04Security Audits
Findings you can act on, ranked by what actually matters.
A structured assessment of your application, API surface, cloud configuration and architecture — delivered as reproducible findings with a remediation path, not a tool export.
01Where it starts
What we usually walk into.
Automated scans produce volume, not clarity. Teams receive hundreds of findings without exploitability context, business impact or a realistic fix, and the important issues get lost.
We have a scanner report and no idea which twelve of these four hundred findings matter.
We are about to launch and have never had the system reviewed.
A customer requires an independent assessment before signing.
We changed cloud providers and are not sure what is exposed.
We had an incident and need to know whether the same class of issue exists elsewhere.
02Approach
How we do the work.
Manual, architecture-aware assessment supported by tooling. Every finding is reproduced, rated for exploitability and business impact, and paired with a specific remediation.
- 01
Scope written down, in both directions
What is in scope, what is explicitly out, what techniques are permitted, and who to call if something breaks. Authorisation is confirmed in writing before any testing begins.
- 02
Manual review where it counts
Tooling covers breadth: dependencies, known CVEs, obvious misconfiguration. Humans cover depth: business logic, authorisation, workflow abuse and trust-boundary failures — the issues scanners cannot express.
- 03
Every finding reproduced
Each finding includes the exact steps to reproduce it, the evidence, the affected component and the conditions required. If we cannot reproduce it, it is reported as an observation, not a finding.
- 04
Rated by exploitability and impact
A theoretical high severity behind three authentication layers ranks below a medium that any authenticated user can trigger. We rate what it means for your business, and say so.
Capabilities and deliverables
Capabilities
- Web application and API assessment
- Authentication and session management review
- Authorisation and access-control testing
- Cloud configuration and IAM review
- Infrastructure-as-code review
- Dependency and supply-chain analysis
- Mobile application assessment
- Architecture and trust-boundary review
What you receive
- Executive summary written for non-technical decision-makers
- Technical findings with reproduction steps, evidence and affected components
- Risk rating combining exploitability, business impact and exposure
- Specific remediation guidance per finding, with effort estimates
- Architectural observations — the systemic causes behind repeated findings
- Remediation verification re-test after fixes are applied
Common use cases
- Pre-launch application and API assessment
- Cloud configuration and identity review
- Authentication and authorisation assessment
- Third-party and dependency risk review
- Technical due diligence for investment or acquisition
- Periodic assessment as part of a security programme
Technologies typically involved
- Burp Suite
- OWASP ZAP
- Semgrep
- Trivy
- Nuclei
- Terraform
- Kubernetes
- AWS IAM
- Azure Entra ID
03Engagement
How it runs.
- 01
Scope & authorisation
3–5 days
Written scope, rules of engagement, testing window and escalation contacts.
- 02
Assessment
1–3 weeks
Automated coverage plus manual review across the agreed surface.
- 03
Reporting
1 week
Findings walkthrough with engineering, executive briefing for leadership.
- 04
Re-test
After remediation
Verification of remediated findings and an updated report.
04Security
Security considerations.
These apply to this service specifically. They are engagement conditions, not aspirations, and we will put them in the contract.
- Testing proceeds only under a signed authorisation covering the exact scope
- No destructive techniques, no denial-of-service testing, no testing outside the agreed window
- Findings are encrypted at rest and shared only with named recipients
- Evidence is destroyed on an agreed schedule after the engagement closes
05Outcomes
What changes afterwards.
A short, ordered list of what to fix first, evidence you can show a customer or auditor, and a re-test that confirms the fix.
- 01
A ranked, finite list of work rather than an undifferentiated backlog
- 02
Evidence that satisfies customer security reviews and internal governance
- 03
Systemic causes identified, so the same class of issue stops recurring
- 04
Verified closure through re-test, not self-declared
06Questions
Asked before every engagement.
A focused application or API assessment typically runs one to two weeks. A broader review covering cloud configuration, identity and multiple services runs three to four. Scope determines duration, and we give you a fixed window before we start.
We prefer a production-equivalent environment. Where production testing is necessary, we agree a window, avoid destructive techniques entirely, and stay reachable throughout. Denial-of-service testing is never part of our scope.
Yes. We produce a shareable summary alongside the detailed technical report, so you can evidence the assessment without disclosing exploitable specifics.
One remediation verification round is included in the standard engagement. It matters: a finding is not closed because a ticket was closed.
Frequently runs alongside
Ready to scopesecurity audits?
Bring the problem, the constraints and the deadline. We will tell you what is achievable, what it costs and what we would do first.