Nobody tests security before launch.Will anyone try to break in before it goes live?
Security testing is often bought separately, late, or not at all.
A security review runs before every production deployment, with a deliberate attempt to break in, and each finding is reproduced, fixed and guarded by a test.Before it goes live, we try to break in the way an intruder would, and fix what we find.
No test finds everything, so the report lists what remains open, with an owner, the risk it carries and a mitigation plan. The review is our own, not an independent certified audit.
26 Aug 2026: six access paths found, two reproduced live, all fixed. source: the worked example
Go deeper: the security review
Scope: authentication and sessions; tenant isolation enforced in the database; authorisation on every route (is this record yours, not only are you logged in); uploads, URL ingestion, tokens and oversized bodies; key separation; rate limits on public endpoints; pinned dependencies; headers and exposed ports.
The six findings on our own product: a cancel that took an id and no owner; uploaded HTML served into an unsandboxed frame; password hashing on the event loop; URL ingestion with no address check; a malformed bearer token answering 500; one key doing both session-signing and secret-sealing. Each was fixed with a test that failed before the fix.