Services
Pentesting and AppSec
Testing of applications, pipelines and identity, ending in findings your engineers can reproduce and fix.
Findings you can act on.
Every finding comes with steps to reproduce it and a fix your team can ship. Automated scanning goes into CI, and fixes are re-tested, so results do not stop at a report.
Penetration testing
Scoped testing of web applications, APIs, cloud accounts and Kubernetes clusters, with reproducible findings and a re-test.
AI red teaming
Adversarial testing of LLM applications and agents: prompt injection, tool abuse, data exfiltration and unsafe output handling.
SAST and DAST
Static and dynamic scanning set up in CI, with rules tuned to your codebase and results triaged before they reach developers.
StackHawk
DAST in the pipeline for APIs and web apps, with scan configuration and authentication handled.
StackRox
StackRox (Red Hat Advanced Cluster Security) deployed across clusters, with image, deployment and runtime policies tuned.
Snyk
Code, dependency and container scanning integrated into repositories and CI, with policy and ownership routing.
Cloudflare WAF
Managed and custom rules, rate limiting and bot settings, configured as code and tested in log-only mode before enforcement.
AWS WAF
Web ACLs, managed rule groups and custom rules across accounts, with logging into your security data store.
ModSecurity
ModSecurity with the OWASP Core Rule Set on nginx or Apache, tuned to cut false positives on your traffic.
Entra ID auditing
Review of Entra ID tenants: conditional access, privileged roles, app registrations, consent grants and sign-in log coverage.