Exposed surface audit
Inventory of reachable services, access and secrets, with a prioritised reduction plan.
Security is not a layer you add. It is an operational discipline, and a source of applied research.
The overwhelming majority of compromises we know of start with a secret that should not have been where it was: a private key in a consumer sync service, an interface token in a code repository, a password in a version-controlled configuration file. The bots that sweep those sources find them within hours.
We apply one rule without exception: secrets live in a vault encrypted at rest, version controlled, unlocked by a master key held offline. A secret taken out of the vault has a lifetime and a scope. Rotation is never limited to changing a value, it includes finding every place the old value was used.
Serious incident response follows an order that is not negotiable: isolate before understanding, preserve traces before cleaning, rebuild rather than repair, and only return to service on a machine whose state can be asserted.
The most common mistake is rotating new keys on a machine that is still compromised, which hands the new ones to the same attacker. We document those sequences, we rehearse them, and we keep the indicators of compromise we encounter in order to search for them elsewhere.
On a merchant platform, fraud is not an exceptional incident, it is a continuous flow. We build measurable signals rather than intuitions: consistency between billing and delivery address, credential reuse, attempt velocity, gap between the basket and the account history.
Those signals inform a decision, they do not accuse. A score feeds an explicit, reviewable and logged decision, so that a refusal can always be explained to the customer.
We carry out applied work on authenticity verification in two directions. The first concerns reviews and reputation signals, a significant share of which is artificially produced. The second concerns the authentication of physical products and the traceability of their chain of custody.
This work draws on data analysis, image processing and applied electronics. It feeds directly into our other divisions, which are its first users.
Inventory of reachable services, access and secrets, with a prioritised reduction plan.
Encryption at rest, version control, rotation procedure and removal of already exposed secrets.
Written procedure, roles, isolation and rebuild sequence, and a tabletop exercise.
Injection, access control, session handling, data exposure, dependencies.
Signals, scoring, logged decisions and assembly of dispute files.
Bespoke work on authenticity, traceability and instrumentation, on a scope defined with you.
Technologies
Describe your situation in a few lines. If it falls outside what we do well, we will say so immediately.
Get in touch