The security we sell is not an 80-page PDF. It is a reduced attack surface, secrets that no longer sit in your git history, a CI that blocks regressions and alerts someone actually reads. Every finding comes with the fix applied or a patch ready to merge — not just a line in a risk table.
Your enterprise prospect sends a security questionnaire and you have nothing to answer. We close the real gaps and document what already exists.
Forgotten open ports, API keys in git, containers running as root, dependencies never updated — inventory and cleanup.
Rotation, vault, least privilege, MFA where it matters. With the procedure that keeps it true after we leave.
Your logs go somewhere but nobody reads them. We build the rules that matter and the runbook for the day it fires.
Prices excl. Swiss VAT where applicable · invoiced by Ninabot Sàrl, Geneva · secure Stripe payment · if the scope doesn't fit the tier, we say so at kickoff: reduced scope, higher tier, or refund. At mission end, you choose: ongoing hosting on your instance, or full export + certified destruction of the environment.
Specific to security missions: payment triggers scoping, not testing. No reconnaissance and no testing begins before the signed written authorisation defining the perimeter — we provide the template at kickoff. If scoping reveals that the perimeter is not yours, depends on a third party who does not consent, or exceeds what the tier can seriously cover, you are refunded in full.
No, and we don't claim it is. It is a correction-oriented technical audit run by a SOC / incident-response profile. If you need a formal certified pentest for a regulator, we point you to an accredited firm — and we prepare your stack so they find little.
Only with explicit written authorisation and an agreed window. By default we work read-only and on pre-production. Anything that could interrupt a service is cleared with you first.
You are told immediately, before any report, through the emergency channel agreed at scoping. If it is actively exploited, we switch to incident response and re-discuss scope.
They live in your dedicated environment, hosted in Switzerland. Nothing is published, nothing is reused. Full export then certified destruction at the end, if you ask for it.
Not exactly what you need?
Post your mission — fixed-price quote within 24 business hours