Security work, built in from the first line of code.
Security is not a feature we add at the end. We build it into how software is designed, written, released and run, with scanning on every release, careful access control, and logs your auditors can actually use.
What we do
Security work for the systems we build, and for systems other people built.
-
Security reviews of existing systems
A review of your code, hosting and access, with a plain-language report of the risks and what to fix first.
-
Secure design
The threats to your system worked out at the start of a project, so the right protections are designed in rather than added later.
-
Scanning on every release
Code, dependency and container scanning in the delivery pipeline, so known weaknesses are caught before release.
-
Identity and access control
Single sign-on, two-factor authentication, roles, and the least access people and services need.
-
Audit logs and monitoring
Logs that record who did what and when, kept safely and useful in an investigation.
-
Compliance evidence
Controls mapped to SOC 2 and ISO 27001, with evidence collected continuously. Our product Afranta automates much of it.
-
Fixing what audits find
We fix the issues raised by audits and security tests, and record the evidence that each one is closed.
-
Secrets and data protection
Encryption in transit and at rest, and passwords and keys kept in proper secret stores, never in the code.
Security as a habit
Behind this work
Our managing director, Johnson Nuviadenu, holds AWS Certified Security (Specialty), Certified Information Systems Auditor (CISA) and CompTIA SecurityX certifications. Our product Afranta collects continuous evidence for SOC 2, ISO 27001 and more.
-
Every change reviewed
A second engineer reviews each change before it is merged.
-
Least access
People and systems get only what they need, and access is reviewed.
-
Patched on schedule
Security patches and dependency updates on a schedule you agree, so small problems don't pile up.
-
Evidence kept
Records of reviews, tests and changes, ready for your auditors.
-
Incidents handled
When something goes wrong, we fix it, then write up what happened and what we are changing.
-
Plain language
Findings explained clearly, with priorities, not buried in jargon.
Technology we use
We'll suggest the simplest set of tools that does the job, and that your own team can live with after we're done.
Standards
- SOC 2
- ISO 27001
- OWASP guidance
In the pipeline
- Code scanning
- Dependency scanning
- Container scanning
Access
- Single sign-on
- Two-factor authentication
- Role-based access
Protection
- Encryption in transit and at rest
- Secret stores
- Audit logging
What you get
Everything your team needs to run it, change it and understand it.
- A prioritized report of risks and fixes
- Scanning in your delivery pipeline
- Access control by role, reviewed
- Audit logs you can search
- Evidence mapped to SOC 2 and ISO 27001 controls
- A record of every fix, ready for your auditors
How a project runs
Nothing starts without your sign-off, and you'll see working software every two weeks.
- 1
A free call
Thirty minutes to talk through what you need. If we're not the right fit, we'll say so.
- 2
Discovery
A few short workshops to agree goals, users, constraints and what success looks like.
- 3
Design
Screens you can click through and test with real users before we write any code.
- 4
Build
Two-week sprints. Each one ends with a demo of working software you can try and comment on.
- 5
Launch
Automated tests, security checks and a go-live plan with a way back if something goes wrong.
- 6
Looking after it
Your system moves onto a Managed Services retainer, supported by the people who built it.
What happens after launch?
You can keep us on to look after it. The people who wrote the code are the ones who keep it running, so nothing gets lost in a handover.
Common questions
- Can you help us get ready for SOC 2 or ISO 27001?
- We build and run software in a way that produces the evidence auditors ask for, and our product Afranta collects continuous evidence for SOC 2, ISO 27001 and more, with an Audit Hub for auditors.
- Can you review a system someone else built?
- Yes. We review the code, hosting and access, and give you a prioritized list of risks and fixes in plain language.
- How do you charge?
- Build work is billed by the hour against an estimate we agree before we start, and you see hours and progress every sprint. Looking after a live system is a monthly or yearly retainer.
- Where do we start?
- With a free 30-minute call. If we're not the right fit, we'll tell you. If we are, we agree goals and an estimate before any work begins.
Tell us what you're working on
The first call is free and there's no sales pitch. We reply within 24 hours.