Classify · control · secure the code

Data and application security

Find the sensitive data you did not know you held, control who can reach it, and secure the software that touches it — with the registers, matrices and logs to prove it.

Data security

You cannot protect what nobody has mapped

Most breaches are embarrassing rather than sophisticated: sensitive data sitting somewhere nobody knew about, with permissions nobody reviewed. This is the work that closes that gap.

Discovery first

Sensitive data mapping

Find where regulated and sensitive data actually lives — including the copies in test environments, exports and mailboxes that no architecture diagram shows.

Register included

Data classification

A classification scheme your staff can actually apply, backed by a classification register, so protection is proportionate instead of uniform and ignored.

DLP incident log

Data loss prevention

DLP policy design and tuning, with an incident log that records what was blocked and why — the evidence auditors ask for and most organisations cannot produce.

Keys under control

Encryption & key management

Encryption at rest and in transit, with a key management process that survives staff turnover rather than living in one person head.

Permissions matrix

Access rights review

An access rights and permissions matrix showing who can reach what, so the quarterly review becomes a task rather than a project.

Reduce the blast radius

Retention & disposal

Document retention and secure disposal schedules, because data you no longer need is pure liability the day you are breached.

Application security

Secure the software before it ships

Fixing a vulnerability in design costs a conversation. Fixing it in production costs a weekend, a disclosure and sometimes a customer. We move the work left.

In the pipeline

Static code analysis

SAST wired into your pipeline with the findings triaged, so developers get the handful that matter rather than a wall of noise they learn to skip.

Practical, not theoretical

Secure coding standards

A secure coding checklist your team will actually use, aligned to the languages and frameworks you build in rather than a generic list.

Prioritised

Application risk matrix

Rank your application estate by exposure and business impact, so remediation effort lands where a breach would hurt most.

Tracked, not assumed

Patch & update tracking

A patch and update tracker across applications and dependencies — the boring control that prevents most of the incidents we get called to.

Defaults are dangerous

Misconfiguration review

Security misconfiguration assessment across app servers, frameworks and cloud services, where the default setting is very often the vulnerability.

iOS & Android

Mobile app testing

Secure mobile testing for iOS and Android builds, covering storage, transport, authentication and the third-party SDKs nobody audited.

Mobile development
What you actually receive

Documents, not just advice

Every engagement leaves you with artefacts your team can operate and your auditor can read. These are the deliverables, not a summary of them.

  • Sensitive data map and data classification register
  • Access rights and permissions matrix
  • DLP incident log and tuned policy set
  • Encryption key management process
  • Document retention and secure disposal schedule
  • Application risk matrix and secure coding checklist
  • Static code analysis findings log with triage and owners
  • Patch and update tracker covering apps and dependencies

Do you know where your sensitive data is right now?

Most organisations find out during an incident. A data discovery and classification assessment answers it in weeks, for a fixed price.

Book a Data Security Assessment

Published

FAQ

Common questions

With discovery. Until you know where sensitive and regulated data actually lives — including copies in test environments, exports and mailboxes — every other control is guesswork. A data mapping and classification assessment is the usual first engagement and is quoted as a fixed price.

It is a scheme that rates data by sensitivity so protection is proportionate. Without it, organisations either protect everything equally (expensive and ignored) or nothing consistently. You get a classification register your staff can actually apply.

Yes — policy design, deployment and the tuning that decides whether staff work with it or route around it. You also get a DLP incident log recording what was blocked and why, which is the evidence auditors ask for and most organisations cannot produce.

Yes. We produce an access rights and permissions matrix covering systems, shares and applications, so the quarterly access review becomes a routine task rather than a project nobody starts.

Static code analysis wired into your pipeline with findings triaged, secure coding standards for the languages you actually use, an application risk matrix, patch and dependency tracking, security misconfiguration review, and mobile app testing for iOS and Android.

Only if it is left untuned. Raw SAST output is mostly noise, and developers learn to skip it. We triage findings so the team sees the handful that matter, which is the difference between a control that works and one that is bypassed.

Yes — storage, transport security, authentication and the third-party SDKs that nobody audited, across iOS and Android builds. It pairs naturally with our mobile development practice if you also need the fixes implemented.

Documents, not a slide deck: sensitive data map, classification register, permissions matrix, DLP incident log, key management process, retention and disposal schedule, application risk matrix, secure coding checklist and a patch tracker.