Capability · Epcotec

Security and GRC Engineering

AppSec review, OAuth/OIDC and IAM rollouts, hardening and audit-ready evidence for regulated environments. Delivered by named senior engineers, fixed scope, staging from week one.

Start a project All capabilities
What we deliver

Scope, in plain terms.

Application security reviews

Structured review of application code, dependencies and cloud infrastructure against actual attack paths. Findings arrive ranked by exploitability and cost to fix, not by scanner volume.

OAuth, OIDC and CIAM rollouts

Design and rollout of token lifetimes, scopes, session policy and permission inheritance across customer identity platforms, with migration paths that move existing users without forced password resets.

IAM design with least privilege

Role structures, entitlement reviews and break-glass access designed around what each workload actually needs. Defaults deny; exceptions are named, owned and reviewed on a published cadence.

Baselines, MFA and secrets management

Hardening applied as reviewed baselines: enforced MFA, managed secrets, restricted network paths and logging that survives audits. Each change is reversible and lands through normal delivery pipelines.

GRC evidence systems

Controls mapped to the artefacts that prove them, collected continuously instead of before audits. Evidence lives where auditors can reach it, with named owners and clear freshness.

Responsible disclosure intake

A working disclosure channel: published policy, triage workflow, response times and reviewer communications that turn inbound reports into fixed issues rather than reputational risk.

Rough time estimate

Window: 2-6 weeks

Team: 1 security eng

Complexity: M


Indicative only. A fixed price follows a free 30-minute scope review.

Get a fixed quote
Delivery process

Fixed scope. Weekly demos. Staging from week one.

Threat model and scope

We map the estate, rank real threats and agree scope, so effort goes to attack paths that matter rather than to checklist theatre.

Review and hardening sprints

Findings and fixes move together in short sprints. Each sprint closes with re-verification, so risk actually falls instead of accumulating in a backlog nobody reads.

Evidence automation

Controls are wired to collectors that produce artefacts continuously, mapped to the frameworks your auditors expect, with owners and refresh intervals recorded alongside each control.

Audit dry-run

We run the audit before the auditors do: evidence sampled, gaps closed and responses rehearsed, so the real cycle is confirmation rather than discovery.

Handover

Runbooks, ownership maps and a walk-through leave your team able to operate the controls and extend the evidence system without us on call.

Benchmark deliveries

Proven in this discipline.

Audit evidence in hours

A GRC evidence system replaced annual evidence hunting. Audit cycles dropped from weeks of collection to hours of sampling, with every control traceable to a current artefact.

CIAM with zero data egress findings

A customer identity platform built with permission inheritance passed penetration testing with zero data-egress findings, holding its access boundary across every downstream integration from day one.

Scoped retrieval in a protected boundary

OAuth and OIDC scoped retrieval shipped inside a protected government boundary, issuing narrowly scoped tokens and recording every access decision for review without slowing authorised users.

More evidence in the delivery history and the complete 734-engagement register.

FAQ

Asked before signing.

Do you work to our existing frameworks?

Yes. We map controls to the standards your auditors already use, ISO 27001, Essential Eight, SOC 2 or internal policy, rather than asking anyone to restate work.

What does a typical engagement cost?

Most engagements run two to six weeks with one security engineer. Scope drives cost: a focused hardening sprint costs less than a full evidence system build.

Can you work alongside our developers?

Yes. We review, pair and hand over inside your delivery pipeline, so fixes land as normal pull requests and your team owns every control afterwards.

How do you handle confidential findings?

Findings go to named owners only, encrypted in transit and at rest. Nothing is disclosed externally without written instruction, and responsible disclosure runs through agreed channels.

Talk to the engineers.

No account managers. Your message lands with the people who would deliver it, and you get a straight answer within one business day.

Book a discovery call