Cybersecurity: Find the holes before someone else does
Most breaches in small and mid-sized companies are not exotic. They are an over-permissive database rule, a leaked key in a repository, or an admin endpoint with no server-side role check. Fixing the ordinary things well removes the majority of real risk.
custom · 1–4 weeks · 3 packages
Who this is for
- Products holding customer or health data
- Teams preparing for a client security review or audit
- Apps where roles are checked in the browser only
- Companies after an incident or a suspicious login
At a glance
- Audit turnaround: 1–2 weeks
- Deliverable: Findings with patches, not just a report
- Follow-up: Quarterly re-audit option
- Critical issues: 0 left open
- Audit turnaround: 10 days
- Re-test: Included
What we audit
We review authentication and session handling, database row-level security, role storage and privilege escalation paths, storage bucket policies, server function permissions, secret management, dependency vulnerabilities and logging. Findings come with severity, reproduction steps and a patch — not a PDF of theory.
- Row-level security policy review on every table
- Roles stored server-side, never in the client or profile row
- Secret and key hygiene, rotation procedure
- Dependency and supply-chain scanning
Privilege escalation is the common thread
The pattern we find most often is trust placed in the client: an admin flag in local storage, a role column a user can update, or an endpoint that assumes the front end filtered the request. Every authorisation decision belongs on the server, backed by a separate roles table and a security-definer check function.
Keeping it fixed
Security decays with every feature. We add policy tests to CI, enable automated dependency alerts, and schedule a short re-audit each quarter so the same class of issue does not reappear in the next module.
What's included
- Application penetration testing
- OWASP Top 10 audits
- SOC 2 / ISO readiness support
- Secure auth and RLS policy design
What you receive
- Threat model and attack surface map
- Prioritised findings report with severity
- Database RLS and permissions review
- Remediation plan (and optional fixes)
- Re-test and verification round
Our cybersecurity process
- Scope: Assets, roles and rules of engagement.
- Test: Automated scans plus manual exploitation.
- Report: Findings, evidence and business impact.
- Fix: Remediation with your team or ours.
- Verify: Re-test and sign-off.
Technologies
OWASP ZAP, Burp, Supabase RLS, Auth0, Cloudflare, Snyk
Packages and pricing
- Security Audit (₹85,000): App + database review with report. Best for: Pre-launch checks
- Harden & Fix (₹2,00,000): Audit plus implementation of fixes. Best for: Live products
- Compliance Track (Custom): SOC 2 / ISO evidence and controls. Best for: Enterprise deals
Cybersecurity FAQs
Will testing affect production?
We test staging by default, and any production work is scheduled and rate-limited.
Do you re-test after fixes?
Yes, one verification round is always included.