Services
Two specialities,and the workaround them.
Managed bug bounty triage and penetration testing come first. The rest is there when the problem is bigger than a single test.
Managed bug bounty triage
Every report validated, rated and written up before it reaches your engineers.- Platform programmes
- Self-hosted programmes
- Programmes you have not launched yet
Penetration testing and security assessment
Manual, depth-first testing of applications, APIs, networks and cloud.- Web applications
- APIs
- Networks and infrastructure
- Cloud
- Ad hoc VAPT
- Red team exercises
Vulnerability and programme management
Ongoing assessment, prioritisation and remediation tracking on an agreed cycle.- Vulnerability management
- Security programme support
Governance, risk and compliance
Regulatory alignment, risk management and compliance framework implementation.ISO 27001 and Cyber Essentials Plus readiness / Regulatory compliance advisory / Third party risk management / Board level risk reportingSecurity architecture and implementation
Security design, deployment guidance and infrastructure hardening.Cloud security architecture / Zero trust architecture / Security tool consolidationAdvisory and strategic services
Fractional security leadership and specialist consulting.Virtual CISO (vCISO) / M&A security due diligence / Compliance gap analysis / Cyber insurance readiness