Web apps and APIs built to be attacked

Web apps and APIs with security in from the first sketch, and a pentest before every release.

Every request, checked

Designed against OWASP ASVS, OWASP API Security Top 10 and NIST SSDF.

Request pathbrowser to database

  1. Browser

    Headers from day one

    Strict CSP, HSTS and the rest, set on the first deploy.

  2. Edge

    Input checked at the edge

    Every request validated against a schema before it reaches your logic.

  3. Sign-in

    Sign-in and sessions

    Secure cookies, sessions rotated at sign-in, rate limits on anything guessable.

  4. Every route

    Authorisation on every route

    Checked on the server for every request and every object.

  5. Data

    Secrets out of the code

    In your secret store. Never in the repo, the bundle or the logs.

  6. Build

    Dependencies on purpose

    Pinned versions, a committed lockfile, a scan on every change.

Attackers go for the same few joints every time. We settle them in the design, before any feature code.

Portals, APIs and the tools behind them

  • Web applications

    Portals, dashboards and account areas, with roles designed before the first screen.

  • APIs and back ends

    TypeScript and Node, with authorisation checked on the server for every route and object.

  • Fast static sites

    Astro sites that ship almost no JavaScript and keep a strict Content Security Policy on.

  • Internal tools

    Admin panels and back-office tools, where one missing check exposes everything.

  • Integrations

    Payments, email, webhooks and third-party APIs, signatures verified, secrets on the server.

  • Hardening what you have

    We review your codebase the way we’d attack it, then fix what matters most.

TypeScript, front to back

  1. Interface

    AstroReactNext.js

    Astro when a site should ship almost no JavaScript. React or Next.js for an application.

  2. APIs and back end

    TypeScriptNode.js

    TypeScript end to end, so the interface and the API agree.

  3. Data

    PostgreSQL

    Constraints and permissions live in the database as well as in the code.

Tools we use: Semgrep, CodeQL, Burp Suite and Playwright.

We build our own this way

  • imgosint

    Status: Coming soonmacOS · Windows

    • A local console on 127.0.0.1 only. Nothing is sent to Vulnara.
    About imgosint
  • vulnaratechnologies.com

    • Static Astro, no inline scripts, a strict CSP, and it works without JavaScript.
Which stack will you use?

Usually TypeScript on both sides: Astro, React or Next.js up front, Node and PostgreSQL behind. Running something else? We’ll say before we quote whether we can do it well.

Can you take over an existing app?

Yes. We review the code and its dependencies, then agree with you what to fix first.

Tell us about your web app.

Send the idea, or the codebase you already have. We’ll reply with a written quote.