Aller au contenu principal
All services

Service

Cybersecurity

Audits, hardening, GDPR/NIS2 compliance. Security as a property, not an afterthought.

Security is a property of the product, not a bolted-on layer. We perform audits (code, infrastructure, OWASP Top 10), pentesting, hardening, and GDPR/NIS2/ISO 27001 compliance. Our rule: defense in depth, least privilege, fail secure, zero trust.

What we deliver

Concrete, measurable, no surprises.

  • OWASP Top 10 audit

    Code review, SAST/DAST analysis, OWASP Top 10, OWASP ASVS, API Top 10. Deliverable: prioritised report and remediation plan.

  • Pentest & red team

    Black/grey/white box intrusion tests, realistic scenarios, exploitation chains. Executive + technical report, post-fix retest.

  • GDPR & NIS2 compliance

    Impact assessment, processing register, technical measures, DPIA, processor contracts, NIS2 governance.

  • Application security

    Headers (CSP, HSTS, COOP/COEP), secure cookies, MFA, RBAC, PostgreSQL RLS, DOMPurify sanitisation, webhook signatures.

  • SecOps & SOC

    Log centralisation (SIEM), detection (IDS/EDR), incident response, threat intelligence, reverse engineering.

  • Training & awareness

    Developer training (secure coding), ops (hardening), and staff (phishing, digital hygiene).

Non-negotiables

Our production standards.

Tools adapt to your context; our standards never move. Every project inherits this baseline — it is written into your contracts, not just this page.

  • OWASP and ASVS frameworks on every audit
  • Critical patches deployed within 72 hours
  • Secrets encrypted, never present in code
  • Contractual incident response, 24/7
  • Actionable audit reports, no jargon
  • Your teams trained on the right reflexes

Process

Four steps, one standard.

  1. 01

    Scoping & threat

    STRIDE modelling, CVSS scoring, critical asset identification, attack scenarios. Deliverable: threat model.

  2. 02

    Audit

    Code review, SAST/DAST scan, intrusion test, infrastructure audit, config audit. Deliverable: prioritised report.

  3. 03

    Remediation

    Criticality-ordered treatment plan, application/infrastructure fixes, retest validation. Documentation of accepted residual gaps.

  4. 04

    Compliance & continuity

    GDPR/NIS2/ISO 27001 compliance, governance, periodic reviews, continuous training, CVE monitoring.

FAQ

Frequently asked questions.

What's the difference between an audit and a pentest?
Audit = methodical review of posture (code, config, process). Pentest = active attack simulation, on a defined target.
Are you certified?
The team includes OSCP, CEH, CISSP profiles. For formal ISO 27001 / SOC 2 certification, we work with auditor partners.
Do you write the full GDPR compliance package?
Yes — register, DPIA, processor contracts, data-subject information. For the DPO role we recommend a specialised legal partner.
How does a pentest unfold?
Scoping (perimeter, windows, modes), reconnaissance, exploitation, post-exploitation, report, retest. Typical duration: 1 to 3 weeks.
What about NIS2 for critical actors?
Asset mapping, technical and organisational measures, incident management, governance, reporting. Full support available.
Do you train our teams?
Yes — secure coding, infrastructure hardening, phishing awareness. Programmes tailored to dev / ops / general staff.

Ready to start?

Let's talk about your project. Reply within 48h, free quote, no strings attached.