Security, Design & Quality
Cybersecurity & Compliance
Security built in from the start, not bolted on at the end. Penetration testing, secure system design, HIPAA/SOC 2 compliance engineering, and hardening for systems that cannot afford a breach.

Penetration testing, secure architecture, and compliance engineering.
- Vulnerabilities found before attackers do
- Compliance that unblocks enterprise deals
- Security built in, not bolted on
The problem
Compliance is blocking deals, and a breach would cost far more than prevention.
Security work falls into three kinds: finding weaknesses in what exists, designing systems so fewer of them appear, and preparing the evidence that customers and auditors ask for. Deals often stall on a security questionnaire long before any attack happens.
We test applications and infrastructure the way an attacker would, report each finding with the steps to reproduce it and a fix, and help your engineers close them. For frameworks such as SOC 2 and HIPAA, we prepare the technical controls and documentation an independent auditor will review. Certification itself is issued by auditors, not by us.
What you receive
What a project produces.
A scoped penetration test
Testing of the applications, APIs and infrastructure agreed in writing, within agreed rules of engagement.
A findings report
Each issue with its severity, proof, affected systems and a specific remediation, ordered by risk.
Fix support and retest
Help with the fixes, followed by a retest that confirms each one.
Architecture and threat model review
A review of how the system is built, and the risks that follow from the design.
Compliance gap assessment
A comparison of your current controls with SOC 2 or HIPAA requirements, and a plan to close the gaps.
Hardening and monitoring
Secure configuration, secret management, dependency scanning and logging that supports incident response.
How we approach it
The positions we take.
Tests are scoped and written down
We agree the targets, dates and rules before testing starts, and we test only what you authorise.
Every finding can be reproduced
You get the exact steps, so your engineers can see the problem for themselves and confirm the fix.
Fix the cause
Where a class of bug appears repeatedly, we recommend changing the pattern in the code instead of fixing instances one by one.
How it runs
Four steps, from the first call to hand-over.
1
Scope and authorise
We agree what is tested, when, and how, and you sign the authorisation. Nothing outside that scope is touched.
2
Assess and test
We review the design, then test the system as an attacker would, recording each finding with proof.
3
Report and fix
You receive a report ordered by risk, and we walk your engineers through each finding and how to close it.
4
Retest and hand over
We retest the fixes and confirm the result in writing, along with recommendations for keeping the gains.
Is it a fit
When we are the right people, and when we are not.
A good fit
- A customer's security review is slowing or blocking a sale.
- You are about to launch, or have changed a lot, and want independent testing.
- You want security built into how your team works.
Another route is better when
- You need an audit certificate issued by us. Formal SOC 2 reports come from licensed audit firms, and we prepare you for them.
- You want us to test systems you do not own or are not authorised to test.
- You are under active attack. Contact an incident response provider first. We can help afterwards.
What we ask on the first call
- What must you demonstrate, and to whom?
- Which systems are in scope?
- What data are you protecting?
- Have you had testing or an audit before?
- Which deadline is driving this?
Questions
About Cybersecurity & Compliance.
Something missing? Write to [email protected] and an engineer will answer.
Do you provide SOC 2 or HIPAA certification?
No. Certification and audit reports are issued by independent auditors. We prepare the technical controls and evidence, and support you during the audit.
Will testing disrupt our systems?
We agree a testing window, avoid destructive tests, and can test a staging copy. You are told before anything risky.
How long does a penetration test take?
It depends on the size of the application. We give an estimate after reviewing the scope on the first call.
Can you keep our findings confidential?
Yes. Reports are shared only with the people you name, and an NDA can be signed before we see anything sensitive.
Describe what you need.
Describe the problem in plain language. An engineer reads every inquiry and replies within one business day, with a written scope and fixed price before you commit to anything.
- Reply
- Within one business day
- First call
- Free, no commitment
- Confidentiality
- NDA on request, before you share anything
- [email protected]
