Four areas of assessment

We set the scope before we start. Sometimes one area is enough to answer your question.

Delivery process maturity

We measure the level of your process against OWASP SAMM and NIST SSDF. Not to hand out a grade — to know what specifically moves you up a level.

  • Interviews with the team
  • Review of process and practices
  • Assessment against recognized frameworks
  • Mapa luk z priorytetami

Architecture review

We review the architecture from a security angle: trust boundaries, data flows, authentication, authorization, component isolation.

  • Data flow diagrams
  • Threat modeling
  • Analiza granic zaufania
  • Rekomendacje architektoniczne

Technical security

We check what actually happens in the build and release process: configuration, secrets, permissions, dependencies, supply chain.

  • Configuration review
  • Secrets management
  • Permissions analysis
  • Dependencies and supply chain

Technical compliance

We map the technical requirements arising from regulations onto your actual state. We show the gap and say plainly where our role ends.

  • Mapping requirements to the process
  • Analiza luki
  • Implementation priorities
  • Pointing out areas outside our scope

Ways to work together

Assessing one product is different work than fifteen microservices in three teams. We choose the scope after a conversation — from a single system to a complex multi-team environment.

Basic assessment

One system, one team. An answer to the question: where we stand and where to start.

  • Process maturity assessment
  • Technical configuration review
  • Raport z priorytetami
  • Walkthrough with the team
Ask for a quote →
Full assessment

Process, architecture, technical security and the regulatory gap in one.

  • Wszystko z diagnostyki podstawowej
  • Architecture review and threat modeling
  • Supply chain analysis
  • Mapping of regulatory requirements
  • A staged implementation plan
  • A separate walkthrough for the board
Ask for a quote →
Recurring review

A repeatable maturity assessment for companies that want to track progress over time.

  • Measuring progress against the starting point
  • Updating priorities
  • Reakcja na zmiany regulacyjne
  • Ongoing contact with the team
Ask for a quote →

Co dostajecie na koniec

Risks by cost, not alphabet

A list ranked by what each risk can actually cost you and what removing it costs. Without that, prioritization is guesswork — and most reports end exactly there.

A concrete order of action

What to do first, what next, what can wait. Split into what you can do yourselves and what needs our help. Sometimes it turns out you don't need us at all.

A walkthrough with the team

A report no one read is useless. We go through the findings with your team and your management — separately, because they have different questions and a different language.

What this most often relates to

Questions we get
most often

How is this different from a pentest?+

A pentest is a snapshot from a specific day — it says what was vulnerable at the moment of the test. An assessment asks why that vulnerability arose at all and whether another one like it won't arise tomorrow. They are two different things and do not replace each other.

Do you need access to the code?+

For the process and architecture assessment, documentation and a conversation with the team are usually enough. For the technical review we need access to the build pipeline configuration and organization settings. We agree the scope in writing before we start and apply the principle of least privilege to ourselves too.

How much of our team's time will it take?+

Realistically from a few to a dozen or so hours in total — mostly interviews and follow-up questions. We don't pull the team off work for weeks. That an assessment must not paralyze the company is a condition for us, not a declaration.

What if the report shows things are bad?+

That is good news, even though it doesn't sound like it. Better to hear it from us than from a client's auditor or from an incident. The report always ends with a plan — we don't leave you with a list of problems and no idea what to do with them.

How long does it take?+

From a few business days for a focused assessment to two–four weeks for a full one. We set the boundary before we start, so nothing drags on endlessly.

Do we then have to take an implementation from you?+

No. The report is yours and you can act on it yourselves or with anyone else. If you have the skills and the time — that will be cheaper, and that is what we will advise.

Want to reduce risk
and IT costs?

We reply within 24h on business days