VerifiedDossier · Security
Controls, not slides
Audit, patching, access, attack surface. We show what closed. Untested work is never written as “100% secure”.
Security on file
Dossiers where risk is technical, not marketing. Hardening, consent, reduced surface.
Security protocol
From surface to control
Inventory. Patch. Access. Then WAF — not the other way around.
Inventory
Plugins, users, ports, backups.
Patch
Real CVEs, not vanity scans.
Access
Who can do what. Secrets out of the repo.
Routine
Updates, journal, incident.
Security is a process.
A homepage badge is not a control.
Portfolio questions
Q1.Do you pentest?
When the contract requires it. Otherwise: hardening and config audit — we write clearly what is and isn’t covered.
Q2.Is GDPR security?
Partly. Consent and data are another dossier, but they bind to access.
Same protocol
You have an attack surface. We’ll map it.
Get an audit quote. A risk list, not a green badge.
