Application and API review
Authentication, authorization, input paths, data exposure, business logic, secrets and dependency risks across the agreed surface.
Security engineering services
ANULUM reviews software, infrastructure and AI-integrated systems within a written authorisation boundary. Findings are tied to affected assets, reproducible evidence, practical remediation and—when contracted—a controlled retest.
The exact methods follow the assets, threat model, business impact and agreed rules of engagement.
Authentication, authorization, input paths, data exposure, business logic, secrets and dependency risks across the agreed surface.
Controlled grey- or black-box testing under signed targets, exclusions, timing, safety limits, contacts and evidence handling.
Manual and tool-assisted inspection of high-risk paths, trust boundaries, cryptographic use, failure handling and dependency custody.
Identity, network, host, container, TLS, logging, backup and administrative paths reviewed against the agreed baseline.
Roles, escalation, containment, evidence preservation, communication, recovery and tabletop exercises before an incident demands them.
Prompt injection, retrieval poisoning, tool authorization, cross-role disclosure, model supply chain and unsafe failure behaviour.
| Object | What it records |
|---|---|
| Rules of engagement | Named systems, authority, methods, exclusions, safety stops, contacts, timing and evidence custody |
| Executive view | Business impact, affected boundary, prioritised decisions and material uncertainty |
| Technical findings | Reproduction, evidence, severity rationale, affected versions and safe handling notes |
| Remediation plan | Recommended control, owner, dependency, acceptance test and sequencing |
| Retest record | Exact fix and version tested, result, remaining exposure and closure decision |
Important boundary
Testing provides evidence about the agreed systems, methods and time window. It does not prove the absence of vulnerabilities, certify legal compliance or replace independent legal, regulatory or accredited certification advice.
See the deployment control set → Inspect the public Trust Centre →
A confidential scoping conversation can identify the target, evidence needs and safest useful level of review.