Services · 04 · 1-3 weeks

Security assessment and hardening

Code review for authorization, injection and secrets, infrastructure and CI/CD hardening, preparation for enterprise security questionnaires and NIS2 requirements. A report with findings, severity and a remediation plan. Behind it: hundreds of security findings found and fixed in production code, not just reported.

Duration
1-3 weeks
Who for
Teams with a security questionnaire from a large customer on the desk, a due diligence ahead or NIS2 obligations to document.
How it starts
Access to code and infrastructure, written agreement, then one to three weeks of work.

What changes for youAn honest answer to "how exposed are we" and a document you can show a customer or an investor.

What you get

  • Security code review: authorization, injection, secrets in code, dependencies, error handling
  • Infrastructure and configuration hardening: public exposure, TLS, headers, permissions, segmentation
  • Secure SDLC: secrets, dependency scanning, CI/CD security, access control, backup and restore
  • A report with findings, severity and a remediation plan, plus the remediation if you want it
  • Support for the NIS2 self-assessment, if you are an important or essential entity

This is not a cybersecurity audit under Romanian OUG 155/2024 and not a penetration test. We find, recommend and fix; for pentests we work with specialized partners.

Method

How we work

Four rules that have kept us away from failed rewrites and 3 a.m. incidents.

01

Incremental beats rewrite

We moved a production SaaS platform from a mixed PHP and Node.js stack to Symfony 7, with verified behavioral parity, while the product kept shipping. We recommend a rewrite only when the audit numbers actually support it.

02

Tests go in before the refactor

We document existing behavior, generate and verify tests, then change things. Nothing reaches production without the safety net.

03

AI orchestrated, human judgment

We use AI agents daily, including multi-agent setups, for tests, review, migrations and documentation. They compress delivery time. Architecture, decisions and accountability stay human, and we answer for every change that reaches production.

04

Boring on purpose

Clean architecture, small units, unexciting technology that keeps working. We write code as if someone else maintains it tomorrow, because that is exactly what will happen.

Contact

Let's talk

Tell us what you have, in your own words. You do not need to know which technology the system runs on; we will work that out. You get back questions and a written proposal.

Write to usor directly at [email protected]