IT security and governance for software companies
Security gaps found, fixed and proven closed.
We test your web apps and APIs by hand, review your cloud setup and show your developers how to fix what we find. Then we test again to prove it is closed.
Testing starts only with your written authorization. Secvillee is a Webvillee Technology company.
Authorization before any test starts.
Testing, never a scan sold as a test.
A finding closes only after the retest.
A lead and a separate reviewer on every engagement.
The problem
A security questionnaire can stall a deal you have already won.
Your customer sends a security questionnaire. It asks how you test your product and whether you fixed what you found. If you cannot answer clearly, the deal waits.
You ship fast. Your APIs are exposed. New AI features go live before anyone reviews their security.
A report does not answer the questionnaire. A fixed and verified finding does.
How it works
Find it. Fix it. Prove it.
- Cloud
- Application
- Network and infrastructure
- DevSecOps Later phase
- Governance
- Scope agreed
- Find it
- Fix it
- Prove it
- Closed
Step 01
Find it.
We test by hand, with your written authorization and an agreed scope. You get evidence you can reproduce. A scan alone is never sold as a penetration test.
Step 02
Fix it.
Every finding comes with a fix walkthrough in your developers’ own language. We go through it with them.
Step 03
Prove it.
We test again after the fix. A finding is closed only when the retest confirms it. We agree the retest with you before work starts.
- Found
- Fix shown
- Retested
- Closed
function getOrder(user, order) {- if (user) return order;+ if (user.id === order.ownerId) return order; throw new Forbidden();}Before any test
No testing starts until five things are agreed.
Agreed 01
Signed authorization
Agreed 02
Agreed scope
Agreed 03
Exclusions
Agreed 04
A test window
Agreed 05
An emergency stop contact
Services
Four services to start with
01 ↗
Web and API penetration testing
Manual testing of your applications, APIs, logins, roles and business logic. You get reproducible evidence and a verified retest.
02 ↗
Cloud security posture review
A read-only review of your AWS, Azure or Google Cloud accounts: identity, storage, logging, exposure and encryption. Every fix has an owner.
03 ↗
Governance and compliance readiness
An ISO/IEC 27001:2022 gap assessment, policy frameworks, DPDP Act 2023 readiness and help with customer security questionnaires. Advisory support.
04 ↗
Secure infrastructure setup and maintenance
We set up your firewall, security tools, secure remote access and security policies. Then we maintain them.
DevSecOps support, network and cloud testing, and AI application testing follow in later phases.
Domains
One program across five security domains.
Secvillee is built around five domains: cloud, application, network and infrastructure, DevSecOps and governance. Each domain has a named lead, so you do not need three or four separate vendors.
04 DevSecOps
Service
Later phase
People
A named person answers for your work.
Every engagement has a named lead and a separate reviewer for the report. You know who to call.
Secvillee is a Webvillee Technology company. Webvillee’s software, cloud, ERP and AI delivery teams stand behind us, so our fix advice is practical. If we test a system that Webvillee built, we tell you.
Named lead
Answers for the engagement.
Separate reviewer
Checks the report.
Webvillee delivery teams
Software, cloud, ERP and AI.
Our promise
What we promise, and what we do not.
We promise
- A report you can act on
- Fix walkthroughs
- A retest
- Testing only inside the scope you authorize in writing
We do not
- Issue a "secure" certificate
- Claim a status we have not been awarded
- Name a client without written permission
Tell us what you build.
Book a scoping call. We will talk through your systems, what is in scope and what we would test.