Security & compliance

Know where your system is exposed before someone else does.

Audits and penetration tests, with every finding ranked and written down. Encryption and data protection built into the system instead of added after. Compliance work for PDPA, GDPR, CCPA and ISO 27001 that ends with documented evidence rather than a filled-in template.

The free consultation

Bring the system that worries you.

  • A working session on your live system, or the one you are about to build.
  • Written findings, ranked by severity, that you can hand to any team.
  • You are not obliged to fix them with us.
  • 12years building
  • 43systems delivered
  • 37organisations
  • 18sectors

What you get

Six things you leave with, each of them written down.

Security work that ends in a document you can act on: with us, with your own team, or with an auditor.

Audit

A ranked list of what is exploitable

Penetration testing and vulnerability assessment of your application and the infrastructure under it. Every finding comes with its severity, how it was reproduced, and what fixes it.

Privacy

Data handling that meets PDPA, GDPR and CCPA

A map of the personal data you hold, where it flows and who can reach it. That map drives the consent, retention and access controls the regulations require, which we put in the system and on paper.

Encryption

Data protected at rest and in transit

End-to-end encryption where it belongs, secure storage, and transmission protocols. Each is configured, tested and documented so the next engineer can see why the choice was made.

ISO 27001

An ISMS an auditor can assess

The policies, risk register, controls and evidence that make up an information security management system aligned to ISO 27001. Certification is issued by an accredited body; we build what it assesses, with your team, so it is maintained after we leave.

Incident response

A plan for the day something goes wrong

Monitoring that alerts on the signals that matter, and a written response plan: who is called, what is isolated, what is told to whom. Response times are set out in your support agreement.

Training

A team that recognises the attack

Security practice and threat-awareness sessions for your staff and your developers. They cover phishing, credential handling and secure coding, and are pitched at the way your organisation works day to day.

Work in this area

Systems we have delivered that hold sensitive data.

5 of the 43: a biometric visa system, a district land office's consent records, a ministry's statistics, a refinery's safety records and a broker's client data.

All 43 systems
Client Management System — InstaForex
Finance
Client Management System · InstaForex
Data Management and Statistical for Mobile — Kementerian Tenaga, Teknologi Hijau dan Air (KeTTHA)
Government
Data Management and Statistical for Mobile · Kementerian Tenaga, Teknologi Hijau dan Air (KeTTHA)
Sistem Semakan E-Consent — Pejabat Tanah Daerah Kuala Langat
Government
Sistem Semakan E-Consent · Pejabat Tanah Daerah Kuala Langat
Internal Pricing, Safety Records and Incident Management — Hengyuan Refining Company Berhad (HRC)
Oil & Gas
Internal Pricing, Safety Records and Incident Management · Hengyuan Refining Company Berhad (HRC)
Pintar ID — Heitech Padu Berhad
Technology
Pintar ID · Heitech Padu Berhad

In writing

Three things you get before the first invoice.

01

The findings are yours.

We hand over every report, test result and policy document as it is produced, rather than holding it back until the final invoice. You can act on it with us or with anyone else.

02

Remediation is fixed price.

After the assessment, we quote the fixes for phase one as a defined scope at a defined cost. You are never signing an open-ended security engagement.

03

A warranty, in writing.

Defects in controls and fixes we shipped, we fix at no charge for the warranty period. A support agreement with named response times is available after that.

How it runs

Five stages. You receive something you own at each.

  1. 01Insight

    A written scope and the risks found in the first session.

  2. 02Strategy

    The remediation and compliance plan, with a fixed price for phase one.

  3. 03Build

    Fixes and controls landing in your repository every sprint.

  4. 04Launch

    The production release, retested, with the evidence attached.

  5. 05Support

    Documentation, a warranty, and named response times if you want them.

Other services

Security is usually one part of a larger piece of work.

Start with a free consultation on your system.

Bring the system that holds your most sensitive data, or the one you are about to put in front of an auditor. We spend a working session on it and you leave with written findings that are yours to act on, with us or with anyone else.