Web apps and APIs built to be attacked
Web apps and APIs with security in from the first sketch, and a pentest before every release.
Every request, checked
Designed against OWASP ASVS, OWASP API Security Top 10 and NIST SSDF.
Request pathbrowser to database
Browser
Headers from day one
Strict CSP, HSTS and the rest, set on the first deploy.
Edge
Input checked at the edge
Every request validated against a schema before it reaches your logic.
Sign-in
Sign-in and sessions
Secure cookies, sessions rotated at sign-in, rate limits on anything guessable.
Every route
Authorisation on every route
Checked on the server for every request and every object.
Data
Secrets out of the code
In your secret store. Never in the repo, the bundle or the logs.
Build
Dependencies on purpose
Pinned versions, a committed lockfile, a scan on every change.
Attackers go for the same few joints every time. We settle them in the design, before any feature code.
Portals, APIs and the tools behind them
Web applications
Portals, dashboards and account areas, with roles designed before the first screen.
APIs and back ends
TypeScript and Node, with authorisation checked on the server for every route and object.
Fast static sites
Astro sites that ship almost no JavaScript and keep a strict Content Security Policy on.
Internal tools
Admin panels and back-office tools, where one missing check exposes everything.
Integrations
Payments, email, webhooks and third-party APIs, signatures verified, secrets on the server.
Hardening what you have
We review your codebase the way we’d attack it, then fix what matters most.
TypeScript, front to back
Interface
AstroReactNext.js
Astro when a site should ship almost no JavaScript. React or Next.js for an application.
APIs and back end
TypeScriptNode.js
TypeScript end to end, so the interface and the API agree.
Data
PostgreSQL
Constraints and permissions live in the database as well as in the code.
Tools we use: Semgrep, CodeQL, Burp Suite and Playwright.
We build our own this way
vulnaratechnologies
.com - Static Astro, no inline scripts, a strict CSP, and it works without JavaScript.
Questions
Which stack will you use?
Usually TypeScript on both sides: Astro, React or Next.js up front, Node and PostgreSQL behind. Running something else? We’ll say before we quote whether we can do it well.
Can you take over an existing app?
Yes. We review the code and its dependencies, then agree with you what to fix first.
Tell us about your web app.
Send the idea, or the codebase you already have. We’ll reply with a written quote.










