SaaS security audit: our services
Three main offers (starter review, full audit, ongoing monitoring) and stack-specific audits. Built for French vendors of HR, payroll, and recruiting SaaS.
What a stranger can make
Red team your AI agent: injections through read content, exfiltration chains, scope abuse. Report in 5 days, reusable in your clients' questionnaires.
See the serviceRed — the full pictureEvery action of your agent,
Source → sink flow mapping, per-task scope, business-impact prioritization, a deploy-ready action control plan. €2,500–4,000.
See the serviceBlue — soonIn spec, it passes.
The layer between your agent and its tools: action allowlist, argument validation, inspectable journal. Red mode (scanner) and Blue mode (runtime). In development — design partners.
See the serviceSupabase AuditWhat your Supabase policies do.
Supabase security audit: RLS rules (SELECT, INSERT, UPDATE, DELETE), Storage, Edge Functions, API access, and common exposures.
See the serviceFirebase AuditYour Firebase backend.
Firebase security audit: Firestore rules, Storage, Functions, Auth, and access control in real application context.
See the serviceNext.js AuditYour Next.js app.
Next.js security audit: middleware, routes, authentication, server actions, headers, and common configuration issues.
See the serviceWordPress AuditYour production WordPress.
WordPress security audit: REST API, plugins (ACF and more), custom themes, exposures, and common access bypasses.
See the serviceLaravel AuditYour Laravel stack.
Laravel security audit: production debug, routes, policies, authentication, queue, storage, and typical exposures.
See the serviceAPI & webhook auditYour APIs and callbacks.
API and webhook security audit: REST, GraphQL, authentication, authorization, signature, rate limiting, introspection.
See the service