Skip to content
Blocify

Services

Security, QA & Compliance

Find it before somebody else does.

Security work is cheapest when it is continuous and most expensive when it is a surprise. We run it as part of delivery — threat models at design time, automated scanning in the pipeline, and a review before anything with consequence ships.

We also run it as a standalone service for teams who built elsewhere and now need an independent opinion: application penetration testing, cloud configuration review, smart-contract audit preparation and a remediation plan with effort estimates attached.

On the compliance side we do the engineering half of the work — the evidence, the controls, the documentation — so your auditor and your legal counsel are arguing about paperwork rather than about your architecture.

Capabilities

What this practice actually covers.

01

Application security review

Manual review plus tooling across the surfaces that actually get attacked: authentication, authorisation, tenancy boundaries and the integration layer.

  • Authentication, session and access-control review
  • Multi-tenant isolation and privilege-escalation testing
  • Injection, deserialisation and file-handling review
  • Dependency and supply-chain analysis with SBOM
02

Penetration testing

Time-boxed, scoped testing against a staging environment, reported in a format your customers' security questionnaires will accept.

  • Web application and API penetration testing
  • Mobile application testing including local storage and transport
  • Cloud and infrastructure configuration review
  • Retest after remediation, included
03

Smart contract audit preparation

Static analysis, invariant testing and internal review that removes the findings you should never have paid an external auditor to discover.

  • Slither, Echidna and Foundry invariant campaigns
  • Economic and governance attack modelling
  • Internal review by a second senior contract engineer
  • External audit coordination and finding remediation
04

AI system security

A newer surface with old failure modes. We test what the model can be talked into and what it can reach when it gets there.

  • Prompt-injection and jailbreak testing against your guardrails
  • Tool-permission and data-exfiltration boundary review
  • Training and retrieval data leakage checks
  • Red-team report with reproducible cases
05

QA automation

Testing that runs without a human remembering to run it, on every commit, with results a product manager can read.

  • End-to-end suites with Playwright across critical journeys
  • API contract testing and mocked integration environments
  • Load, soak and chaos testing to find the real ceiling
  • Release regression packs and go/no-go criteria
06

Compliance engineering

The technical evidence behind the certificate: logging, access control, data mapping, retention and the documentation to prove it.

  • GDPR data mapping, retention policy and DPA support
  • ISO 27001 and SOC 2 control implementation and evidence
  • NIS2 and DORA readiness assessment for regulated sectors
  • EU AI Act classification and technical documentation

Deliverables

What lands in your account.

  • Findings report with severity, reproduction steps and fix effort
  • Executive summary suitable for customers and investors
  • Automated security and QA checks committed to your pipeline
  • Control and evidence documentation pack
  • Retest report confirming remediation

Stack

  • Burp Suite
  • OWASP ZAP
  • Semgrep
  • Trivy
  • Slither
  • Echidna
  • Playwright
  • k6
  • Snyk

Chosen per engagement, not by habit. If your team already runs something else and it works, we work in it rather than around it.

Staffed by

Every engagement in this practice is delivered by a named team you interview yourself — designed, hired and led through our team-building practice.

See the people

Engagement

Three ways to start.

Indicative starting figures for a typical engagement, excluding VAT. Your actual number comes from a written scope — but it will be in the same neighbourhood.

Security Assessment

An independent opinion before a launch or a raise.

Duration
2 weeks
Team
2 security engineers
From
€16,500

Compliance Readiness

Getting evidence-ready for ISO 27001 or SOC 2.

Duration
6–10 weeks
Team
Engineer + consultant
From
€34,000

Continuous Security

Keeping the pipeline and the posture healthy.

Duration
Rolling
Team
Fractional security engineer
From
€6,900 / month

FAQ

Questions about this practice.

Ask us directly
Can we share the report with customers?
Yes. Every assessment includes an executive summary written to be shared with customers, partners and investors, alongside the technical detail for your engineers.
Do you certify us for ISO 27001 or SOC 2?
No — certification comes from an accredited auditor. We do the engineering half: implementing controls, producing evidence and writing the technical documentation they will ask for.

Get started

Tell us what you need built — or who you need building it.

Send us the situation as it actually is. You get back a shaped engagement, a named team, a fixed timeline and a number you can put in front of a board.

A partner replies within one business day — with questions, not a sales sequence.