Skip to content
Myrran

Additional service

A clear look at the exposures in the systems you ask us to review.

Security work at Myrran is concrete: how accounts are protected, how an application handles input and permissions, how secrets are stored, and whether backups and access removal actually happen.

We review the systems in scope, explain the issues in the order they matter, and help implement the fixes that belong in the product or the administration process. We do not claim to be a certified auditor or a round-the-clock security operations centre.

Rounded navy clay shield with a sand-colored lock

Who it is for

Teams preparing a launch, companies that have accumulated shared passwords, and founders who want a sober review before they handle more customer data.

  • Scope first

    The domains, apps, and accounts included. Everything else is out of scope and said so.

  • Access and identity

    Who has administrator rights, whether recovery is possible, and whether former staff still can sign in.

  • Application risks

    Authentication, authorisation, exposure of data, and dependency issues visible in the agreed codebase.

  • Secrets and hosting

    Where credentials live, and whether environments are separated.

  • Backup and recovery

    Whether a restore has a documented path. We do not invent an uptime guarantee.

  • Remediation support

    We can fix issues in systems we are allowed to change, and write the rest as actions for your vendors.

Limits we will say out loud

  • This is not a penetration-test certificate, ISO audit, or regulated attestation.
  • We do not offer 24/7 monitoring or incident-response retainers on this website. If an engagement later includes them, the contract will say so.
  • We will not test systems you do not own or have not authorised in writing.

Questions

Only if the agreement says so and the rules of engagement are written down. A general review is broader and less invasive. We will not blur the two.