Business data
We map sensitive records across collection, migration, storage and export. Your data owners confirm who needs access and how long records must be retained.
We plan and implement security controls within an agreed scope. Your team helps identify sensitive operations; together we assign responsibility for protection, verification and incident response on the chosen infrastructure.
Customer records, payment approvals and service availability expose different risks. We assess the data, application and infrastructure together to identify the controls each workflow needs.
We map sensitive records across collection, migration, storage and export. Your data owners confirm who needs access and how long records must be retained.
We turn user roles and sensitive actions into application requirements. Security checks become part of development and release acceptance, with findings assigned for resolution.
We review deployment access, configuration and recovery arrangements. Responsibilities cover your infrastructure team, hosting providers and the agreed support service.
For an action such as exporting customer records, we define who can initiate it, what the system allows and how an unexpected event is handled.
Choose sign-in and additional verification for the account and the sensitivity of the action.
Check permission for the requested action and records, including calls made directly to the API.
Define where exported data can go, how it is protected and which events enter the audit log.
Assign alert review, access revocation and recovery decisions to named owners.
The security plan records each control, its owner and the evidence needed for acceptance. We agree these checks with your technical team before implementation.
We test permitted and blocked actions against the role matrix. Your team names who approves access changes after launch.
We review encryption and key access, then check retention, export and deletion rules for the agreed data flows.
We check that agreed events identify the actor, action and affected record. We also define access to logs and prevent sensitive values from entering them.
We agree code, dependency and configuration checks. Findings retain an owner, a resolution decision and evidence of retesting.
We define who receives alerts, assesses impact and authorises containment. The support agreement sets coverage and response expectations.
We test a restore against agreed recovery targets and check the restored records. The plan names who maintains backups and authorises recovery.
These two research areas address password authentication and message protection. We assess their fit against existing identity services, device constraints and operating requirements.
OPAQUE allows password authentication without revealing the password to the server. The assessment covers implementation choice, account recovery and integration with existing identity services.
Explore the researchThe Ecliptix Protection design explores key agreement and rotation for messaging. Assessment covers device identity, group membership and key handling throughout a conversation.
Explore the researchShare the systems involved, sensitive operations and any supplier-review requirements. We will identify the questions that need investigation and agree the assessment scope with your team.