Skip to content
devwallssecurity
Two monitors carrying source code in a darkened room
services / application security

Application security

Testing at the end of a release cycle finds bugs. Sitting with the team while the design is still soft prevents whole classes of them.

duration
Retained, or 3-week blocks
team
1–2 embedded engineers
retest
Included, 90 days
what we cover

design

We join the RFC review and argue about trust boundaries while changing them is still cheap.

code

Source-assisted review of authentication, authorisation, tenancy, and anything handling money.

dependencies

Provenance, transitive risk, and a realistic view of which advisories actually apply to you.

handover

The goal is that you need us less each quarter. We consider a shrinking retainer a success.

what you get

everything below, on every engagement

01Threat model per service, kept in your repository and reviewed each quarter
02Secure design review at the RFC stage, before code is written
03Source-assisted testing across the highest-risk paths
04Abuse-case test suite handed to your QA team to own
05Working sessions with your engineers, recorded and kept
questions we get

Yes, under your access controls, with our commits signed and clearly attributed.

other services
A dense city skyline at night, lit windows in red and amber

scope a application security

Tell us what the system does and who relies on it. We will come back with a scope, a price and a date, usually within two working days.