Service catalogue
Focused scope.
Useful answers.
Start with one clear question. Leave with evidence, priorities and practical next steps.
App & Code Review
Review the code behind your next launch.
A focused security review of your application, architecture and integrations. Especially useful for AI-generated apps, Python/Flask projects and APIs that are about to meet real users.
AI-built and vibe-coded app reviews · Python & Flask security · API and application reviews
Scope can include
- Authentication, sessions and access controls
- Input handling, APIs and sensitive data
- Secrets, dependencies and deployment settings
What you leave with
Prioritised findings, supporting evidence, practical fixes and a walkthrough with your team.
Discuss this reviewOne agreed application or codebase. Remediation, retesting and broader penetration testing are scoped separately.
Exposure & OSINT
Understand what your public footprint reveals.
See your organisation from the outside. We connect public-source research with an attack-surface review to identify exposed assets, leaked information and gaps worth investigating.
Attack-surface reviews · Exposure checks · Business OSINT · Digital-footprint reviews
Scope can include
- Domains, subdomains and internet-facing assets
- Accidental data, repository and credential exposure
- Business, brand and public digital-footprint research
What you leave with
An evidence-backed exposure inventory, prioritised risks and clear recommendations to reduce your footprint.
Discuss this reviewPublic-source research and authorised assets only. No access to private accounts or systems without permission.
Security Hardening
Turn security intentions into everyday practice.
Strengthen the systems your work depends on. We review the setup, identify practical improvements and agree which changes to help you implement.
Cloud & configuration reviews · DevSecOps · Security posture reviews · Remote-work security
Scope can include
- Cloud configuration, permissions and secrets
- DevSecOps pipelines and deployment safeguards
- Identity, MFA, devices, backups and remote-work access
What you leave with
A prioritised hardening plan with agreed implementation support and a practical handover.
Discuss this reviewChanges are agreed before implementation. Ongoing monitoring, incident response and compliance certification are not included.
Not sure where to start?
Tell us what’s on your radar. We’ll help you find the right starting point.
Scope, deliverables and pricing are agreed before work begins.