Services

We test the application, the servers underneath it and the cloud account around it, then stay on as your part-time security lead or build and look after the software itself.

Testing & audits

One-off engagements, one clear report.

Ongoing

Month to month, built to last.

Software nobody maintains

Sites and apps launched and left behind: outdated dependencies, expired certificates and admin panels nobody remembers.

See what's included: Web development
In detail

What each engagement covers.

VAPT

Expose vulnerabilities before they become breaches.

01 / 05
repeater — invoices
GET /api/v1/invoices/7731 HTTP/1.1Host: app.example.testAuthorization: Bearer ‹customer_b› HTTP/1.1 200 OK{ "id": 7731, "owner": "customer_a", "total": 48200 } ✕ another customer's invoice · IDOR · High 8.1
  • Web applications & APIs
  • Mobile apps
  • External & internal networks
  • Role and tenant access control
Learn more
Infrastructure security audit

Harden the servers everything runs on.

02 / 05
sshd_config.diff — prod-db-01
# /etc/ssh/sshd_config- PermitRootLogin yes- PasswordAuthentication yes+ PermitRootLogin no+ PasswordAuthentication no+ AllowGroups ops-admins ✕ 5432/tcp open to 0.0.0.0/0 · restrict to app subnet
  • Server hardening (CIS)
  • Access & privileged accounts
  • Firewall & segmentation
  • Patching, logging & backups
Learn more
Cloud security review

Close the gaps in your cloud accounts.

03 / 05
iam — ci-deploy
$ aws iam get-policy-version …/ci-deploy{  "Effect": "Allow",  "Action": "*",  "Resource": "*"} ✕ CI user is full admin · access key 912 days old
  • AWS, Azure & Google Cloud
  • IAM & least privilege
  • Public exposure
  • Logging & detection
Learn more
Part-time security lead

A security lead, without the full-time hire.

04 / 05
security-review — september.md
## Done this month✓ Acme Bank questionnaire answered (212 q)✓ SSO enforced on the admin console✓ Leaver access review: 4 accounts removed ## Open risks✕ Backups never restore-tested→ Next: patch policy, restore test, VAPT scope
  • Security roadmap & ownership
  • Client security questionnaires
  • Policies & audit readiness
  • Incident guidance
Learn more
Web development

Built secure, and kept that way.

05 / 05
deploy — portal@main
$ npm run build && npm run check:security✓ dependencies: 0 known vulnerabilities✓ CSP: default-src 'none', no inline scripts✓ authorisation tests: 48 passed✓ no secrets in the bundle → deploying to production · backups verified
  • Web apps & company websites
  • Security testing before launch
  • Hosting, patching & updates
  • Monitoring & backups
Learn more

Let's strengthen your security — get in touch.

Araval · Technologies
Email us
  1. 01Tell us what you need and by when
  2. 02We reply with questions or a written scope
  3. 03You get a fixed quote before any work starts
Discuss your scope