Security · Review and hardening · Fixed price
Your provider is certified. Your code is not. We find where attackers get in and close the door.
The data centre has access control and a certificate. The firewall runs. And still: a login form built wrongly lets anyone into the database. An outdated library opens the door. No provider certificate helps against that.
We test your website or application the way an attacker would, fix what we find and write it up so your data protection officer, an auditor or an investor can read it. No seal, but software that survives an audit.
Fixed price after a short conversation. Results as a readable report with location and fix. Technical review, not a certification and not legal advice.
Typical findings
- Data centre
- certified, inherited
- Encryption
- fine
- Login
- database exposed
- Libraries
- 14 outdated
- Browser protection rules
- missing
- Logs
- none
Example, not a customer case. The infrastructure is usually fine. The application itself is the weakest link.
What we do differently
-
We test like an attacker
Automated scanners find the obvious. We look for what they miss before somebody else does.
-
We fix, not just report
A report with fifty findings helps nobody. We close the gaps and show they are closed.
-
Readable for non-technical people
The report is written so data protection officers, management and auditors understand it.
-
No seal, no subscription
We issue no certificates. We build software that survives an audit, at a fixed price.
The problem
The weakest link is the application.
Data centre security is inherited. Application security has to be built.
-
Attacks on the application
A firewall does not stop a badly built input. If a form lets commands through to the database, the door is open no matter how secure the server is.
-
Outdated building blocks
Every application consists of dozens of third-party libraries. Many of them have known holes nobody closed because nobody looked.
-
Audits that fail
Investors, customers and authorities ask about the application, not just the server certificate. Anyone who can only show a provider seal then fails.
What gets checked
From the ten most common holes to your own rules.
We work through the known lists of the most common vulnerabilities and then go where your application is special.
The basis is the lists of the most common web vulnerabilities, the technical requirements of the GDPR and the requirements auditors place on applications under ISO 27001.
-
Login and rights
Can someone see other people’s data by changing a number in the address. Can passwords be guessed. Do you stay logged in when you should not.
-
Inputs
Forms, search fields, file uploads. Do commands get through to the database or into other users’ browsers.
-
Building blocks and dependencies
Which third-party libraries are in use, which have known holes, which are no longer maintained.
-
Browser protection rules
Rules that tell the browser which scripts may run and who may embed the page. If they are missing, the page is open to many attacks.
-
Data and logs
Where does personal data sit, who can reach it, what is logged. Is there a trail when something has happened.
-
Servers and delivery
Does everything run on the servers you think it does, or has someone started a service in a foreign cloud on the side.
How it runs
From the review to the documentation
-
one meeting
Conversation
What should be checked, who needs the result, is there an upcoming audit or funding round. Then a fixed price.
-
one to three weeks
Review
Infrastructure, application, building blocks, rights, logs. We try to get in, by agreement and with your permission.
-
by scope
Hardening
We fix what we found: rebuild code, replace building blocks, set protection rules, set up logs.
-
included
Documentation
A report with location, risk, fix and evidence. Written for data protection officers, auditors and investors.
Prices
Fixed price by scope.
The price depends on the size of the application and on whether we only review or also fix.
What you get
- by quote
Review
Review of the application, the building blocks, the rights and the servers. Report with locations, risk and recommendation.
- by quote
Review and hardening
Plus the fixing of the findings and the evidence that they are closed.
- by quote
Repeat
Annually or before an upcoming audit. Shorter because the state is known.
All prices net. Technical review, not a certification and not legal advice.
Where it runs
Secure software on secure ground.
What we build runs at Hetzner in Nuremberg or Falkenstein. The data centres are ISO 27001 certified. The rest is construction.
-
Privacy from the start
Only as much data as necessary, for as short as necessary, in Germany. Not afterwards, but at the design stage.
-
Hardened against the usual
The most common web attacks are known. Our applications are built against them from the start, with strict protection rules in the browser.
-
Audit-ready
Documents and logs you need to pass your own audit are part of the handover.
Related
Security is part of every service.
-
Custom software
Built from the start so it survives an audit.
See custom software -
Website
Static pages without plugins have practically no attack surface.
See website -
Monitoring
Certificates, reachability and changes continuously in view.
See monitoring -
Tracking and privacy
Cookie banner, consent and what goes to Google and Meta.
See web tracking
Common questions
Review, permission, documentation.
Do you issue a certificate?
No. Certificates are issued by certification bodies. We make sure your application passes such an audit and deliver the documents for it.
Is the review dangerous for live operation?
We test by agreement, with your written permission, preferably on a test environment. Anything that could disturb operation is announced beforehand or left out.
What if you find something critical?
Then you hear about it immediately, not only in the report. Critical findings are closed first.
Is that enough for the GDPR?
The regulation requires appropriate technical measures. The review and the report are evidence of that. The legal assessment stays with your data protection officer.
How often should you review?
After major changes and once a year. Before a funding round or a customer audit in any case.
Next step
Find out where you really stand.
The provider is secure. Now let us make sure your application is too. Short conversation, then a fixed price.
Fixed price, readable report, fixing included if wanted.