Technical audit & cybersecurity
Find out whatwill breakbefore it does.
Code, technical debt, vulnerabilities, architecture, infrastructure, performance, backups. We read, we measure, we attack with your written permission, we test the restore, then we write down what we found, in the order you need to deal with it.
What we look at
You set the scope: everything, or only what worries you. To find out what an attacker would do with what we find, add a penetration test.
Code quality
Readability, test coverage, duplication, outdated or vulnerable dependencies. Everything that slows your team down every week without anyone putting a figure on it.
Technical debt
We list it, estimate what it costs you and propose a plan to pay it down in instalments, without freezing new work for six months.
Risk analysis
Data leak, outage, compromised account, the only person who understands the system handing in their notice. For each risk: how likely, how bad, what to do about it.
Architecture & infrastructure
How the application is split up, hosting, network, access rights, secrets management, server configuration. Where a mistake costs the most.
Performance
Response times, slow queries, behaviour under load. We measure before we advise, and tell you whether the problem lies in the code, the database or the hosting.
Backups & disaster recovery
A backup nobody has ever restored proves nothing. We test the restore, measure how many hours and how much data you would lose, and write the disaster recovery plan.
Penetration testing & bug bounty
We attack your system the way someone with bad intentions would, except with your written permission, on a scope and on dates you have signed off.
Penetration test
Web application, API, servers exposed to the internet. We start from the outside with no access, or with a user account if you want to know how far it gets someone. Every vulnerability comes with its proof, its severity and the fix to make, then we check the fix holds.
Bug bounty programme
So that security researchers keep testing your system over time. We set the scope and the rules with you, help you choose the platform, triage the reports as they come in, and fix what's confirmed or get it fixed.
How an audit runs
Duration: 2 to 4 weeks- Step 1
Scoping
Half a day: what worries you, what you want to be able to decide at the end, the access we need.
- Step 2
Immersion
Reading the code and its history, reviewing infrastructure and access, interviews with your developers. Read-only access is enough.
- Step 3
Written findings
What works, what breaks, what doing nothing will cost. Each point ranked by severity and effort, readable by non-technical people.
- Step 4
Prioritisation
We make the calls together. The audit doesn't commit you to hiring us for the work.
After the audit, if you want
The report is yours and can go to any team. If you'd rather we handle what we found, work on the code goes through our software team.
Legacy code rescue
The project nobody dares touch any more: we map it, get it under test and get it moving again without rewriting everything.
Paying down the debt
The audit's plan, tackled in instalments alongside your ongoing work. Tests go in before each change, so you know straight away if something breaks.
Fixing vulnerabilities
Whether they came from the audit, the penetration test or the bug bounty. Dependencies updated, secrets taken out of the code, access rights reviewed, configuration hardened. Every fix checked and logged.
A recovery plan that works
Off-site backups, a step-by-step written restore procedure, a dated drill. On the day it all goes down, someone knows what to do.
Our other areas of expertise
An audit is often the starting point for a certification or an overhaul of how the team works.
ISO 27001 · GDPR · HDS · Qualiopi
Gap analysis, risk analysis, policies, technical controls, audit preparation.
Agile · Git · CI/CD
Rituals, branching, code review, continuous integration, automated tests, documentation, metrics.
Positioning · tools · quotes
Positioning, brand image, community management, choosing tools and suppliers, second opinion on a quote.
Tell us what's worrying you.
Describe your platform in a few clicks. We'll get back to you for a first 30-minute call, free and with no strings attached. If everything looks fine, we'll tell you then.