Security & sovereignty
Systematic penetration testing, data hosted in Europe outside the US Cloud Act, encrypted secrets, edge WAF - a documented, verifiable security posture.
Security is not an annual audit: it is a continuous posture, from architecture to the edge. Our projects are tested before every major release, hosted on ISO 27001-certified European infrastructure, and protected by independent layers of defence - if one is bypassed, the others hold.
Pentest before every launch
Penetration test in grey-box mode (simulated limited access) or black-box mode (external attacker) before every major go-live. Report delivered to the client with vulnerabilities classified by OWASP Top 10 and CVSS, and a remediation plan costed in person-days.
Data sovereignty
Hosted on BSO, a European Kubernetes infrastructure certified ISO 27001 and HDS. Data does not fall under the US Cloud Act. Secrets are managed in Bitwarden Secrets Manager (EU instance), not in plain-text environment variables.
Defence in depth
Cloudflare Access and WAF in front of the origin, OWASP rules enabled in block mode, automatic TLS, rate limiting, DDoS mitigation. Kubernetes pods are isolated by namespace with NetworkPolicies and strict RBAC. The Docker image is rebuilt on every deployment.