Services

Security that earns trust.

Service made concrete. We help organisations find their weaknesses before attackers do, and get ready for the standards their customers and regulators expect — because keeping people safe is one of the clearest ways to serve them.

Offensive security

Vulnerability assessment & penetration testing.

We test your systems the way a real attacker would — methodically, and only with your written permission — then hand you a plain-English report you can actually act on. Every engagement is scoped to your environment and run in line with recognised methodologies (OWASP, PTES, NIST).

Web & API penetration testing

The apps and APIs your business runs on.

  • OWASP Top 10 and business-logic flaws
  • Authentication, authorisation & session testing
  • REST and GraphQL API abuse cases
  • Findings ranked by real-world risk

Network & infrastructure testing

Your internal and external attack surface.

  • External perimeter and internal network testing
  • Misconfigurations, weak services & patch gaps
  • Privilege-escalation and lateral-movement paths
  • Segmentation and exposure review

Cloud & configuration review

AWS, Azure and GCP, properly hardened.

  • Identity & access (IAM) review
  • Storage, network and secrets exposure
  • Benchmark-aligned configuration checks
  • Practical, prioritised hardening steps

Compliance readiness

ISO 27001 & 27701 readiness.

Certification starts long before the auditor arrives. We get you audit-ready — mapping where you stand today, closing the gaps, and translating the standard into plain English your team can own and maintain. We prepare you for certification; we are not a certification body.

ISO/IEC 27001 readiness

Your information security management system, audit-ready.

  • Gap assessment against the standard
  • Risk assessment & Statement of Applicability
  • Policies, controls and evidence you can sustain
  • Guidance right up to your certification audit

ISO/IEC 27701 readiness

Privacy, built on top of your ISMS.

  • Privacy information management (PIMS) extension
  • Mapping to POPIA and GDPR obligations
  • Controller and processor controls
  • A privacy programme your customers can trust

How an engagement works.

01

Scope

We agree exactly what's tested, when, and the rules of engagement — in writing, before anything begins.

02

Test

We assess your systems methodically and safely, flagging anything urgent the moment we find it.

03

Report

You get a clear report: what we found, why it matters, and how to fix it — ranked by real risk, not jargon.

04

Remediate

We walk your team through every finding and stay available while you close the gaps.

05

Retest

We verify your fixes actually worked — so you finish with proof, not just a to-do list.

What you walk away with.

01

A report you can use

Written for engineers and the board alike — technical detail and an executive summary in one place.

02

Risk-ranked findings

Every issue prioritised by real-world impact, so you fix what matters first.

03

Remediation guidance

Not just what's wrong — clear, practical steps to put it right.

04

A retest, included

Verification that your fixes hold, built into the engagement.

Let's find the gaps before someone else does.

Tell us what you're protecting and we'll scope the right engagement — no obligation, no jargon, just a conversation with the person who does the work.

Book a scoping call