Services

Pentesting and AppSec

Testing of applications, pipelines and identity, ending in findings your engineers can reproduce and fix.

Findings you can act on.

Every finding comes with steps to reproduce it and a fix your team can ship. Automated scanning goes into CI, and fixes are re-tested, so results do not stop at a report.

Penetration testing

Scoped testing of web applications, APIs, cloud accounts and Kubernetes clusters, with reproducible findings and a re-test.

AI red teaming

Adversarial testing of LLM applications and agents: prompt injection, tool abuse, data exfiltration and unsafe output handling.

SAST and DAST

Static and dynamic scanning set up in CI, with rules tuned to your codebase and results triaged before they reach developers.

StackHawk

DAST in the pipeline for APIs and web apps, with scan configuration and authentication handled.

StackRox

StackRox (Red Hat Advanced Cluster Security) deployed across clusters, with image, deployment and runtime policies tuned.

Snyk

Code, dependency and container scanning integrated into repositories and CI, with policy and ownership routing.

Cloudflare WAF

Managed and custom rules, rate limiting and bot settings, configured as code and tested in log-only mode before enforcement.

AWS WAF

Web ACLs, managed rule groups and custom rules across accounts, with logging into your security data store.

ModSecurity

ModSecurity with the OWASP Core Rule Set on nginx or Apache, tuned to cut false positives on your traffic.

Entra ID auditing

Review of Entra ID tenants: conditional access, privileged roles, app registrations, consent grants and sign-in log coverage.