Services
Security that earns trust.
Service made concrete. We help organisations find their weaknesses before attackers do, and get ready for the standards their customers and regulators expect — because keeping people safe is one of the clearest ways to serve them.
Offensive security
Vulnerability assessment & penetration testing.
We test your systems the way a real attacker would — methodically, and only with your written permission — then hand you a plain-English report you can actually act on. Every engagement is scoped to your environment and run in line with recognised methodologies (OWASP, PTES, NIST).
Web & API penetration testing
The apps and APIs your business runs on.
- OWASP Top 10 and business-logic flaws
- Authentication, authorisation & session testing
- REST and GraphQL API abuse cases
- Findings ranked by real-world risk
Network & infrastructure testing
Your internal and external attack surface.
- External perimeter and internal network testing
- Misconfigurations, weak services & patch gaps
- Privilege-escalation and lateral-movement paths
- Segmentation and exposure review
Cloud & configuration review
AWS, Azure and GCP, properly hardened.
- Identity & access (IAM) review
- Storage, network and secrets exposure
- Benchmark-aligned configuration checks
- Practical, prioritised hardening steps
Compliance readiness
ISO 27001 & 27701 readiness.
Certification starts long before the auditor arrives. We get you audit-ready — mapping where you stand today, closing the gaps, and translating the standard into plain English your team can own and maintain. We prepare you for certification; we are not a certification body.
ISO/IEC 27001 readiness
Your information security management system, audit-ready.
- Gap assessment against the standard
- Risk assessment & Statement of Applicability
- Policies, controls and evidence you can sustain
- Guidance right up to your certification audit
ISO/IEC 27701 readiness
Privacy, built on top of your ISMS.
- Privacy information management (PIMS) extension
- Mapping to POPIA and GDPR obligations
- Controller and processor controls
- A privacy programme your customers can trust
How an engagement works.
Scope
We agree exactly what's tested, when, and the rules of engagement — in writing, before anything begins.
Test
We assess your systems methodically and safely, flagging anything urgent the moment we find it.
Report
You get a clear report: what we found, why it matters, and how to fix it — ranked by real risk, not jargon.
Remediate
We walk your team through every finding and stay available while you close the gaps.
Retest
We verify your fixes actually worked — so you finish with proof, not just a to-do list.
What you walk away with.
A report you can use
Written for engineers and the board alike — technical detail and an executive summary in one place.
Risk-ranked findings
Every issue prioritised by real-world impact, so you fix what matters first.
Remediation guidance
Not just what's wrong — clear, practical steps to put it right.
A retest, included
Verification that your fixes hold, built into the engagement.
Let's find the gaps before someone else does.
Tell us what you're protecting and we'll scope the right engagement — no obligation, no jargon, just a conversation with the person who does the work.
Book a scoping call