ERP and CRM permissions
Who in Logo, Mikro, Netsis, Business Central or SAP Business One may open new customer records, alter prices or edit bank details? We capture the answer in a compact role matrix built around segregation of duties.
Why would an attacker fight your firewall when an overlooked setting in a business application opens the way? Imagine a Kayseri furniture producer. All users work in Logo Tiger as administrators, a shortcut someone took years ago to get a report running. Orders from Trendyol and Hepsiburada flow in through an integration authenticated as a staff member, so that employee's login can never be switched off without halting sales. The payment gateway secret is hard-coded into the website, and the previous web agency still has a copy of the repository. Individually, none of these is a breach; together, they make one far more likely. Application security removes these weak spots from the software your business depends on. For packaged products the work centres on permissions, accounts and connections. For custom software we add the source code, its libraries and the release pipeline. Either way we coordinate with your software partner, work remotely and keep the application usable throughout.
Off-the-shelf and bespoke applications are both in scope. Packaged software mostly needs attention to permissions and connections; bespoke systems also need their code and build process reviewed.
Who in Logo, Mikro, Netsis, Business Central or SAP Business One may open new customer records, alter prices or edit bank details? We capture the answer in a compact role matrix built around segregation of duties.
Marketplace, e-invoice, courier and banking connections each run under a dedicated technical identity with the smallest set of rights that works. Someone resigning no longer takes an integration down with them.
Keys, connection strings and certificates are pulled out of repositories, configuration files and mail threads and placed in Azure Key Vault, AWS Secrets Manager or a suitable team vault. Anything that may have leaked is reissued.
Where supported, sign-in goes through Entra ID or Google; where not, personal accounts with a second factor. Removing a leaver becomes a single action.
Custom projects get automated library vulnerability checks, secret detection and lightweight static analysis in CI, catching a risky package before it reaches production.
Changes to supplier bank accounts, prices and user rights are recorded with who and when. That helps spot invoice fraud early and gives you evidence if a dispute arises.
Weaknesses cluster where applications connect, so we begin by charting those connections.
All applications, their users, every integration and its identity, and the locations of keys, captured on a single page.
Permissions, identities, secrets and logging reviewed application by application, with findings sorted by severity and a proposed remedy for each.
Gradual migration to dedicated identities, vaulted secrets and the new roles, timed with your vendor so no connection drops.
An onboarding checklist for future apps and integrations, automated pipeline checks and a yearly access review.
Orphaned credentials are the quiet risk. An integration still logging in as someone who left, an agency admin account nobody disabled, a gateway key committed to code: they trigger no alerts, yet sooner or later someone stumbles on them. Give every credential an owner, a reason to exist and a rotation date.
We draw up the role matrix with you and, given admin access, apply it remotely; otherwise your software partner applies it with our guidance. Changes always go through the application's own admin tools, never straight into its database.
Issue new keys in each seller centre, point the integration at them and revoke the old ones. The new keys then go into a vault with restricted viewing rights. Payment gateway credentials are handled the same way.
No, penetration testing is its own service within Software testing and QA. Application security builds the day-to-day controls around roles, secrets and libraries, which also makes it quicker to fix whatever a pentest uncovers.
A company with a few applications and half a dozen integrations normally needs one to two weeks for the assessment. Clear scopes get a fixed quote; open-ended work is billed at €55 per hour plus VAT against an agreed estimate.
Tell us which applications and integrations you run. We will suggest the most useful place to start.
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.