All services
Service
Cybersecurity
Audits, hardening, GDPR/NIS2 compliance. Security as a property, not an afterthought.
Security is a property of the product, not a bolted-on layer. We perform audits (code, infrastructure, OWASP Top 10), pentesting, hardening, and GDPR/NIS2/ISO 27001 compliance. Our rule: defense in depth, least privilege, fail secure, zero trust.
What we deliver
Concrete, measurable, no surprises.
Non-negotiables
Our production standards.
Tools adapt to your context; our standards never move. Every project inherits this baseline — it is written into your contracts, not just this page.
Process
Four steps, one standard.
FAQ
Frequently asked questions.
- What's the difference between an audit and a pentest?
- Audit = methodical review of posture (code, config, process). Pentest = active attack simulation, on a defined target.
- Are you certified?
- The team includes OSCP, CEH, CISSP profiles. For formal ISO 27001 / SOC 2 certification, we work with auditor partners.
- Do you write the full GDPR compliance package?
- Yes — register, DPIA, processor contracts, data-subject information. For the DPO role we recommend a specialised legal partner.
- How does a pentest unfold?
- Scoping (perimeter, windows, modes), reconnaissance, exploitation, post-exploitation, report, retest. Typical duration: 1 to 3 weeks.
- What about NIS2 for critical actors?
- Asset mapping, technical and organisational measures, incident management, governance, reporting. Full support available.
- Do you train our teams?
- Yes — secure coding, infrastructure hardening, phishing awareness. Programmes tailored to dev / ops / general staff.