Skip to content
Security

Security work that holds up in production.

We run pen tests, review code, audit infrastructure, and respond to incidents. Every report is written by the engineer who did the testing, with reproduction steps for each finding.

Security as standard

We secure what we build, and what you already have.

Security is part of how we build, not a separate service bolted on at the end. We also take on audit, hardening, and incident work on software other teams have written.

  • Penetration testingWeb, mobile, and API testing. You get a written report with clear reproduction steps for every finding.
  • Secure code reviewLine-by-line review using Semgrep, CodeQL, and an engineer who understands the framework you're built on.
  • OWASP Top 10 hardeningAuth, injection, SSRF, deserialization, SSJI. Baseline defenses and regression tests so issues don't come back.
  • Infrastructure auditsAWS, GCP, Kubernetes. IAM, network policy, secrets, and CI pipeline review with written remediation.
  • Incident responseWhen something is actively wrong: triage, containment, forensic notes, and a post-incident writeup for your team.
  • SOC 2 & ISO 27001 readinessControls mapping, evidence collection, and the engineering work that closes findings before your auditor arrives.
Responsible disclosure

Found something in our software? Tell us.

If you believe you have found a security vulnerability in any Leyecodes-operated service or in software we ship, we want to hear from you. We will acknowledge reports within one business day and coordinate a fix before any public write-up.

How to report

  • Email security@leyecodes.com with a clear description and reproduction steps.
  • If you need encryption, request our PGP key in your first message.
  • Please do not test against production data belonging to our clients. Use synthetic accounts where possible.

What we commit to

  • Acknowledge your report within one business day.
  • Keep you updated while we triage and remediate.
  • Credit you in any advisory we publish, unless you prefer to stay anonymous.
  • Not pursue legal action against researchers acting in good faith within the boundaries of this policy.

Out of scope

  • Automated scanner output without a working proof of concept.
  • Denial-of-service, social engineering, and physical attacks.
  • Clickjacking on pages with no sensitive state, and missing best-practice headers on static marketing routes.
Request a security audit

Have a project in mind?

Tell us about it. We reply within one business day.

You'll get a real reply from the people who would actually build it, not a templated proposal.