Security audit and hardening
An audit that returns two hundred findings with no ranking is useless. What matters is knowing where to start, and what it costs to do nothing about the rest.
What we examine
The surface actually exposed to the internet, usually wider than people think. Access rights, named or otherwise, and what is still open in the name of a former employee. Secrets, meaning keys and passwords left in a repository or a configuration file. Dependencies, some carrying vulnerabilities known for years.
We also look at the deployment chain, because an attacker who gains publishing rights gains everything else.
- Map of the exposed surface, ports and services included
- Review of access, roles and dormant accounts
- Search for secrets in the code and in its history
- Inventory of dependencies and known vulnerabilities
- Examination of the deployment chain and its access
A report ranked by risk
Every finding comes with the concrete scenario that makes it dangerous, what an attacker would need to exploit it, and the effort to fix it. That ranking lets a management team decide knowingly, including deciding to accept a risk and record it.
- A written exploitation scenario for each finding
- Estimated remediation effort, not only the risk
- A clear line between urgent and desirable
- Accepted risks recorded rather than passed over in silence
Hardening, not just reporting
Most audits stop at the report. We apply the fixes when you want them, in the agreed order, with verification afterwards. An unacted report costs more than no audit at all: it documents the fact that you knew.
- An encrypted, versioned secret vault put in place
- Rotation of compromised or ageing keys
- Hardening of servers, access and application headers
- Verification after fixing, with written evidence
Security audit and hardening
Do you carry out penetration tests?
We run application testing on the scope you authorise in writing, within a defined framework. We do not test a system you do not own or whose operator has not given consent.
How long does an audit take?
One to three weeks depending on scope. The report is delivered with a ranking, and the remediation phase is priced separately so that you can hand it to whoever you choose.
What about keys that are already exposed?
Revoke them, do not hide them. A key once published in a repository must be treated as known, even if the commit was deleted since. Rotation is among the first actions we recommend.
Security research
Hardening, incident response, secret management, and applied work on fraud and authenticity.
In the division Security research
Let us talk about what you want to build.
Describe your situation in a few lines. If it falls outside what we do well, we will say so immediately.
Get in touch