VANDANAlabs

Cybersecurity

Most security reports end with a PDF. Ours end with a fix.

Application and cloud security for teams who need the problem solved, not documented. We audit, test, and threat-model — and because we're engineers first, we can also write the patch, harden the infrastructure, and get you through the compliance review that's holding up your deal.

What's included

Everything the job actually needs.

  • Application security audits and secure code review
  • Penetration testing across web, mobile, API, and cloud surfaces
  • Cloud posture and IAM review — over-permissive roles, exposed storage, missing controls
  • Dependency and supply-chain scanning, with a plan for the findings
  • SOC 2, ISO 27001, HIPAA, and GDPR readiness
  • Remediation — we fix what we find, not just report it

Work like this

  • A security audit ahead of an enterprise procurement review
  • SOC 2 readiness for a startup blocked on a deal by a security questionnaire
  • Remediating someone else's penetration test report that nobody had time to action
  • Locking down a cloud account that grew for three years without a plan
  • Threat modelling a system before it ships rather than after the incident

Fixed price bands

  • Security audit$12k–$25k

    Find the holes, ranked by what an attacker would actually reach first.

    23 weeks

  • Audit & remediation$30k–$55k

    The audit, plus we fix what we find rather than handing you a PDF.

    47 weeks

  • Compliance programmeFrom $60k

    Get through the certification or the enterprise security review that is blocking a deal.

    1016 weeks

Fixed price for a fixed scope, not an hourly estimate. Extra integrations and urgency are published add-ons. Programmes larger than the top band are scoped and priced individually — there is no ceiling on what we take on.

Price your version →

Typical stack

OWASPThreat modellingSAST / DASTBurp SuiteSnykAWS IAMTerraform

Not dogmatic about it. If your team already runs something else, we work in your stack rather than making you adopt ours.

Also available

The rest of what we do.

One team across all of it. Adding a second workstream doesn't mean finding a second vendor.

Need cybersecurity?

Tell us what you're trying to build and what's riding on it. We'll come back with how we'd approach it and what it takes.

We reply to every serious enquiry within one business day