Security Expertise

Security for your data, software and infrastructure

We plan and implement security controls within an agreed scope. Your team helps identify sensitive operations; together we assign responsibility for protection, verification and incident response on the chosen infrastructure.

Protection areas

Scope protection around what the business depends on.

Customer records, payment approvals and service availability expose different risks. We assess the data, application and infrastructure together to identify the controls each workflow needs.

Business data

We map sensitive records across collection, migration, storage and export. Your data owners confirm who needs access and how long records must be retained.

Application security

We turn user roles and sensitive actions into application requirements. Security checks become part of development and release acceptance, with findings assigned for resolution.

IT infrastructure

We review deployment access, configuration and recovery arrangements. Responsibilities cover your infrastructure team, hosting providers and the agreed support service.

Security across the workflow

Trace a sensitive action from sign-in to recovery.

For an action such as exporting customer records, we define who can initiate it, what the system allows and how an unexpected event is handled.

  1. 01

    Confirm identity

    Choose sign-in and additional verification for the account and the sensitivity of the action.

  2. 02

    Check permission

    Check permission for the requested action and records, including calls made directly to the API.

  3. 03

    Handle data

    Define where exported data can go, how it is protected and which events enter the audit log.

  4. 04

    Respond and recover

    Assign alert review, access revocation and recovery decisions to named owners.

Controls and verification

Make the controls verifiable.

The security plan records each control, its owner and the evidence needed for acceptance. We agree these checks with your technical team before implementation.

Access

We test permitted and blocked actions against the role matrix. Your team names who approves access changes after launch.

Data

We review encryption and key access, then check retention, export and deletion rules for the agreed data flows.

Events

We check that agreed events identify the actor, action and affected record. We also define access to logs and prevent sensitive values from entering them.

Testing

We agree code, dependency and configuration checks. Findings retain an owner, a resolution decision and evidence of retesting.

Response

We define who receives alerts, assesses impact and authorises containment. The support agreement sets coverage and response expectations.

Recovery

We test a restore against agreed recovery targets and check the restored records. The plan names who maintains backups and authorises recovery.

Security research

Explore authentication and protected messaging.

These two research areas address password authentication and message protection. We assess their fit against existing identity services, device constraints and operating requirements.

Authentication research

OPAQUE

OPAQUE allows password authentication without revealing the password to the server. The assessment covers implementation choice, account recovery and integration with existing identity services.

Explore the research
Messaging research

Ecliptix Protection

The Ecliptix Protection design explores key agreement and rotation for messaging. Assessment covers device identity, group membership and key handling throughout a conversation.

Explore the research
Plan the security scope

Bring your security requirements into the project brief.

Share the systems involved, sensitive operations and any supplier-review requirements. We will identify the questions that need investigation and agree the assessment scope with your team.