Kernel components on UNIX and Windows
Profound knowledge of OS internals and the threat landscape, with contributions to Fortune 25 security solutions.
We maintain a specialized security practice, from kernel filter drivers to key management. Built by engineers who understand the threat landscape from the inside.
We help customers build security into the product rather than around it, from kernel-level controls to enterprise-grade key management.
Profound knowledge of OS internals and the threat landscape, with contributions to Fortune 25 security solutions.
Our engineers contribute to on-prem, cloud, and containerized security solutions. We work with industry standards like FIPS, KMIP, and PKCS.
Expert consulting for organizations developing and customizing software, or maintaining an online presence. We work alongside your engineering org.
We train developers and test engineers to think about security, so security issues are considered throughout the development life cycle, not patched at the end.
Audit of software development and QA practices, source code handling, bug tracking systems, and vulnerability management.
We suggest and implement specific tools to assess and report security quality of in-house software before deployment, plus due diligence and vendor obligations for off-the-shelf and customized software.
We review the security of SaaS solutions from the perspective of an insider threat as well as a malicious attacker from the outside.
Assess the security of deployed servers, update and patching of software on the servers, and instantiate a regular scan of deployed servers for ongoing information security status auditing.
Specific attacks of well-known vectors such as OWASP top 10 and CWE top 25, using appropriate tools and ad-hoc techniques.
Software source code audit to identify insecure practices and potential vulnerabilities for open source and client-developed software. Software security audit for software deployed where the source code is not available.
Separation of privileges for insider access to various server components and the data therein, separation of user data, assessing the secure storage of secrets across user groups, and architecture and deployment changes to ensure data access control.