Skip to main content

Dev Station Technology

Security and governance

Building software that survives the questionnaire

We are engineers who build to a security standard, not a penetration testing firm. On a Norwegian education platform that meant national data protection rules, security testing across SPT, SSAT and NVA, and a migration of sensitive records with nothing lost.

Book a 30-minute scoping call Read what we do not do

If you need a certified penetration test or an ISO 27001 certificate, we will point you at firms who issue those.

What a client security questionnaire usually asks.
Where does our data sit Region, and who can reach itAnswerable
Who has access Named people, revocableAnswerable
How are secrets stored Vault, not config filesAnswerable
What is logged And kept for how longAnswerable
What happens on a breach Written, and rehearsedOften not
The last row is where most deals stall.

Security work we have delivered

  • Norwegian EdTechSPT, SSAT and NVA security testing
  • National data lawEducational records, compliance met
  • HashiCorp VaultSecrets on a production platform
  • Zero records lostMigration of sensitive data

Where the line is

We build securely. We do not certify.

Security services cover a wide range and buyers often need two different suppliers. Being clear saves you a wasted procurement round.

Not us

Certification and offensive testing

  • Issuing an ISO 27001 or SOC 2 certificate
  • Certified penetration testing with a signed report
  • Red team exercises against your organisation
  • Acting as your data protection officer

These need accredited firms. We work alongside them and fix what they find.

Us

Engineering to the standard

  • Access control designed and enforced server side
  • Secrets in a vault, credentials rotated, nothing in the repository
  • Data residency and retention built to the rule that applies to you
  • Security testing during build, as the Norwegian platform had
  • Audit trails that answer who did what, when, to which record
  • Remediation of findings from someone else's report

This is the work that makes an audit survivable, and it happens during the build rather than after it.

Plain definitions

Two questions that sort out which supplier you need

Security is three trades sharing one word. Buying the wrong one wastes a quarter and leaves the original problem in place.

Audit, penetration test, or secure development?

An audit checks your organisation against a framework and produces findings against controls. A penetration test attacks a running system and produces a report of what got through. Secure development is building the thing so that both of those go well.

They happen at different times and by different people. A pen test on software that was never built with access control in mind produces a long report and an expensive quarter. We are the third trade, and we work alongside the other two.

What do SOC 2, ISO 27001 and Cyber Essentials ask of the software?

Less than people expect, and more specifically than people expect. Access controlled and reviewed, credentials managed and rotated, changes logged, data classified with a retention rule, backups tested, and an incident process somebody has actually read.

Most of a certification is organisational rather than technical. The software side is a short list, it is cheap to build in from the start, and it is expensive to retrofit three weeks before an assessment. That timing gap is the whole reason this page exists.

What we build

Six controls we put in by default

Access enforced at the server
Permissions checked where data is served, not hidden in the interface. A hidden button is not a control.
Secrets management
HashiCorp Vault on the IoT platform, or the cloud provider service. Rotation planned rather than promised.
Data residency and retention
Storage in the region your rule requires, with deletion schedules that actually run.
Audit trail
Who did what, when, on which record, kept long enough to answer a question a year later.
Security testing during build
On the Norwegian platform this covered SPT, SSAT and NVA alongside development rather than as a gate at the end.
Incident runbook
Written steps for the day something goes wrong, agreed with the people who would have to follow them.

What people ask us for

Six situations that bring companies here

Every one of these arrives with a deadline attached, which is usually somebody else deadline.

A client questionnaire you cannot answer
Ninety questions from a prospect procurement team, and four of them stop the deal. Usually access review, secret handling, logging and the breach process.
Findings from somebody else test
A pen test or audit report already exists and needs fixing. We remediate against other firms reports regularly and we do not argue with the finding to protect a build.
Entering a regulated market
Where the software has to meet rules it was never designed for. On the Norwegian platform this meant national data protection law covering records about children.
A residency demand from a customer
Data has to sit in a named region, provably, with access limited to named people. Straightforward to build and awkward to retrofit.
An access model that leaks
Where permissions are enforced in the interface and somebody has noticed. This is a modelling problem far more often than a coding one.
An incident with no runbook
The question is not whether something will go wrong. It is whether the first hour is spent responding or deciding who is in charge.

Tell us which questionnaire you are stuck on

Three fields. An engineer reads it, not a sales rep. You get an answer within one working day.

  • We look at the questions you cannot currently answer
  • You get a written view on what to fix, with a cost band
  • No obligation, and no phone number needed to start

Our work

Sensitive records, national rules, no losses

Case study, Norway

A school data platform rebuilt to meet the rules it had outgrown

The client ran a system that could no longer meet current security standards, holding years of records about children. A previous vendor had missed the delivery date and the deadline with schools was contractual. We rebuilt the platform in modules, ran security work covering SPT, SSAT and NVA, put a separate team on the migration, and stayed on for 60 days of warranty after go-live.

  • .NET
  • Angular
  • AWS
  • SPT
  • SSAT
  • NVA
Records lost in the migration
Zero
Compliance with national data protection law
Met
Warranty support after go-live
60 days

Technology

The controls we put in, and what they run on

Six things, all of them cheaper during a build than after an assessment.

Access enforcement
Checked at the server on every request, through Keycloak or Azure AD B2C. A hidden button is not a control and never has been.
Secrets and credentials
HashiCorp Vault on the IoT platform, or the cloud provider service, with rotation planned rather than promised.
Encryption and residency
In transit and at rest, in the region your rule requires, inside a tenant you own.
Audit trail
Who did what, when, to which record, retained long enough to answer a question a year later rather than a week later.
Pipeline checks
Dependency scanning and secret detection inside the build, so a known-vulnerable package fails the pipeline instead of reaching production.
Security testing during build
On the Norwegian platform this covered SPT, SSAT and NVA alongside development rather than as a gate at the end.

Who does the work

Twenty engineers, eight of them senior

Security work needs people who will tell you what is wrong with something they built themselves. That is a cultural property rather than a certification, and it is easier to maintain in a small team.

Engineers in Ho Chi Minh City
20
Senior engineers
8
Average experience
5+ yrs
Working with US, UK and EU teams
10+ yrs

You interview whoever we put forward. Ask what they would find first if they attacked their own last project, and see whether the answer is specific.

How we work

Five engagement models, and you pick how much you keep

The models differ in one thing: how much of the management you hand over. Everything else, including who owns the code, is the same in all five.

Changing model later is normal. Augmentation into a dedicated team is the common direction, and the people stay.

Engineers join your team and work inside your process, your board and your code review.

Team control
You manage the day to day
Pricing
Monthly per person, by role and seniority
Minimum
1 month

A team that works only on your product, with a lead on our side running delivery.

Team control
Shared. Our lead runs delivery, you set priorities
Pricing
Monthly per role, lead included
Minimum
3 months

A long-term engineering site under your standards, where we carry recruitment, HR, payroll and equipment.

Team control
You direct the work, we run operations
Pricing
Monthly per role plus site costs
Minimum
6 months

One price for a scope that is genuinely settled, with the overrun carried by us.

Team control
We deliver, you accept against written criteria
Pricing
Fixed bid, paid against milestones
Minimum
Project based, usually 10 to 14 weeks

Everything in the centre model, with the whole team moving into your own Vietnamese entity on an agreed date.

Team control
Transfers from us to you
Pricing
Monthly per role, transfer price agreed up front
Minimum
2 to 6 years

FAQs

Questions we get on the first call

Can you give us an ISO 27001 certificate?

No. Certification comes from an accredited body, and anyone telling you otherwise is selling something else. We build to the controls and help you answer the evidence questions.

Do you do penetration testing?

Not as a certified service. We commission or work alongside a testing firm, then fix what the report finds. Marking our own homework would not be worth much to you.

Can you help with GDPR?

On the engineering side, yes: residency, retention, deletion, access control and audit trails. Legal interpretation belongs with your counsel or DPO.

What if a report has already found problems?

Send it. Remediation is straightforward work and we would rather start from a real finding than a general assessment.

Do you sign customer security agreements?

Yes, including NDAs before repository access, which every engineer on your project signs.

Where does our data sit?

In your own cloud tenant, in the region your policy requires, with access you grant and can revoke.

What does this cost, and how long does it take?

Answering a stuck questionnaire and fixing what it exposes is usually two to four weeks. Remediating a full pen test report, or building residency and audit trail into a system that has neither, is a project in its own right. Rebuilding a system that cannot meet the rules at all is larger again, as the Norwegian platform was. Pricing follows the engagement model above.

Can you get us SOC 2 or ISO 27001?

No. Those certificates come from accredited assessors and we are not one, so anybody telling you a development firm can issue them is worth walking away from. What we do is build the technical controls those frameworks look for, and fix what an assessor finds. We will name firms who do the assessment.

What about NIS2, DORA or the UK Cyber Essentials scheme?

Same answer with different letters. The scheme decides what evidence you must produce; we build the software so the evidence exists. Take the question of whether a regime applies to you to counsel, because scope questions in these regimes turn on your sector and size rather than on your technology.

Send us the questions you cannot answer

A client questionnaire or an audit finding is the fastest way to see what needs building. Thirty minutes and you will know what is engineering work and what needs an accredited firm.

Book a 30-minute scoping call Read what we do not do

Let's Talk