Security built into the application, not bolted on top
We build and implement security solutions that run in production, not reports
that sit in a drawer: application firewalls, incident management applications and IAM/OAuth systems —
plus security audits and penetration testing for what you already have.
We don't sell boxes. We build and operate these systems every day.
For one of our platforms we operate a standalone security service — its own domain, its
own database — providing the application firewall, incident detection and identity for a business
application with over 100 active users and hundreds of access tokens. What we describe below is not a
catalogue offer: it is what keeps real applications running, right now.
Solutions we build and implement
Application Firewall (WAF)
A Web Application Firewall built as our own module, integrated directly into your application —
not a generic appliance that doesn't know what it protects. It filters requests before they
reach your business logic: SQL injection and XSS blocking, brute-force protection, rate
limiting on sensitive endpoints, IP and pattern blocklists, with every decision logged. Rules
are tuned on your application's real traffic, not on assumptions.
Incident Management
A security incident management application: detection patterns running continuously over your
application's logs and traffic, real-time alerts when something deviates from normal, and a
record of every incident — from detection to closure — with owner, timeline and measures
taken. In the end you have exactly what any audit asks for: proof that incidents are seen,
handled and learned from.
IAM / OAuth
Identity & Access Management as a separate service: a single place that knows who your
users are and what they are allowed to do, across all of your company's applications.
Token-based authentication (OAuth-style, server-to-server), granular authorization on five
levels — company → role → right → API and page, per HTTP verb — so a right granted or revoked
propagates instantly to every connected application. Users are managed once, not in each
application separately.
Custom security modules
When no product on the market covers your exact need, we build it: custom-developed security
modules, integrated directly into the applications and infrastructure you already have.
Two-factor authentication, document signing and verification, application-level encryption of
sensitive data, detection rules specific to your domain, security connectors to external
systems — whatever protection logic you need, built to measure and kept in production by us.
Security audit & penetration testing
We assess the applications and infrastructure you already have: code and configuration review,
penetration testing of web applications (authentication, sessions, injections, access
control), server and data exposure checks. Deliverable: a report with the vulnerabilities
found, ordered by real risk — not by scanner noise — a concrete remediation plan, and
re-testing after you fix. Everything under NDA, with rules of engagement agreed in writing
beforehand.
What it looks like in production
The security service we operate for our clients includes exactly the modules above,
running around the clock:
our own WAF — filtering application traffic before routing;
detection and incidents — monitoring patterns and alerting on application
events;
IAM as the identity provider — the business platform has no users of its
own: it creates and authenticates everything through the security service's APIs, with
role-based authorization per API and per page;
encryption — sensitive data is encrypted at the application level (AES),
not just in transit.
We can implement the same model on your applications — in full, or only the modules you need.
How we work
1. Assessment
We start from what you have: applications, infrastructure, past incidents. A short audit shows
where the real risk is and what deserves treatment first — in writing, with priorities.
2. Implementation
We implement the agreed modules — WAF, incident management, IAM — integrated with your existing
applications, with a separate test environment and no downtime for users.
3. Operation and re-testing
Security is not a project with an end date: we monitor, tune rules on real traffic and re-test
periodically. We report what was blocked, what changed and why.
Security audit
A free 30-minute technical discussion, under NDA if needed. By the end you will know:
which parts of your applications and infrastructure carry real risk;
what a penetration test would cover and what it would cost, with a fixed written estimate;
whether you need a WAF, incident management or IAM — or just a few targeted fixes.
No strings attached. If the risk doesn't justify the investment, we'll tell you directly.