The people who do the work
Security architects and engineers who focus on SaaS platforms, led by a consultant with 15 years in the industry. You’ll meet us on the scoping call.
Request a scoping callBetween us we hold CISSP and ISO 27001 Lead Auditor certifications, and we’ve worked hands-on in AWS, Azure and Google Cloud.
Sanskrit for the opening of the eyes. That’s what an assessment does for your company: you see who and what can reach your data and your customers’ before you decide what to fix.
Scale with your eyes open.
Where our experience comes from
What we did in earlier roles, and the part of a platform each piece helps with. We focus on multi-tenant SaaS now, after years in fintech, banking and healthcare. We don’t name employers, clients or products.
Platform design reviews
Web app and API
Security architecture reviews of SaaS and cloud platforms, from how customers are kept apart to how data moves. Our team signed off once the serious findings were closed.
Application and API testing
Web app and API
Threat modelling, hands-on testing and design reviews of cloud services, APIs, mobile apps and databases.
Multi-cloud visibility
Cloud account
One place to see every account, identity and security setting across AWS, Azure and Google Cloud, wired into policy reviews and releases.
Detection and response
Cloud account
Alert rules and investigation steps built on cloud, device, server and Microsoft 365 logs, used from the first alert to the clean-up.
Supply-chain incidents
Packages and pipeline
Investigation support for several organisations after a software supplier was compromised, from building the timeline to helping them recover. It informs how we look at pipelines and third-party code.
Data protection at scale
Your team
Wrote and rolled out the rules for labelling and protecting a large company’s sensitive files.
See how we work first
The report and the design example are fictional, written the way we’d write them for you.
- Our sample reportTen findings on a made-up billing company, each with what fixed looks like.
- A design example: replacing a stored cloud keyHow an app can read its data in another cloud without a key anyone could copy.
- Our notesWhat we’d check first in each part of a platform, and what to ask any provider.
Meet us on a free call
Tell us a little about your platform and we’ll set up a free 30-minute scoping call. Leave out passwords and customer data. We reply within one working day.
