Security Audit Report
We conducted a comprehensive audit, penetration testing, and ISO 27001 implementation for a SaaS client.
- Security testing
- Audit
Portfolio
50 projects across sectors. Client names are withheld under confidentiality agreements.
We conducted a comprehensive audit, penetration testing, and ISO 27001 implementation for a SaaS client.
We conducted manual red teaming and exploitation of APIs and mobile apps for a finance client.
Performed large-scale infrastructure vulnerability scanning for an enterprise client using Nessus and Nmap.
Performed SAST and DAST on a SaaS application before release.
Conducted OWASP Top 10 vulnerability testing on an e-commerce platform.
Evaluated customer database configuration and access controls using custom scripts and Nessus for a financial client.
Performed comprehensive security assessment across all layers of a medical system using OpenVAS and Metasploit.
Security assessment aligned with national regulations for a government client, using Qualys and Nessus.
Performed post-patch vulnerability revalidation for a technology client using Burp Suite and Nmap.
Simulated external attacks on the enterprise network using Metasploit and Nmap.
Simulated lateral movement and privilege escalation using BloodHound and Cobalt Strike for a finance client.
Conducted deep manual exploitation of the application’s business logic using Burp Suite Pro and custom scripts.
Tested API endpoints and authorization mechanisms for an e-commerce client using Postman and Burp Suite.
Conducted thorough penetration testing of web, API, and network systems for HIPAA compliance using Kali Linux and Metasploit.
Unannounced stealth attack simulation for a government client using Cobalt Strike and Empire.
Re-tested previous exploitation findings for a tech client using Burp Suite and Metasploit.
Assessed and implemented AWS Organizations for an enterprise client.
Hardened Azure AD and Storage for customer data using Azure Security Center and Defender.
Security policies aligned across AWS and Azure using Terraform and custom scripts for a finance client.
Automated cloud compliance checks for healthcare with AWS Config Rules and Lambda.
Implemented CloudWatch and GuardDuty to deliver real-time security alerting and monitoring for an e-commerce client.
Designed a secure cloud architecture from the start of migration, using CloudFormation and Terraform.
Created cloud incident playbooks and simulations using AWS Detective and Azure Sentinel.
Analyzed Active Directory attack paths for an enterprise client using BloodHound and custom scripts.
Implemented a tiered admin model and Privileged Access Management with Microsoft LAPS and GPO for a financial client.
Integrated Active Directory logs with SIEM using Splunk and Microsoft Defender for Identity for threat detection in a healthcare setting.
Investigated and restored a domain compromised by ransomware using forensic and Microsoft tools.
Performed strict ACL cleanup and permission delegation using BloodHound and PowerShell.
Implemented Microsoft LAPS and network segmentation for an enterprise client.
Audited and implemented CIS Benchmarks for Active Directory using Nessus.
Security testing and implementation of Keychain for a finance client using Frida and Burp Suite.
Tested and implemented code obfuscation for an e-commerce client using MobSF and Drozer.
Conducted end-to-end testing of a cross-platform healthcare app and its API using Postman and Burp Suite.
Provided secure coding training and integrated mobile SAST with SonarQube and GitLab CI.
Tested business logic and transaction data integrity for a finance client using Frida and custom scripts.
Tested SSL/TLS pinning implementation using Burp Suite and Wireshark.
Conducted security analysis of external libraries and SDKs for an e-commerce client, using MobSF and Dependency Check.
An automated messaging bot integrated with the store’s inventory and logistics systems.
Developed a customer support bot for a B2B SaaS platform using React, Node.js, and NLP.
A workflow automation system for logistics that uses APIs to retrieve shipping data and generate PDF documents.
Automated email marketing based on user behavior.
A workflow engine with integration powers a tiered approval system for corporate expenses.
Developed an LLM-based AI agent trained on the e-commerce company’s knowledge base.
Built a custom web dashboard that aggregates data from multiple POS systems for a restaurant chain.
Developed a React dashboard that visualizes sales data and marketing metrics for an e-commerce client.
Built a real-time multi-warehouse stock management system for a retail client using React, Node.js, and MongoDB.
Internal project management application for a creative agency, built with React, Node.js, and PostgreSQL.
Developed a Solidity smart contract with a reward algorithm and a React/Web3.js DApp dashboard for a crypto client.
Built a digital art marketplace on Polygon with lazy minting, using Solidity, Web3.js, and React.
Developed and audited custom smart contracts using Solidity on Ethereum for a blockchain client.
Describe what you need. We will share a realistic scope and timeline openly.