CI/CD and software supply chain security

Assessment of the path from a commit to production: repositories, pipelines, runners, dependencies and build artefacts.

Infrastructure and cloud

The pipeline that builds and deploys your software holds more privileges than most administrators. It reads the source code, carries the signing keys and the cloud credentials and writes to production. It is also assembled from third-party actions, plugins and packages that change without notice.

We test this path the way an attacker would: what a contributor with minimal rights can do, what a malicious dependency or pull request can reach, and whether the artefact that is deployed is provably the one that was reviewed.

01Scope

What we test

  • Source control: branch protection, review rules, permissions, access tokens
  • Pipeline definitions: injection through untrusted input, unsafe triggers, pull request workflows
  • Runners: isolation, state that survives between jobs, network reach, self-hosted risks
  • Secrets: scope, exposure in logs, long-lived credentials against short-lived federation
  • Third-party actions, plugins and templates: pinning and provenance
  • Dependencies: dependency confusion, typosquatting, lock files, install scripts
  • Artefacts and registries: signing, provenance, access control
  • Deployment: separation of duties, approvals, infrastructure as code

02Approach

How the work is done

  1. Mapping

    We trace the path from a commit to production and list the systems, identities and secrets along it.

  2. Configuration review

    Repositories, pipelines and registries are reviewed against the OWASP Top 10 CI/CD Security Risks and the SLSA requirements.

  3. Attack simulation

    From the positions of an external contributor, an internal developer and a compromised dependency we attempt to reach secrets and to alter what is built. The work is done on forks and test projects wherever that proves the point.

  4. Hardening plan

    Changes are ordered by the attack paths they close. Each comes with the configuration that implements it.

Methodology

03

What you receive

  • Diagram of the delivery path with identities, secrets and trust boundaries
  • Attack paths with the configuration that enables each step
  • Hardening plan with ready-to-apply configuration
  • Executive summary for management
  • Technical report: every finding with evidence, CVSS 4.0 vector, CWE class and fix
  • Debrief call with your engineers
  • One retest of every finding within 60 days of the report
  • Attestation letter after the retest

04

What we need from you

  • A written authorisation from the owner of the systems, signed before work starts, that names the assets, the dates and the testers
  • Read access to the repositories and pipeline configuration in scope
  • A low-privilege developer account of the kind a new employee receives
  • A test project in which pipelines can be triggered freely
  • A list of the production systems the pipelines deploy to

05Standards

Standards behind the method

06Questions

Questions about this service

Will you run malicious code in our pipelines?

We run harmless proof code that shows what would be reachable, for example the name of a secret and not its value. Production pipelines are touched only where the rules of engagement allow it; most paths are proven in a test project with the same configuration.

We use a managed CI service. Is the provider not responsible for security?

The provider secures the platform. What you put on it is yours: permissions, triggers, secrets and third-party components. That is where attacks on pipelines succeed.

Does this include a software bill of materials?

We verify that the bill of materials your build produces is complete and matches the artefact. Generating and maintaining it is part of your build; we recommend how.

08Request

Tell us what needs testing

  • Website check free of charge
  • Reply within 1 business day
  • NDA before any technical detail
  • Fixed price for paid engagements
  • No obligation

Request an assessment

Describe the systems and the goal. We reply within 1 business day with clarifying questions and the next step.

Who to reply to

We reply to this address unless you choose another channel.

A sole proprietor writes their own name.

Preferred channel
What to assess
Services of interest

Choose all that apply.

Free check

We check your website free of charge

For businesses. If we find no problems, you receive the report free of charge as well. You pay for the report only when we find problems, and its price depends on their number and severity.

Terms of the free website security check

Application security

Infrastructure and cloud

Adversary simulation

AI, Web3 and cryptography

Programs and assurance

Application security

Free website security check

We look at your website from the outside, the way an attacker does, and check whether it can be broken into: weak settings, outdated software, exposed files, unsafe forms. The check is free of charge.

Application security

Web application penetration testing

We try to break into your web application the way a real attacker would: log in to the accounts of other people, read the data of other customers, change prices or orders. You learn what is possible before criminals do.

Application security

API security testing

An API is the channel through which your app, your website and your partners exchange data with your servers. We check that nobody can use it to read or change data that is not theirs.

Application security

Mobile application penetration testing

We examine your iOS or Android app and the servers behind it: what the app keeps on the phone, what can be extracted from it and whether its requests can be tampered with.

Application security

Secure code review

We read the source code of your product and find the mistakes that lead to a break-in, including those that cannot be seen from the outside.

Infrastructure and cloud

Cloud & Kubernetes security assessment

We check how your cloud is set up (AWS, Azure, Google Cloud, Kubernetes): who has access to what, which data is open to the internet and how far an attacker gets after the first mistake.

Infrastructure and cloud

Infrastructure penetration testing

We test your servers and your office network from the outside and from the inside: can an attacker get in, and once inside, reach the accounting system, the mail or the backups.

Infrastructure and cloud

External attack surface assessment

We find everything your company exposes to the internet, including what has been forgotten: old websites, test servers, leaked passwords. Then we show which of it can be attacked.

Infrastructure and cloud

CI/CD & supply chain security

We check the path your code takes from the developer to the customer: build servers, third-party libraries, access keys. Whoever controls that path controls your product.

Adversary simulation

Red team operations

A full-scale exercise. We play a real attacker with a goal, for example to reach customer data, and you see whether your defence notices and stops it.

Adversary simulation

Purple team exercises

We and your defenders work side by side: we execute an attack technique, your team checks whether it sees it, and the gaps in monitoring are closed on the spot.

Adversary simulation

Social engineering assessment

We test people, not machines: the phishing emails, calls and messages that attackers use to obtain passwords. You learn how many employees would be deceived and what to train.

AI, Web3 and cryptography

AI & LLM security testing

If your product has a chatbot or another AI model, we check whether it can be talked into revealing confidential data, breaking its own rules or acting on behalf of someone else.

AI, Web3 and cryptography

Smart contract audit

Before a smart contract holds money, we look for mistakes in its code that would let someone withdraw or freeze the funds. After deployment such mistakes cannot be corrected.

AI, Web3 and cryptography

Cryptography review

We check how your product encrypts data and protects keys: whether the right algorithms are chosen and whether they are applied correctly. A mistake here makes the encryption useless.

Programs and assurance

Bug bounty program management

A bug bounty is a program in which independent researchers look for vulnerabilities in your product and are paid for each one they find. We launch and run such a program for you.

Programs and assurance

Vulnerability disclosure program (VDP)

A public page and a procedure that tell researchers how to report a vulnerability to you safely. Without them reports get lost or arrive as threats. We set the process up and handle incoming reports.

Programs and assurance

Continuous penetration testing

Instead of one test a year, we test every significant change of your product throughout the year, so that a new vulnerability does not wait for months to be found.

Programs and assurance

Compliance-driven penetration testing

A penetration test scoped and documented to match what an auditor, a regulator or a large customer expects to see in a report: PCI DSS, DORA, NIS2, ISO/IEC 27001, SOC 2. Whether the report is accepted is decided by them.

Services of interest

Not sure yet

Choose this if you do not know which service you need. Describe the task in your own words, and we will suggest the service in the reply.

Domain or URL of the website or of the main system to test, for example app.example.com.

What needs testing, why now, and any deadline or compliance requirement. No passwords, keys or vulnerability details.

Confirmations

Do not send credentials, keys or details of a vulnerability through this form. Such material is exchanged later only as an encrypted archive, with the password sent separately.

Automated abuse check