- Duration
- 1-3 weeks
- Who for
- Teams with a security questionnaire from a large customer on the desk, a due diligence ahead or NIS2 obligations to document.
- How it starts
- Access to code and infrastructure, written agreement, then one to three weeks of work.
What changes for youAn honest answer to "how exposed are we" and a document you can show a customer or an investor.
What you get
- Security code review: authorization, injection, secrets in code, dependencies, error handling
- Infrastructure and configuration hardening: public exposure, TLS, headers, permissions, segmentation
- Secure SDLC: secrets, dependency scanning, CI/CD security, access control, backup and restore
- A report with findings, severity and a remediation plan, plus the remediation if you want it
- Support for the NIS2 self-assessment, if you are an important or essential entity
This is not a cybersecurity audit under Romanian OUG 155/2024 and not a penetration test. We find, recommend and fix; for pentests we work with specialized partners.