Dev shop. Security included.
We read the code an attacker would read.
Most breaches are not exotic. They are an authorization check nobody wrote, a debug endpoint that shipped, a query built by string concatenation. We find those while we take over the repo, and we ship the fix.
Not a report you hand to someone else. Findings, then remediation in the same engagement if you want us in the repo.
One engagement
A financial platform, seven years in production
50+
OWASP findings, including 23 broken access control and 23 SQL injection issues.
1 year
A remote code execution endpoint sat in production, merged under a pull request titled "fix".
48 hours
From first report to the immediate-action list: kill the endpoint, ship the IDOR fix, block source maps.
The engagement started with one question: could a logged-in user read another user's data? The answer was yes, and the endpoint handed back a working authentication token for whichever account you asked about. Pulling that thread found the rest. Read the full case study.
How we work
Take over the repo. Fix what we find.
Read the source
Full repo access. Authorization gaps, leftover debug routes, injection, secrets. The findings that scanners miss because a human merged them.
- Source review against OWASP
- Prove the finding in staging where a staging copy exists
- Written report your engineers can work from
Ship the fix
We are a development shop. Remediation is the job, not a referral. You can keep your own team on the patch list, or we stay in the repo.
- Prioritized patch order
- Fixes in the same engagement if you want us there
- Re-test once the patches land
Change how you ship
For teams who keep shipping the same class of bug. Secure SDLC, review checklists, and the controls a state or healthcare buyer will ask for.
- PR review that catches debug routes titled "fix"
- NIST 800-53 mapping when the program needs it
- SOC 2 / HIPAA notes in the report when you ask
Fixed fee, scoped on the call. This is not a productized pentest. It is engineers in your codebase.
Who runs it
- Sean O'Dea — principal engineer. CISSP, GIAC GPEN. Kaseya-scale remediation (100,000+ findings). The financial-platform case study is his.
- Benjamin R. — security operations. Ran SecOps at a public company. Same Kaseya and Public Consulting Group years as Sean. CISSP, GPEN (Honors).
What you get back
- Executive summary a board can read
- Technical findings with reproduction steps and severity
- The patches, if you want us to write them
- One re-test once the fixes land
FAQ
Common questions
Is this a scanner report?
No. Scanners are part of the sweep, but the findings that matter come from reading the code and then proving them in a staging copy. A scanner will not tell you that an endpoint returns a valid token for someone else's account.
Do you fix what you find?
Yes. That is the difference. A report with no patch is someone else's product. We take over the repo and we can ship the fix in the same engagement. You can still keep your own team on the list if you want.
Will you test production?
Only with written authorization and an agreed window. Exploitation runs against staging wherever a staging copy exists.
How fast can you start?
Normal scheduling runs a couple of weeks out. If you are mid-incident, say so on the call. Expedited starts exist and cost more.
What does it cost?
Fixed fee, quoted after scoping. It depends on the size of the codebase and whether we stay to write the patches. The scoping call is 30 minutes and free.
Find it. Then fix it.
Book a scoping call. 30 minutes. Bring the repo URL and the stack.
Las Vegas, NV