Security
Security you can evidence, not just claim
Assessment, secure architecture and compliance readiness. Particularly relevant if you handle personal data across Japan, Korea or the EU, where the question is rarely "are you secure?" and almost always "can you show it?".
What we do
- 01
Security assessment
Architecture review, threat modelling and code-level assessment, delivered as a prioritised and actionable finding list.
- 02
Secure by design
Identity, secrets handling, least-privilege boundaries and data classification built in from the first sprint.
- 03
Compliance readiness
Control mapping and evidence collection for APPI, PIPA, GDPR and ISO 27001 — written so an auditor can follow it.
- 04
Application and cloud hardening
WAF policy, dependency and supply-chain hygiene, logging and detection tuned to the things that actually matter.
Technologies we work with
- Threat modelling
- OWASP ASVS
- ISO 27001
- APPI
- PIPA
- GDPR
- SAST / DAST
- Zero Trust
Have a project in this area?
Tell us the shape of the problem and we will tell you honestly whether we are the right team for it.