Since 1999

 

Security & Accessibility Assessment Services

We provide cybersecurity and digital accessibility assessments, including open book code review, for custom applications and government document programs that our client organizations build, run, or are responsible for maintaining compliance on. As a cybersecurity firm, we treat digital accessibility as an organizational risk management discipline: unaddressed ADA and WCAG gaps are a legal liability, and we apply the same independent, evidence-based review framework we use for application security to reduce that exposure.

Digital Accessibility Audits

ADA Title II and WCAG document accessibility review for government agencies, powered by our Metadata Minder platform — documented, independent evidence of an active compliance program, addressed through the same risk management framework we apply to application security to reduce your legal liability.

Learn More

Application Code Review

Open-book review of your custom application's source code, cloud infrastructure, and authentication and access control — the #1 issue on the OWASP Top 10, measured against NIST 800-63B — producing a signed report suitable for your own customers' security inquiries.

Learn More

ASVS & MASVS Application Security Reviews

Systematic assessment against OWASP's Application Security Verification Standard and its mobile counterpart MASVS, tailored to exclude requirements that don't apply to your context.

Learn More

SAMM Security Reviews

An evaluation of your organization's software security maturity using OWASP SAMM, in partnership with New Oceans Enterprises for the policy and vCISO side of the journey.

Learn More

How We Work With You

Every engagement starts with understanding your specific environment and compliance obligations, not a one-size-fits-all checklist. We tailor the standard to what actually applies to your system, and you get a detailed report with actionable recommendations your team can act on. We spend real effort making sure the work fits your situation, not the other way around.

Follow Up Training

Frank Rietta presenting on stage at SnowFroc 2020 on the topic of Web Application Security and Patching Production Now

For an additional modest fee, we provide follow up developer training and lunch and learns for our clients. We can even quiz and provide certificates for those who complete the training. Our clients have been able to use this service to satisfy their contractual obligations to ensure that proper developer security training has been delivered to the team.