Security engineering services


Find the weakness. Preserve the evidence. Prove the fix.

ANULUM reviews software, infrastructure and AI-integrated systems within a written authorisation boundary. Findings are tied to affected assets, reproducible evidence, practical remediation and—when contracted—a controlled retest.

01Authority signed02Surface bounded03Findings evidenced04Fixes retested

Six service lines

The exact methods follow the assets, threat model, business impact and agreed rules of engagement.

Reproducible findings
01

Application and API review

Authentication, authorization, input paths, data exposure, business logic, secrets and dependency risks across the agreed surface.

02

Authorised penetration testing

Controlled grey- or black-box testing under signed targets, exclusions, timing, safety limits, contacts and evidence handling.

03

Security-focused code review

Manual and tool-assisted inspection of high-risk paths, trust boundaries, cryptographic use, failure handling and dependency custody.

04

Infrastructure hardening

Identity, network, host, container, TLS, logging, backup and administrative paths reviewed against the agreed baseline.

05

Incident readiness

Roles, escalation, containment, evidence preservation, communication, recovery and tabletop exercises before an incident demands them.

06

AI and agent security

Prompt injection, retrieval poisoning, tool authorization, cross-role disclosure, model supply chain and unsafe failure behaviour.

The deliverable is a decision packet

ObjectWhat it records
Rules of engagementNamed systems, authority, methods, exclusions, safety stops, contacts, timing and evidence custody
Executive viewBusiness impact, affected boundary, prioritised decisions and material uncertainty
Technical findingsReproduction, evidence, severity rationale, affected versions and safe handling notes
Remediation planRecommended control, owner, dependency, acceptance test and sequencing
Retest recordExact fix and version tested, result, remaining exposure and closure decision

How we work

  1. Authorise and scope Confirm ownership or delegated authority, systems, data, methods, exclusions and emergency stop contacts in writing.
  2. Map and test Establish the attack surface and apply controlled review or testing while preserving a clear evidence chain.
  3. Report and decide Separate verified findings, reasonable hypotheses and unavailable evidence; agree remediation priorities.
  4. Retest and close Verify contracted fixes against the exact changed system and record residual risk or further work.

Important boundary

A security review is not a certificate.

Testing provides evidence about the agreed systems, methods and time window. It does not prove the absence of vulnerabilities, certify legal compliance or replace independent legal, regulatory or accredited certification advice.

See the deployment control set → Inspect the public Trust Centre →

Define the authority boundary before sharing sensitive detail.

A confidential scoping conversation can identify the target, evidence needs and safest useful level of review.

Scope a security engagement Open procurement questions →