Not an add-on. One continuous workflow.
Security starts with requirements and ownership. The necessary safeguards follow the data, risks and operating model.
What we examine systematically in projects
Access
Accounts and permissions are limited to what is required. Administrative access receives additional protection and logging rules.
Development
Reviews, automated checks and separated environments are used in proportion to the project risk.
Dependencies
Libraries and services are inventoried, updated and assessed when relevant vulnerabilities emerge.
Data
Data types, purpose, storage locations, retention and deletion are documented for each project.
Operations
Monitoring, updates, backups and recovery are named operating tasks with accountable owners.
Incidents
Reporting paths, containment, communication and follow-up are prepared and practised together when appropriate.
Report a vulnerability responsibly
Do not send sensitive details through public channels. First identify the affected surface, potential impact and a secure way to contact you.
[email protected]
We acknowledge receipt, arrange a secure exchange and treat reports confidentially. The specific response time depends on severity and availability.
Start a security reportAssess security for a specific project
We classify the data, risks, responsibilities and appropriate safeguards.