Applications audited before delivery
Full-stack development with threat modelling, code review and security testing built into the process rather than added at the end.
The challenge
Most development shops treat security as a final checkbox. We build it in and can show the evidence.
Scope — included and not included
Included
- Threat modelling at design
- Secure coding practices
- Code review
- Security testing before delivery
- Documentation and handover
Not included
- Ongoing feature development unless contracted
- Hosting and operations
- Third party integrations we cannot review
How it works
01
Requirements and threat model
What you need, and what could go wrong, designed in from the start.
02
Build
Secure coding practices, reviewed as it grows.
03
Review and test
Code review and security testing before anything ships.
04
Deliver with evidence
The application, plus the record that it was built this way.
What you receive
- →The application
- →Threat model
- →Code review record
- →Security test results
- →Handover documentation
What we need from you
- ·Requirements
- ·A product owner
- ·Access to integration endpoints
- ·Review availability
Timeline and engagement
Varies by scope. Project engagement, quoted per project.
Standards, methods and tooling
OWASP ASVSOWASP SAMMThreat modellingPortal hosted in Canada
Frequently asked questions