Skip to content

Honest findings, not reassuring reports.

Every finding arrives with a reproducible attack path and a remediation step your own team can execute.

What you get

  • Critical gaps found before outsiders use them
  • Findings ranked by real danger, not by count
  • Compliance evidence ready for ISO 27001, SOC 2, or PCI-DSS
  • Your own team learns how to close them, not just receives a list

Capabilities

What this covers

AI System Security Testing

The assistant you deployed can be hijacked. We prove it first.

  • Tested for whether it can be coaxed into leaking customer data
  • Tested for whether its limits of authority can be exceeded
  • Tested against instructions embedded in documents and incoming messages
  • Every finding comes with a reproduction, not just a warning
  • Fixes your own team can carry out

Typical scope

  • AI system security test

    Testing whether an assistant can be coaxed into leaking data, exceeding its authority, or obeying instructions an outsider slipped in.

    • Tested against instructions embedded in documents and messages
    • Tested for whether customer data can be drawn out
    • Tested for whether its limits of authority can be exceeded

    Typical duration: 1–2 weeks

  • AI agent & assistant security test

    Testing AI-driven systems: instructions smuggled in through outside text, cross-user data leakage, agents talked past their authority, and costs an attacker can force upward.

    • Injection through documents, email, and web pages
    • Cross-user and cross-tenant data leakage
    • Talking an agent past its authority limits

    Typical duration: 2–3 weeks

Request consultation

Talk to us about scope and pricing.

Fractional CISO

Security leadership without a full-time hire.

  • Prospects’ security questionnaires answered quickly, not left for weeks
  • Priorities set by real danger, not by the length of the list
  • Present when auditors and large customers start asking
  • A fraction of the cost of a full-time hire
  • Can be stopped at any time with no employment complications

Typical scope

  • Fractional CISO

    A few days a month setting priorities, answering prospects’ security questionnaires, and sitting through audits.

    • Prospects’ security questionnaires answered quickly
    • Priorities set by real danger
    • Present when auditors and large customers ask

    Typical duration: Monthly

  • Fractional CISO

    A security lead present a few days a month: setting the plan, answering client and regulator questionnaires, leading during incidents, and blocking decisions that will hurt a year from now.

    • A security plan ordered by risk, not by trend
    • Answering client and regulator questionnaires
    • Leading during incidents

    Typical duration: Ongoing

Request consultation

Talk to us about scope and pricing.

Incident Response

Once it has happened: contained, traced, then reported.

  • Containment first, so the damage stops spreading
  • An answer to the question everyone dreads: what data was actually taken
  • The mandatory 72-hour report drafted for you, not handed back
  • Evidence preserved properly from the outset, before it is overwritten
  • A tabletop exercise so the next incident is less panicked than the first

Typical scope

  • Emergency breach response

    Containment so it stops spreading, forensics on what was actually taken, and drafting the mandatory 72-hour report.

    • Containment first, so the damage stops spreading
    • An answer to: what data was actually taken
    • The mandatory 72-hour report drafted for you

    Typical duration: Minimum 3 days

  • 72-hour incident readiness

    Written procedures, escalation paths, and a quarterly tabletop exercise so the first incident is not met with panic.

    • Written procedures that can actually be followed under pressure
    • Escalation paths with names and numbers, not just job titles
    • A quarterly tabletop exercise

    Typical duration: Monthly

  • Incident response retainer

    A number to call when things go wrong, staffed by people who already know your architecture — not a team starting to read while the first hour burns.

    • A written response time
    • A team that knows your systems before the incident
    • Help drafting the regulator report

    Typical duration: Ongoing

  • Post-incident forensics & recovery

    Establishing what actually happened: how they got in, how far they went, what data was touched, and whether they are still inside.

    • An evidence-based timeline
    • The true scope of data touched
    • Closing the entry path and evicting the attacker

    Typical duration: 2–6 weeks

Request consultation

Talk to us about scope and pricing.

Security Engineering

Defences designed, tested, then proven.

  • Identify vulnerabilities before attackers exploit them
  • Compliance with global standards (ISO 27001, PCI DSS)
  • Comprehensive technical and executive reports
  • Step-by-step remediation guidance
  • Testing with zero downtime – no operational disruption
  • Internationally certified team (OSCP, CEH)

Typical scope

  • Supply chain & release pipeline security

    An inventory of third-party components, flags on the vulnerable ones, and scanning of code and secrets before production.

    • A component inventory with versions
    • Vulnerable components flagged and ranked by danger
    • Accidentally committed secrets found

    Typical duration: 3–6 weeks

  • Phishing simulation & awareness training

    A phishing campaign written to look like your company’s real correspondence, followed by short training for those who fell for it — not an annual lecture for everyone.

    • Emails written to mirror your real correspondence
    • Click rate per department, not a company average
    • Short training only for those who need it

    Typical duration: 3 weeks

Request consultation

Talk to us about scope and pricing.

Vulnerability Assessment

A complete list of weak points, ranked by real danger.

  • Each period compared with the last rather than standing alone as a report
  • Open findings from earlier periods carried forward until genuinely closed
  • Runs without taking live services offline
  • Periodic evidence ready for auditors without a last-minute scramble
  • Faster warning when a newly exploited flaw appears in the wild

Typical scope

  • Attack surface review

    An inventory of what of yours is visible from the internet, and which of it should not be.

    • A list of externally visible services
    • Flags on what should not be exposed
    • Forgotten legacy systems still switched on

    Typical duration: 3 days

  • Recurring vulnerability assessment

    A monthly recurring assessment with period-on-period comparison: what improved, what is new.

    • Period-on-period comparison, not standalone reports
    • Old unclosed findings carried forward as reminders
    • Periodic evidence for audit purposes

    Typical duration: Monthly, six-month minimum

  • Secure code & supply-chain review

    Reading the source on the paths that matter — login, authorisation, money, and uploads — plus a review of the third-party libraries that ship to production with it.

    • Manual reading of login, authorisation, and money paths
    • Third-party library review including release age
    • Secrets left behind in code history

    Typical duration: 3–5 weeks

Request consultation

Talk to us about scope and pricing.

Penetration Testing

We attack your systems first, before anyone else does.

  • A report you can hand to prospects and auditors alike
  • Every finding carries an attack path that can be reproduced
  • Findings ranked by real danger rather than by count
  • One retest after fixes included, not billed separately
  • Rules of engagement agreed in writing first, including how to halt testing

Typical scope

  • Web & API penetration test — one target

    A real attacking test of the application, with a report you can hand to prospects, plus one retest.

    • A report you can hand to prospects and auditors
    • Every finding carries a reproduction, not just a warning
    • One retest after fixes is included

    Typical duration: 2 weeks

  • Full attack simulation

    An attack resembling a real adversary, unannounced to the internal team, to test detection and response.

    • The internal team is not told — as in a real event
    • Tests detection and response, not just the gaps
    • Rules of engagement agreed in writing beforehand

    Typical duration: Diagnosis first

  • Web application penetration test

    Hands-on testing of your web application: account takeover, cross-user authorisation flaws, injection, malicious upload, and payment flows. Not a scanner report pasted into a document.

    • Manual testing, not scanner output
    • Step-by-step proof for every finding
    • Ranked by real business impact, not raw score

    Typical duration: 2–3 weeks

  • API penetration test

    Endpoint-level testing: object-level authorisation, identifier enumeration, rate limiting, data leaking in responses, and keys that reach further than they should.

    • Cross-role and cross-tenant authorisation testing
    • Rate limiting and quota abuse checks
    • Data leaking through error responses

    Typical duration: 2 weeks

  • Internal network penetration test

    Simulating an attacker already inside your network — from one employee laptop, how far they can move, escalate, and reach core systems.

    • Movement path from entry point to core systems
    • Domain privilege escalation
    • Network segmentation weaknesses

    Typical duration: 3–4 weeks

Request consultation

Talk to us about scope and pricing.

Cloud Security

Servers and data on AWS or Azure sealed properly.

  • Over-broad permissions found and narrowed to what is genuinely used
  • Storage accidentally left open to the public, closed
  • Monitoring installed as part of the work, not recommended on a report’s last page
  • Checks that run on every change, so the environment stays tidy after we leave
  • Configuration evidence ready for ISO 27001, SOC 2, or PCI-DSS

Typical scope

  • Cloud security — one environment

    Assessment and hardening of one AWS, Azure, or GCP environment, with monitoring afterwards.

    • Over-broad permissions found and narrowed
    • Accidentally public storage closed
    • Monitoring installed, not merely recommended

    Typical duration: 2 weeks

  • Cloud security configuration review

    Reviewing AWS, GCP, or Azure configuration: open storage, over-broad permissions, keys never rotated, and audit logging that turns out to be switched off.

    • Publicly reachable storage and databases
    • Excess permissions and keys never rotated
    • Audit logging: on, retained, and long enough

    Typical duration: 2 weeks

Request consultation

Talk to us about scope and pricing.

Identity & Directory Security

One compromised account must not open the whole office.

  • Accounts of departed staff that are still active, found and disabled
  • Excess permissions mapped person by person rather than described in general terms
  • Escalation paths to administrator rights genuinely tested, then shown to you where they work
  • A leaver account-disabling procedure drawn up so it does not recur
  • Monitoring installed along with an answer to who gets called when an alert fires

Typical scope

  • Corporate account security

    A review of the corporate account directory: permissions, privileged accounts, and old accounts never disabled.

    • Dormant-but-active accounts identified
    • Excess permissions mapped person by person
    • Escalation paths to administrator rights tested

    Typical duration: 2 weeks

Request consultation

Talk to us about scope and pricing.

Mobile Application Testing

iOS and Android apps probed the way a real attacker would.

  • Both Android and iPhone tested, not one with the other assumed to match
  • Data stored on the device prised open too — the place most often overlooked
  • Third-party libraries bundled inside the app examined as well
  • Every finding arrives with a reproduction, not merely a warning
  • Safe patterns handed to your team so the same mistake does not recur

Typical scope

  • Mobile app security test

    Testing of the Android and iPhone apps, including the third-party libraries bundled inside them.

    • Both Android and iPhone tested
    • Third-party libraries examined too
    • On-device stored data prised open as well

    Typical duration: 2 weeks

  • Mobile application penetration test

    Android and iOS testing: on-device storage, keys embedded in the bundle, traffic interception, certificate pinning, and behaviour on a rooted or jailbroken device.

    • On-device storage review
    • Hunting for keys and secrets inside the bundle
    • Interception and certificate pinning tests

    Typical duration: 2–3 weeks

Request consultation

Talk to us about scope and pricing.

Audit & Compliance

Guided all the way to ISO 27001, SOC 2, or PCI-DSS.

  • The distance from where you are to ISO 27001 or SOC 2 measured, not estimated
  • A prioritised work list with time and cost estimates attached
  • Evidence assembled along the way, not crammed together before the auditor arrives
  • Policies written to be followed rather than filed
  • Support that continues through to the following year’s surveillance audit

Typical scope

  • Audit readiness

    The gap between where you are and ISO 27001 or SOC 2, with a work list already prioritised.

    • A prioritised work list
    • Time and cost estimates to certification
    • What is already satisfied is recorded too, not just the gaps

    Typical duration: 1–2 weeks

  • Certification support

    Support through to ISO 27001, SOC 2, or PCI-DSS, including preparing the evidence auditors ask for.

    • Evidence assembled along the way, not crammed at the end
    • Policies written to be followed, not to be filed
    • Support during the auditor’s visit

    Typical duration: 3–9 months

  • Indonesian data protection law readiness review

    A full review against Indonesia’s personal data protection obligations: lawful basis, access audit trails, retention limits, data-subject request routes, and the 72-hour breach notification procedure.

    • A personal-data map: what is held, where, and for how long
    • Gap analysis against each obligation
    • A 72-hour breach notification procedure ready to run

    Typical duration: 3 weeks

  • ISO/IEC 27001 readiness programme

    Bringing an information security management system to the point where a certification body can audit it: scope, risk assessment, policies, evidence of operation, and internal audit.

    • Scope set as wide as needed and no wider
    • Risk assessment and statement of applicability
    • Policies that are actually used, not shelf documents

    Typical duration: 4–8 months

  • Financial regulator incident reporting readiness

    Building the detection, assessment, and reporting path so a 24-hour regulator deadline can actually be met — including who decides, what is reported, and who signs.

    • Thresholds: which events must be reported
    • Roles and signing authority
    • A pre-filled report template

    Typical duration: 3 weeks

Request consultation

Talk to us about scope and pricing.

Questions we are asked most

What is the difference between a penetration test and a vulnerability assessment?

A vulnerability assessment catalogues and ranks weaknesses broadly. A penetration test tries to actually break through them to see how far an attacker could get. The first answers "what is weak"; the second answers "how bad it is when someone uses it".

How long does a security audit take?

Two weeks per target, counted from the moment scope and testing authorisation are agreed in writing. The report arrives at the end, and one retest after your fixes is included — not billed as new work.

Can we share the report with other parties?

Yes, and it is often used that way — our reports are written to be handed to prospects, auditors, or investors. They come in two layers: a summary a board can read, and a technical annex for your team. We never disclose findings to anyone without your written permission.

What happens once a gap is found?

Every finding arrives with a reproduction and a remediation step your own team can carry out. Findings are ranked by real danger rather than by count — a long unprioritised list is how the most dangerous item ends up waiting its turn.

Do you also support us through to certification?

Yes, for ISO 27001, SOC 2, and PCI-DSS. Evidence is assembled along the way rather than crammed together before the auditor arrives, and policies are written to be followed rather than filed.

When is a recurring assessment better than a one-off?

When your systems change every month. Testing once a year leaves eleven months in which nobody knows the state of things. A recurring assessment compares each period with the last, and carries forward findings that are still open.

How long does one round take?

About two working days a month for a settled scope, with results in the same week. Nothing needs to be taken offline; the assessment runs without disturbing live services.

Do we receive a certificate?

What we issue is a dated report with the testing evidence behind it, and that is what auditors and prospects actually ask for. A formal certificate can only be issued by an accredited certification body — we support you through to that point but do not issue one ourselves, and anyone claiming otherwise is worth doubting.

How we engage

Choose the engagement that fits where you are

Not every piece of work belongs in a big project. These four are what we normally use — scope and duration agreed before anything starts.

  • Rapid assessment

    Find out what is actually broken before committing a large budget.

    1–2 weeks

    • Interviews with the people who actually run the process
    • A count of the hours and money currently being lost
    • Findings ranked by real cost, not by volume
    • A staged recommendation with time and cost estimates

    Best when: You know something is wrong, but not yet which part is costing you most.

  • Fixed-scope project

    The outcome, the date, and the scope agreed up front.

    4 weeks – 8 months

    • A written scope, a delivery date, and agreed acceptance criteria
    • A demo every two weeks — you watch progress instead of waiting for news
    • Testing plus hand-over of the code and its documentation
    • A warranty period for fixes after the system goes live

    Best when: The need is already clear and you want budget certainty.

  • Dedicated team

    Our team works full time for you, following your priorities.

    From 3 months

    • A standing team: engineering, testing, and one accountable lead
    • You set the priorities, reviewed every two weeks
    • Working Indonesian hours, adjustable to your time zone
    • Scaled up or down month by month

    Best when: The roadmap is long and priorities will still shift along the way.

  • Monthly retainer

    A live system kept running, updated, and watched.

    Monthly, cancel any time

    • Monitoring, backups, and security updates
    • A fixed block of hours each month for fixes and small features
    • An agreed response time when something goes wrong
    • A monthly report on what was done and what needs deciding

    Best when: The system is live and you would rather not wait until it breaks.

  • The code and documentation become yours
  • An NDA from the first conversation
  • A post-release fix warranty
  • Progress reported every two weeks
  • No vendor lock-in — another team can take over

Talk through cybersecurity for your organisation

One conversation is enough to know whether this is worth doing now or later.