Back to Procurement Hub

Security & Compliance

Security is not
an afterthought here.

CEH-certified, OWASP-aligned, DoD 8570 compliant. Every application we build and every audit we deliver is backed by verifiable credentials and documented methodology.

Download Security Overview PDF
CEH
Certified Ethical Hacker
SEC+
CompTIA Security+ · DoD 8570
30+
Security audits completed
0
Post-audit critical incidents

Certifications

Active, verifiable security credentials.

Certification documentation available for vendor qualification on request. All certifications are current and in good standing.

CEH

Certified Ethical Hacker

EC-Council · ANSI Accredited · Certificate available on request

The CEH (ANSI) certification validates expertise in identifying vulnerabilities and weaknesses in target systems using the same knowledge and tools as a malicious hacker, but in a lawful and legitimate manner with documented methodology.

Domains covered: information security overview, attack detection, attack phases, hacking tools, malware, sniffers, social engineering, DoS/DDoS, session hijacking, web server attacks, SQL injection, web application hacking, wireless networks, evading IDS/firewalls, honeypots, cryptography.

Issuing Body
EC-Council
Accreditation
ANSI/ISO 17024
DoD Compliance
8570.01-M
Status
Active
SEC+

CompTIA Security+

CompTIA · DoD 8570.01-M Approved · Certificate available on request

Security+ is a globally recognised, vendor-neutral certification establishing the baseline skills necessary to perform core security functions. It meets DoD 8570.01-M requirements for IAT Level II and IAM Level I positions.

Domains covered: threats, attacks and vulnerabilities; technologies and tools; architecture and design; identity and access management; risk management; cryptography and PKI.

Issuing Body
CompTIA
Accreditation
ANSI/ISO 17024
DoD Level
IAT II / IAM I
Status
Active

Security Methodology

How we approach security on every engagement.

Security is not a phase or a checklist item. It is a continuous practice applied at every stage of every engagement.

01

Secure Development Lifecycle

Security requirements are defined at project scoping, not post-delivery. Authentication models, data protection strategies, and access control architectures are determined before the first line of code is written.

02

OWASP Top 10 Assessment

Every web application we build or audit is assessed against the current OWASP Top 10, the industry standard reference for web application security risk. This includes injection flaws, broken authentication, sensitive data exposure, XML external entities, broken access control, security misconfigurations, XSS, insecure deserialisation, known vulnerable components, and insufficient logging/monitoring.

03

Penetration Testing

For security audit engagements, we conduct active penetration testing, not just automated scanning. Black-box testing simulates an external attacker with no prior knowledge. White-box testing reviews the system with full code and architecture access. Both produce a prioritised findings report with reproduction steps and remediation guidance.

04

API Security Review

REST and GraphQL APIs are assessed for authentication bypass, broken object-level authorisation (BOLA), mass assignment vulnerabilities, rate limiting gaps, and data over-exposure. API fuzzing is applied to identify unexpected input handling failures.

05

Authentication & Session Management

Password hashing (bcrypt/Argon2), multi-factor authentication design, session token entropy and expiry, JWT implementation review, OAuth 2.0 / OIDC configuration review, and CSRF protection are all evaluated and remediated on every security engagement.

06

Remediation Delivery

Security audit engagements include a prioritised remediation report structured by severity (Critical, High, Medium, Low, Informational). Each finding includes a proof of concept, risk explanation, and specific remediation steps. We then optionally implement the fixes directly under the same contract.

Compliance Frameworks

Standards we align with and assess against.

OWASP Top 10

Aligned

The primary reference for web application security risks. Applied to every application we build and every security audit we deliver.

NIST CSF

Aligned

NIST Cybersecurity Framework. Our security audit deliverables reference NIST CSF categories for Identify, Protect, Detect, Respond, and Recover.

DoD 8570.01-M

Compliant

CompTIA Security+ meets DoD 8570 baseline requirements for IAT Level II and IAM Level I. Relevant for federal agency and defense contractor engagements.

GDPR / UK DPA

Compliant

Every UK and EU client engagement includes a GDPR Article 30 review, data processing inventory, and privacy-by-design architecture guidance as standard.

ISO/IEC 27001

Aligned

Security audit reports are structured to align with ISO 27001 control domains. Not currently ISO 27001 certified; alignment documented on request.

OWASP ASVS

Aligned

OWASP Application Security Verification Standard used as the reference framework for level-2 security assessments on higher-assurance contracts.

Security Tooling

Professional-grade tools on every audit.

Automated scanners are a starting point, not a conclusion. All tool output is validated and extended through manual testing before findings are reported.

Burp Suite Pro
Web App Testing
OWASP ZAP
Dynamic Scanner
Nmap
Network Scanning
Metasploit
Exploitation Framework
Wireshark
Traffic Analysis
SQLMap
SQL Injection Testing
Nikto
Web Server Scanner
Dirb / Gobuster
Directory Enumeration
Hydra
Authentication Testing
Snyk
Dependency Scanning
Trivy
Container Security
Semgrep
SAST / Code Review

Security in Development

Every build ships with security baked in.

These practices are applied as standard on every software development contract, not as add-ons or post-delivery reviews.

Parameterised queries to prevent SQL injection on all database interactions
bcrypt/Argon2 password hashing: never MD5, SHA-1, or unsalted hashes
CSRF tokens on all state-changing form submissions
Content Security Policy (CSP) headers configured at deployment
HTTPS enforced site-wide; HTTP Strict Transport Security (HSTS) configured
Role-based access control (RBAC) with principle of least privilege
Input validation and output encoding on all user-supplied data
Dependency vulnerability scanning on every project (Snyk / Composer audit)
Environment variable management: no secrets in source code or repositories
Rate limiting on all authentication endpoints and sensitive API routes

Data Protection

GDPR and UK DPA compliance as standard for all UK/EU clients.

Every application we deliver for UK or EU clients includes a GDPR Article 30 compliant data processing architecture and a privacy-by-design review.

  • · Data processing inventory and Article 30 record
  • · Privacy-by-design architecture review
  • · Data minimisation principles applied in schema design
  • · Retention policy implementation and automated deletion
  • · Subject Access Request (SAR) workflow design
  • · Data Processor agreement templates for third-party integrations

Incident Response

Post-delivery support includes security incident guidance.

All contracts include a post-launch support window. During this period, security incident response guidance is included at no additional cost.

  • · Immediate notification of any suspected security incidents
  • · Root cause analysis and remediation within agreed SLA
  • · GDPR Article 33 breach notification guidance (72-hour requirement)
  • · Post-incident review and hardening recommendations


Need our security credentials for a vendor qualification form?

Download the security overview PDF or contact us for certificate copies and documentation.

Download Security Overview PDF →