

What's not included

  • Compliance certification. We can prepare you for an audit; we are not an auditor and cannot certify you.
  • Continuous monitoring and incident response as a managed service. We will set up the tooling and the runbooks and hand them over.
  • Testing systems you do not own or control. We need written authorisation from the owner, without exception.

Where we hand off, we tell you before the invoice arrives — not after.

Related services

You dream it. We create it.

Discovery call, project brief, or just a question. Get in touch.

Get in touch