Security & Compliance
Security is not
an afterthought here.
CEH-certified, OWASP-aligned, DoD 8570 compliant. Every application we build and every audit we deliver is backed by verifiable credentials and documented methodology.
Download Security Overview PDFCertifications
Active, verifiable security credentials.
Certification documentation available for vendor qualification on request. All certifications are current and in good standing.
Certified Ethical Hacker
EC-Council · ANSI Accredited · Certificate available on request
The CEH (ANSI) certification validates expertise in identifying vulnerabilities and weaknesses in target systems using the same knowledge and tools as a malicious hacker, but in a lawful and legitimate manner with documented methodology.
Domains covered: information security overview, attack detection, attack phases, hacking tools, malware, sniffers, social engineering, DoS/DDoS, session hijacking, web server attacks, SQL injection, web application hacking, wireless networks, evading IDS/firewalls, honeypots, cryptography.
EC-Council
ANSI/ISO 17024
8570.01-M
Active
CompTIA Security+
CompTIA · DoD 8570.01-M Approved · Certificate available on request
Security+ is a globally recognised, vendor-neutral certification establishing the baseline skills necessary to perform core security functions. It meets DoD 8570.01-M requirements for IAT Level II and IAM Level I positions.
Domains covered: threats, attacks and vulnerabilities; technologies and tools; architecture and design; identity and access management; risk management; cryptography and PKI.
CompTIA
ANSI/ISO 17024
IAT II / IAM I
Active
Security Methodology
How we approach security on every engagement.
Security is not a phase or a checklist item. It is a continuous practice applied at every stage of every engagement.
Secure Development Lifecycle
Security requirements are defined at project scoping, not post-delivery. Authentication models, data protection strategies, and access control architectures are determined before the first line of code is written.
OWASP Top 10 Assessment
Every web application we build or audit is assessed against the current OWASP Top 10, the industry standard reference for web application security risk. This includes injection flaws, broken authentication, sensitive data exposure, XML external entities, broken access control, security misconfigurations, XSS, insecure deserialisation, known vulnerable components, and insufficient logging/monitoring.
Penetration Testing
For security audit engagements, we conduct active penetration testing, not just automated scanning. Black-box testing simulates an external attacker with no prior knowledge. White-box testing reviews the system with full code and architecture access. Both produce a prioritised findings report with reproduction steps and remediation guidance.
API Security Review
REST and GraphQL APIs are assessed for authentication bypass, broken object-level authorisation (BOLA), mass assignment vulnerabilities, rate limiting gaps, and data over-exposure. API fuzzing is applied to identify unexpected input handling failures.
Authentication & Session Management
Password hashing (bcrypt/Argon2), multi-factor authentication design, session token entropy and expiry, JWT implementation review, OAuth 2.0 / OIDC configuration review, and CSRF protection are all evaluated and remediated on every security engagement.
Remediation Delivery
Security audit engagements include a prioritised remediation report structured by severity (Critical, High, Medium, Low, Informational). Each finding includes a proof of concept, risk explanation, and specific remediation steps. We then optionally implement the fixes directly under the same contract.
Compliance Frameworks
Standards we align with and assess against.
OWASP Top 10
AlignedThe primary reference for web application security risks. Applied to every application we build and every security audit we deliver.
NIST CSF
AlignedNIST Cybersecurity Framework. Our security audit deliverables reference NIST CSF categories for Identify, Protect, Detect, Respond, and Recover.
DoD 8570.01-M
CompliantCompTIA Security+ meets DoD 8570 baseline requirements for IAT Level II and IAM Level I. Relevant for federal agency and defense contractor engagements.
GDPR / UK DPA
CompliantEvery UK and EU client engagement includes a GDPR Article 30 review, data processing inventory, and privacy-by-design architecture guidance as standard.
ISO/IEC 27001
AlignedSecurity audit reports are structured to align with ISO 27001 control domains. Not currently ISO 27001 certified; alignment documented on request.
OWASP ASVS
AlignedOWASP Application Security Verification Standard used as the reference framework for level-2 security assessments on higher-assurance contracts.
Security Tooling
Professional-grade tools on every audit.
Automated scanners are a starting point, not a conclusion. All tool output is validated and extended through manual testing before findings are reported.
Security in Development
Every build ships with security baked in.
These practices are applied as standard on every software development contract, not as add-ons or post-delivery reviews.
Data Protection
GDPR and UK DPA compliance as standard for all UK/EU clients.
Every application we deliver for UK or EU clients includes a GDPR Article 30 compliant data processing architecture and a privacy-by-design review.
- · Data processing inventory and Article 30 record
- · Privacy-by-design architecture review
- · Data minimisation principles applied in schema design
- · Retention policy implementation and automated deletion
- · Subject Access Request (SAR) workflow design
- · Data Processor agreement templates for third-party integrations
Incident Response
Post-delivery support includes security incident guidance.
All contracts include a post-launch support window. During this period, security incident response guidance is included at no additional cost.
- · Immediate notification of any suspected security incidents
- · Root cause analysis and remediation within agreed SLA
- · GDPR Article 33 breach notification guidance (72-hour requirement)
- · Post-incident review and hardening recommendations
Need our security credentials for a vendor qualification form?
Download the security overview PDF or contact us for certificate copies and documentation.
Download Security Overview PDF →