Service · Cybersecurity

Application security

Why would an attacker fight your firewall when an overlooked setting in a business application opens the way? Imagine a Kayseri furniture producer. All users work in Logo Tiger as administrators, a shortcut someone took years ago to get a report running. Orders from Trendyol and Hepsiburada flow in through an integration authenticated as a staff member, so that employee's login can never be switched off without halting sales. The payment gateway secret is hard-coded into the website, and the previous web agency still has a copy of the repository. Individually, none of these is a breach; together, they make one far more likely. Application security removes these weak spots from the software your business depends on. For packaged products the work centres on permissions, accounts and connections. For custom software we add the source code, its libraries and the release pipeline. Either way we coordinate with your software partner, work remotely and keep the application usable throughout.

Secrets vault
instead of keys in code or email
Job-based roles
rather than blanket admin rights
Library checks
on every build
Change history
for IBANs, prices and user rights

What the work covers in practice

Off-the-shelf and bespoke applications are both in scope. Packaged software mostly needs attention to permissions and connections; bespoke systems also need their code and build process reviewed.

Agree the scope with the engineer who will do the work

ERP and CRM permissions

Who in Logo, Mikro, Netsis, Business Central or SAP Business One may open new customer records, alter prices or edit bank details? We capture the answer in a compact role matrix built around segregation of duties.

One account per integration

Marketplace, e-invoice, courier and banking connections each run under a dedicated technical identity with the smallest set of rights that works. Someone resigning no longer takes an integration down with them.

Vaulted secrets

Keys, connection strings and certificates are pulled out of repositories, configuration files and mail threads and placed in Azure Key Vault, AWS Secrets Manager or a suitable team vault. Anything that may have leaked is reissued.

Application sign-in

Where supported, sign-in goes through Entra ID or Google; where not, personal accounts with a second factor. Removing a leaver becomes a single action.

Build pipeline checks

Custom projects get automated library vulnerability checks, secret detection and lightweight static analysis in CI, catching a risky package before it reaches production.

Audit trail inside the app

Changes to supplier bank accounts, prices and user rights are recorded with who and when. That helps spot invoice fraud early and gives you evidence if a dispute arises.

How we approach the job, from first call to handover

Weaknesses cluster where applications connect, so we begin by charting those connections.

01

Chart

All applications, their users, every integration and its identity, and the locations of keys, captured on a single page.

02

Assess

Permissions, identities, secrets and logging reviewed application by application, with findings sorted by severity and a proposed remedy for each.

03

Fix

Gradual migration to dedicated identities, vaulted secrets and the new roles, timed with your vendor so no connection drops.

04

Sustain

An onboarding checklist for future apps and integrations, automated pipeline checks and a yearly access review.

Orphaned credentials are the quiet risk. An integration still logging in as someone who left, an agency admin account nobody disabled, a gateway key committed to code: they trigger no alerts, yet sooner or later someone stumbles on them. Give every credential an owner, a reason to exist and a rotation date.

Frequently asked questions

We draw up the role matrix with you and, given admin access, apply it remotely; otherwise your software partner applies it with our guidance. Changes always go through the application's own admin tools, never straight into its database.

Issue new keys in each seller centre, point the integration at them and revoke the old ones. The new keys then go into a vault with restricted viewing rights. Payment gateway credentials are handled the same way.

No, penetration testing is its own service within Software testing and QA. Application security builds the day-to-day controls around roles, secrets and libraries, which also makes it quicker to fix whatever a pentest uncovers.

A company with a few applications and half a dozen integrations normally needs one to two weeks for the assessment. Clear scopes get a fixed quote; open-ended work is billed at €55 per hour plus VAT against an agreed estimate.

Find the weak spots inside your business software

Tell us which applications and integrations you run. We will suggest the most useful place to start.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.