Skip to content

Security · Review and hardening · Fixed price

Your provider is certified. Your code is not. We find where attackers get in and close the door.

The data centre has access control and a certificate. The firewall runs. And still: a login form built wrongly lets anyone into the database. An outdated library opens the door. No provider certificate helps against that.

We test your website or application the way an attacker would, fix what we find and write it up so your data protection officer, an auditor or an investor can read it. No seal, but software that survives an audit.

Fixed price after a short conversation. Results as a readable report with location and fix. Technical review, not a certification and not legal advice.

Typical findings

Data centre
certified, inherited
Encryption
fine
Login
database exposed
Libraries
14 outdated
Browser protection rules
missing
Logs
none

Example, not a customer case. The infrastructure is usually fine. The application itself is the weakest link.

What we do differently

  • We test like an attacker

    Automated scanners find the obvious. We look for what they miss before somebody else does.

  • We fix, not just report

    A report with fifty findings helps nobody. We close the gaps and show they are closed.

  • Readable for non-technical people

    The report is written so data protection officers, management and auditors understand it.

  • No seal, no subscription

    We issue no certificates. We build software that survives an audit, at a fixed price.

The problem

The weakest link is the application.

Data centre security is inherited. Application security has to be built.

  • Attacks on the application

    A firewall does not stop a badly built input. If a form lets commands through to the database, the door is open no matter how secure the server is.

  • Outdated building blocks

    Every application consists of dozens of third-party libraries. Many of them have known holes nobody closed because nobody looked.

  • Audits that fail

    Investors, customers and authorities ask about the application, not just the server certificate. Anyone who can only show a provider seal then fails.

What gets checked

From the ten most common holes to your own rules.

We work through the known lists of the most common vulnerabilities and then go where your application is special.

The basis is the lists of the most common web vulnerabilities, the technical requirements of the GDPR and the requirements auditors place on applications under ISO 27001.

  1. Login and rights

    Can someone see other people’s data by changing a number in the address. Can passwords be guessed. Do you stay logged in when you should not.

  2. Inputs

    Forms, search fields, file uploads. Do commands get through to the database or into other users’ browsers.

  3. Building blocks and dependencies

    Which third-party libraries are in use, which have known holes, which are no longer maintained.

  4. Browser protection rules

    Rules that tell the browser which scripts may run and who may embed the page. If they are missing, the page is open to many attacks.

  5. Data and logs

    Where does personal data sit, who can reach it, what is logged. Is there a trail when something has happened.

  6. Servers and delivery

    Does everything run on the servers you think it does, or has someone started a service in a foreign cloud on the side.

How it runs

From the review to the documentation

  1. one meeting

    Conversation

    What should be checked, who needs the result, is there an upcoming audit or funding round. Then a fixed price.

  2. one to three weeks

    Review

    Infrastructure, application, building blocks, rights, logs. We try to get in, by agreement and with your permission.

  3. by scope

    Hardening

    We fix what we found: rebuild code, replace building blocks, set protection rules, set up logs.

  4. included

    Documentation

    A report with location, risk, fix and evidence. Written for data protection officers, auditors and investors.

Prices

Fixed price by scope.

The price depends on the size of the application and on whether we only review or also fix.

What you get

  • Review

    Review of the application, the building blocks, the rights and the servers. Report with locations, risk and recommendation.

    by quote
  • Review and hardening

    Plus the fixing of the findings and the evidence that they are closed.

    by quote
  • Repeat

    Annually or before an upcoming audit. Shorter because the state is known.

    by quote

All prices net. Technical review, not a certification and not legal advice.

Where it runs

Secure software on secure ground.

What we build runs at Hetzner in Nuremberg or Falkenstein. The data centres are ISO 27001 certified. The rest is construction.

  • Privacy from the start

    Only as much data as necessary, for as short as necessary, in Germany. Not afterwards, but at the design stage.

  • Hardened against the usual

    The most common web attacks are known. Our applications are built against them from the start, with strict protection rules in the browser.

  • Audit-ready

    Documents and logs you need to pass your own audit are part of the handover.

Related

Security is part of every service.

  • Custom software

    Built from the start so it survives an audit.

    See custom software
  • Website

    Static pages without plugins have practically no attack surface.

    See website
  • Monitoring

    Certificates, reachability and changes continuously in view.

    See monitoring
  • Tracking and privacy

    Cookie banner, consent and what goes to Google and Meta.

    See web tracking

Common questions

Review, permission, documentation.

Do you issue a certificate?

No. Certificates are issued by certification bodies. We make sure your application passes such an audit and deliver the documents for it.

Is the review dangerous for live operation?

We test by agreement, with your written permission, preferably on a test environment. Anything that could disturb operation is announced beforehand or left out.

What if you find something critical?

Then you hear about it immediately, not only in the report. Critical findings are closed first.

Is that enough for the GDPR?

The regulation requires appropriate technical measures. The review and the report are evidence of that. The legal assessment stays with your data protection officer.

How often should you review?

After major changes and once a year. Before a funding round or a customer audit in any case.

Next step

Find out where you really stand.

The provider is secure. Now let us make sure your application is too. Short conversation, then a fixed price.

Fixed price, readable report, fixing included if wanted.