Service 10 — Cybersecurity

We advise
and protect
your business.

Helping you develop high-quality infrastructure and keep it that way: architecture review, hardening, dependency scanning and continuous security audits from first commit through launch and after.

What is included

  • Architecture review
  • Infrastructure hardening
  • Dependency and secret scanning
  • Application testing
  • Incident readiness
  • Continuous audits

Security is a property of the process

You cannot inspect security into a product at the end. It comes from decisions taken early — how sessions work, where secrets live, what the database user is allowed to do — and from a routine that keeps those decisions true as the code changes.

We build that routine in. Dependency scanning in CI, secrets out of the repository, least privilege by default, and an audit before every launch. For care-plan clients the audits continue on a schedule, because the threat landscape does not stop at handover.

What we are, and what we are not

We are engineers who take security seriously and who have cleaned up after real incidents. We are not your auditor, your QSA or your legal counsel, and we will not pretend to be. Where a standard requires certification, we build to it and work alongside the people who certify it.

Deliverables

What you
actually get.

01

Architecture review

Trust boundaries, authentication, session handling, data flows and the blast radius of each component.

02

Infrastructure hardening

Firewalls, least privilege, patching, disabled defaults and network segmentation where it earns its cost.

03

Dependency and secret scanning

Automated in CI, with a policy for how fast a critical advisory has to be resolved.

04

Application testing

Injection, access control, file handling, rate limiting and the OWASP categories that actually show up in the wild.

05

Incident readiness

Logging that lets you reconstruct events, an escalation path, and a rehearsed restore for the worst day.

06

Continuous audits

Scheduled re-checks after launch, with a written report and a prioritised remediation list each time.

Shapes of the work

Where this
usually lands.

EngagementWhat happensOutput
Pre-launch auditArchitecture, application and infrastructure reviewPrioritised findings with fixes and effort estimates
RemediationWe fix what the audit or a pen test foundVerified fixes and a retest report
Continuous auditScheduled re-checks on a care planRecurring report and a trend line
Incident responseContainment, forensics, recovery, write-upTimeline, root cause and prevention plan

Stack

What we build
this with.

We work in your stack when you have one. These are our defaults when the choice is ours.

OWASPNmapBurp SuiteDependabotTrivyfail2banCloudflare WAFVaultTLSSIEM

Questions

Before you
commit.

We have been breached. Can you help today?
Say so in the first line of your message and we will respond as fast as we can. First priorities are containment and preserving evidence — resist the urge to wipe and rebuild before somebody has looked.
Do you do penetration testing?
We do application and infrastructure testing as part of our audits. For formal third-party pen tests we recommend an independent firm — you should not have the builder marking their own homework — and we remediate what they find.
Can you help us pass SOC 2 or ISO 27001?
We build and document to those controls and work with your auditor. We cannot certify you, and any vendor who says they can is selling you something else.
How much does an audit cost?
A pre-launch audit for a typical web application is scoped in days, not weeks, and quoted as a fixed number once we have seen the architecture.

Ignition

Need cybersecurity?

Tell us the problem, the users and the systems already in place. We will identify the right discovery or build step.