Security and Compliance Services
Certification and privacy programmes, manual penetration testing, code and dependency review, configuration hardening, and security work we run for you month after month. Most clients arrive with one problem and grow into a programme delivered by the same team.
Compliance
Certifications and Privacy Programmes Across 13 Frameworks
Practice Area OverviewMeasured Against
Services in This Area
13 services- 01ISO 27001Build and certify your information security management system.
- 02ISO 27701Extend your ISMS into a privacy information management system.
- 03ISO 22301Certify how your business keeps running through disruption.
- 04ISO 42001Govern your AI systems with the first AI management standard.
- 05DPDP ActGet ready for India's Digital Personal Data Protection Act.
- 06PCI DSSProtect cardholder data and pass your PCI assessment.
- 07HIPAAProtect health information and meet HIPAA requirements.
- 08SOC 2Earn a SOC 2 report your customers can trust.
- 09CCPAMeet California's consumer privacy requirements.
- 10GDPRMeet Europe's data protection standard with confidence.
- 11NEN 7510Certify information security for Dutch healthcare.
- 12EU AI ActPrepare for Europe's risk-based AI regulation.
- 13Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.
VAPT
Manual, Exploit-Driven Penetration Testing Across 7 Surfaces
Practice Area OverviewMeasured Against
PTESOWASPOWASPServices in This Area
7 services- 01Web ApplicationManual testing of your web apps against the OWASP WSTG
- 02Mobile ApplicationAndroid and iOS app testing against the OWASP MASVS
- 03APIREST, GraphQL and SOAP testing against the OWASP API Top 10
- 04Thick Client ApplicationDesktop app testing across binary, traffic and backend
- 05Network InfrastructureExternal and internal network testing with lateral movement
- 06IoT and EmbeddedDevice testing across firmware, hardware and radio
- 07CloudConfiguration and IAM testing across AWS, Azure and GCP
Secure Code Review (SCR)
We read the code that matters. Our engineers walk your authentication, authorization, payment and data-handling paths line by line, then confirm which findings are truly exploitable.
A practice area in its own right, with no sub-services beneath it.
What We Run
Measured Against
- OWASP
- OWASP
- OWASP
- CWEMITRE
Software Composition Analysis (SCA)
Most of your application is code you did not write. We inventory your open-source and third-party dependencies, map their known vulnerabilities, check their licenses, and generate the SBOM that ties it all together.
A practice area in its own right, with no sub-services beneath it.
What We Run
Measured Against
- OWASP
- OWASP
- SPDXLinux Foundation
Hardening and Configuration Review
Benchmark-Based Configuration Hardening Across Cloud, OS, Network and Data Tiers
Practice Area OverviewMeasured Against
MSMicrosoftVENDORCISServices in This Area
5 services- 01Cloud Security Configuration AssessmentBenchmark review of your AWS, Azure and GCP accounts against secure baselines
- 02Operating System Hardening ReviewBenchmark comparison of your Windows and Linux builds against CIS and STIG baselines
- 03Firewall and Perimeter ReviewRule-base and configuration review of your firewalls, VPNs and edge devices
- 04Active Directory and Domain Controller AuditSecurity review of your AD forest, domain controllers and privilege paths
- 05Database and Web Server ConfigurationHardening review of your databases and web servers against CIS Benchmarks
Managed Services
Ongoing Offensive, Defensive and Advisory Security Run by Our Team
Practice Area OverviewMeasured Against
DPDPIndiaSANSServices in This Area
7 services- 01Red Team AssessmentGoal-based adversary simulation across people, process and technology
- 02SOC as a ServiceA 24/7 security operations centre run by our analysts
- 03vCISOSenior security leadership on demand, without a full-time hire
- 04vDPOA data protection officer as a service for the DPDP Act and beyond
- 05Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- 06Awareness TrainingsSecurity training your people actually remember and use
- 07Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong
Tell Us What You Need to Prove
An auditor's finding, a customer's security questionnaire, a board asking about the last penetration test. Start anywhere and we will scope the smallest piece of work that answers it properly.