Services
Security testing that fits how you ship.
Fixed-scope engagements with clear deliverables. Pick one, or combine them — most teams start with a code review before a release.
Secure code review
We read the code paths where security decisions are made and follow data from the point it enters your system to where it's stored, rendered or executed. Tooling helps us cover ground; the findings come from people.
Works well before a major release, after a rewrite, or when you're inheriting a codebase you didn't write.
Typical focus areas
- Authentication, sessions and password reset flows
- Authorization and multi-tenant isolation
- Injection: SQL, command, template, SSRF
- Cryptography and secrets handling
- Payment and billing logic
- Dependency and supply-chain risk
Web & API penetration testing
Authenticated, manual testing of web applications and REST or GraphQL APIs. We test with multiple roles and tenants, because the most damaging bugs are usually about who can see or change what.
Black-box, grey-box or white-box — access to source code makes testing faster and finds more.
Typical focus areas
- Broken object- and function-level authorization
- Business logic abuse and race conditions
- Account takeover paths
- File upload and parsing
- Rate limiting and enumeration
- Cloud metadata and internal service exposure
Threat modeling
A structured working session with your architects and engineers. Together we map components, data flows and trust boundaries, then walk through realistic attack scenarios.
The output is short and practical: what can go wrong, how likely it is, and which controls to build first.
Typical focus areas
- New products and major features
- Moves to microservices or new cloud providers
- Integrations with third-party identity or payment providers
Developer training
Workshops for engineering teams, built around vulnerabilities in the languages and frameworks you actually use. Participants find and fix bugs in realistic sample code rather than watching slides.
Available remotely or on-site, in English or Russian.
Typical focus areas
- Secure coding for backend developers
- Authentication and session management
- Reviewing pull requests for security
Stacks
Languages and platforms we review regularly.
Not on the list? Ask — the principles carry over, and we'll tell you honestly if it's outside our depth.
- Go
- Python
- TypeScript / Node.js
- Java & Kotlin
- PHP
- Ruby
- C# / .NET
- Rust
- React
- Django
- Spring
- Laravel
- PostgreSQL
- Kubernetes
- AWS
- GCP
FAQ
Common questions.
Do you need access to source code?
Not always, but it helps. White-box testing finds more issues in less time, and the fixes we suggest match your actual code instead of guesses about it.
Will testing affect production?
We prefer a staging environment that mirrors production. If production is the only option, we agree on test windows and rate limits in advance and avoid destructive payloads.
How is pricing calculated?
Each engagement has a fixed price based on the agreed scope, so there are no hourly surprises. Retesting fixed issues is included.
Can you sign an NDA?
Yes. We're happy to sign yours, or send ours, before we see any code or documentation.
Do you do compliance audits?
We don't issue certifications. Our reports are structured so they can be used as supporting evidence for SOC 2, ISO 27001 or PCI DSS assessments.
Shipping something important soon?
Tell us what you're building. We reply within two business days.