News

Services

Source code analysis

We read your code thoroughly. AI searches large code bases for patterns and variants; we verify every finding by hand.

  • Manual review of security-critical paths
  • AI-assisted variant analysis across the whole code base
  • Structured around the OWASP WSTG, covering every category of the OWASP Top 10
  • More thorough than any test from outside, usually combined with a penetration test
  • Java, PHP, Ruby, Perl, Python, JavaScript and more; mobile: iOS, Android

Penetration testing

We attack your running application the way a real attacker would: with automated tools, by hand and with an eye for logic flaws.

  • Web applications, APIs and mobile apps
  • Authentication, session handling, business logic
  • Automated scans and manual attacks
  • Based on the OWASP WSTG, including the OWASP Top 10

Infrastructure analysis

Complex applications depend on their infrastructure. We examine the environment your application relies on.

  • Reconnaissance the way a real attacker does it: OSINT and information disclosure
  • AI orchestrates the tools and maps the attack surface
  • Port scans, TLS and certificates, DNS, management interfaces, cloud and test systems
  • Hardening recommendations worked out together with you

Consulting

Independent of any vendor, at every stage of a project, from the architecture concept to a secure development lifecycle.

  • Concept phase: encryption, access control, architecture
  • Regular reviews during development
  • Security processes in operations and introducing an SDL
  • AI in development: new risks and using AI tools safely

Training

Two separate trainings for developers, administrators and DevOps, each with roughly half of the time spent on hands-on exercises.

  • Practical Web Security (classic)
    Every vulnerability explained, exploited and fixed by hand, including the OWASP Top 10 (2025)
  • Practical Web Security (AI focus)
    Finding and fixing vulnerabilities with AI agents, and securing your own AI development environment
  • One to three days, with the agenda tailored to you, at your premises or in Bonn
  • All trainings in German or English