A company built around
one problem

Security of the process in which software is made. We don't do a bit of everything — we do one thing and take it to the end: from assessment, through design, to implementation in your code.

What we do

CyberForge works on the security of the process in which software is made. We don't inspect finished systems once a year — we work where the code is actually made: at feature design, change review, build and release.

We work with technology companies and regulated sectors: banks, fintechs, software houses and software vendors. One thing connects them — they have to deliver fast while proving to a client or a regulator that they do it safely.

We do three things: we train teams, measure process maturity, and implement security practices. We start where there is a real problem — sometimes with a single workshop, sometimes straight with an implementation.

Raport nie zmienia niczego.
Zmienia kod.

People behind the brand

CyberForge is built by two founders who are responsible for its direction, the standard of work, and what ultimately reaches the client.

Michał Jaśniewski, co-founder of CyberForge
Co-founder
Michał Jaśniewski

Responsible for business development and client relationships. Sets the scope of projects and makes sure they answer a real problem, not what is easier to sell. He leads the first conversation and he stands behind what we promise you.

Business developmentScope and pricingCompliance
LinkedIn →
Szymon Mytych, co-founder of CyberForge
Co-founder
Szymon Mytych

Responsible for the technical layer and the standard of delivery. Designs secure delivery processes, leads threat modeling and oversees implementations. He decides whether a solution is ready to hand over to the client.

Secure SDLCThreat modelingAutomation
LinkedIn →

Four pillars of our work

We base every project on these — from the first conversation to handing over the finished solution.

First we measure, then we act

We don't start from a tool or a ready-made solution, because that is guessing. We start by checking what your process really looks like — and only then do we know what makes sense. Sometimes it turns out the problem lies somewhere entirely different than you assumed.

We don't sell scope you don't need

If after a conversation we conclude that one workshop is enough for you instead of a three-month engagement — we will say so, even though we earn less. Selling you something you won't use is the shortest way to make sure you don't come back.

We implement in your code, not in a slide deck

A consultant's work ends on a slide with a recommendation. Ours ends when the change works in your system and has survived the first weeks of the team's normal work. That is the difference that decides whether next year's audit shows the same gaps again.

We don't slow the team down

A control that adds fifteen minutes to a build or floods people with false alarms will be switched off within a week — and rightly so. We choose tools and thresholds so the signal is useful. Security developers hate simply does not work.

We work in what
your team already uses

We provide licenses for security tools and implement them at your side — selected and configured for your process, so they genuinely work.

Build and release

  • GitHub Actions
  • GitLab CI
  • Azure DevOps
  • Jenkins
  • Bitbucket Pipelines
  • Argo CD

Containers and Kubernetes

  • Kubernetes (k8s)
  • k3s
  • AKS · EKS
  • Rancher
  • OpenShift
  • Docker · Helm

Code and dependency analysis

  • CodeQL
  • Semgrep
  • SonarQube
  • Snyk
  • Trivy · Grype
  • Dependency-Track

Security testing

  • OWASP ZAP
  • Burp Suite
  • Nuclei
  • Schemathesis
  • DefectDojo

Secrets and access

  • HashiCorp Vault
  • AWS Secrets Manager
  • Azure Key Vault
  • TruffleHog · Gitleaks
  • OIDC

Supply chain

  • CycloneDX · SPDX
  • Syft
  • Cosign / Sigstore
  • SLSA
  • in-toto

Infrastructure as code

  • Terraform
  • Ansible · Pulumi
  • Checkov
  • tfsec · Terrascan

Policy and modeling

  • OPA / Rego
  • Kyverno
  • Falco
  • OWASP Threat Dragon
  • IriusRisk
  • STRIDE

Monitoring and observability

  • Prometheus
  • Grafana
  • Loki
  • OpenTelemetry

If you already have a tool that is not on this list — that is not a problem. We plug into what works for you, instead of replacing everything from scratch. Replacing a tool is the most expensive and least often necessary way to improve security.

Want to reduce risk
and IT costs?

We reply within 24h on business days