SECURE / SECURITY REVIEW

Check who can access your users’ data.

We review permissions, APIs, credentials, databases and payments, and can fix the problems we agree to address.

Discuss your project

Hiding a button doesn’t necessarily prevent someone from performing the action. We check what users and administrators can actually do by following requests to the code that reads or changes data.

Check permissions

We start with the rules: who may view, change or delete each resource? We test different accounts and roles, including attempts to access another organisation’s data, and check enforcement in the APIs.

  • Authentication, sessions and role changes
  • Tenant isolation and resource ownership
  • Administrative actions, exports and uploads

Examine credentials and integrations

We check where credentials are used, database permissions and calls to external services. For payments, we review event verification and how purchases or subscriptions are updated. Applicable OWASP guidance can inform the checks; this is not a security certification.

Explain the findings

We describe each issue and its possible effect on the product, distinguishing verified problems from questions needing more tests. You get the affected components and the fixes we recommend making first.

Fix and test again

If we agree on implementation, we test both the operations that should be blocked and the ones that should still work. If a fix changes a product rule, we agree on the intended behaviour first.

GET IN TOUCH

It works.
Let’s see if it’s ready for the real world.

Bugs, security, databases, performance, architecture and scalability: find what could become a problem before your users do.

A short description and a link to the product, if you have one, are enough to get started.