services
Cybersecurity for websites and web applications
Audit, leak and breach protection, security headers, request limits, encryption, backups. So the product is not broken in its first week and the customer base is not stolen.
Order: CybersecurityWhat we check and configure
Security headers (CSP with nonce, HSTS, X-Frame, Permissions-Policy), rate limits and bot protection for forms, client and server validation, secret storage, access rights, PII-free logging, TLS, backups and recovery, dependency updates.
From practice
VEYA: per-request CSP nonce with strict-dynamic, zero PII in logs — the tracking function rejects personal-data keys, gateway contract tests. VARENO: passwordless magic-link login, 6-role RBAC, audit_log. FluxrBot: lead e-mails stored as salt plus hash, cryptographically signed licences, minisign OTA updates.
Format
A one-off audit with a report and fixes, or ongoing support with monitoring. Penetration testing by agreement and only with the owner's written permission.
FAQ
My site is on WordPress — can you help?
Yes: updates, hardening, WAF, backups, plugin review. Often cheaper than migrating.
Do you do penetration tests?
Yes, within an agreed scope and with written permission. Without the system owner's permission — no.
request
Tell us the idea. A couple of lines is enough.
We reply within a business day in the messenger you choose. No newsletters.
Or straight to Telegram: @moreteploe