Services / Web development

Web applications and websites built with security from the first commit, then patched, monitored and looked after.

Most insecure software was not built to be insecure. It was built quickly and then left alone. We build web applications and websites with the same eye we bring to testing them.

Every build is security-tested before launch. After launch we handle updates, monitoring and backups, so the site that went live safe stays safe.

deploy — portal@main
$ npm run build && npm run check:security✓ dependencies: 0 known vulnerabilities✓ CSP: default-src 'none', no inline scripts✓ authorisation tests: 48 passed✓ no secrets in the bundle → deploying to production · backups verified
When you need this
  • You need a new web application, customer portal or company website
  • An existing site is out of date and nobody wants to touch it
  • A security test found issues you do not have the people to fix
  • You want one team responsible for building and securing your web presence
Coverage

What's included

The exact scope is agreed in writing before we start. This is what a typical engagement covers.

01

Build

  • Web applications and customer portals
  • Company and marketing websites
  • APIs and integrations
02

Security built in

  • Login and role-based access designed up front
  • Security headers, CSP and TLS by default
  • Dependency and secret scanning on every build
  • Security testing before launch
03

Hosting & deployment

  • Cloud hosting set up and hardened
  • Automated deployments
  • Separate staging and production
04

Maintain

  • Dependency and framework updates
  • Security patches
  • Uptime and error monitoring
  • Backups, with restores tested
Deliverables

What you receive.

  • A working application or website
  • A security test report before launch
  • Source code, documentation and a handover
  • A monthly maintenance report: updates applied, uptime, backups
Standards we work to
  • OWASP ASVS
  • OWASP Top 10
  • WCAG 2.2
  • Core Web Vitals
Before we start

What we need from you

  • A brief, or a discovery session to write one together
  • A product owner who can make decisions
  • Access to existing systems and hosting, if we are taking over a site

Never send passwords or keys by email. We set up a secure channel once the scope is agreed.

Often combined with

Related services.

Let's strengthen your security — get in touch.

Araval · Technologies
Email us
  1. 01Tell us what you need and by when
  2. 02We reply with questions or a written scope
  3. 03You get a fixed quote before any work starts
Discuss your scope