Service · Cybersecurity

Application security

Seen from outside, business software is usually shut reasonably tight; inside, the doors stand open. An ordinary user can see far more than the job needs, the link between the shop and the stock system runs on an administrator account because that was quickest to set up, and the key to the invoicing platform sits in a text file on the bookkeeper's desktop. We put that right whether you run Sage, Cegid, EBP, Odoo, Divalto or something built for you.

One integration
one account with minimal rights
Every 6 months
roles reviewed with the managers
No keys
left in configuration files
Change log
who edited, who exported

Where this service reaches

An application deserves two separate looks: as the place your data rests, and as the channel through which it can leave the company without anyone noticing.

Put your scope to an engineer

Roles and permissions

Rights tied to the job rather than full access for everyone. A sales rep does not need to pull the entire customer list in one click, nor to read the margin on every line.

Integration accounts

Every link, marketplace connector, payment gateway or accounting sync, gets its own account or app registration in Entra ID, carrying exactly the permissions it uses and nothing more.

API keys and tokens

Keys move out of configuration files into a secrets vault, are restricted to known addresses and are rotated on a schedule. Credentials for your e-invoicing platform get a scope matched to their single task.

App consents

We list the third-party applications your staff have granted access to Microsoft 365 or Google Workspace, often during a free trial nobody remembers, and tighten the rules for the next request.

Change log

Who altered a price, who exported the client list, who granted themselves rights, who edited a supplier's bank details. Without that trail there is nothing to examine afterwards.

Updates and dependencies

A regular upgrade routine tried out on a staging environment, plus watch over third-party libraries in anything written specifically for you.

The way an engagement runs

Roles are decided by the heads of department, not by IT. Our part is turning their decisions into configuration.

01

Application inventory

What software is running, who uses it, what it holds and where it sends things, including the small tools one department signed up for without mentioning it.

02

Role matrix

Together with the managers we set the roles and their reach. The result is a plain table you will be able to maintain without us.

03

Configuration

Roles applied, integrations moved onto their own accounts, secrets stored in a vault and logging switched on.

04

Periodic reviews

Twice a year we compare rights against actual jobs. People move between departments, and their access has a habit of travelling with them and never being taken away.

The integration account is often the most powerful account in the company. Full rights, a password that never changes, and nobody ever looking at its sign-ins. Whoever picks up that key gets everything at once, without needing to trick a single employee and without triggering any unusual-login alert.

Questions and answers

Common, seldom necessary. An account limited to a few modules is nearly always enough, and elevated rights can be granted for the length of an upgrade and then withdrawn. We change the password after each session and keep the record of connections.

In a secrets vault or inside the system that consumes them, never in a file on a desktop or in an email. The key carries only the permissions the link needs, and it is replaced as soon as anyone who could have seen it leaves.

This service covers configuration, permissions, integrations and dependencies. Digging through the code for exploitable flaws is penetration testing, which you can order separately under software testing and QA.

Yes, above all where bank details can be changed or data extracted. When the application accepts sign-in through Entra ID or Google Workspace, we hook it up to your company account: the second factor applies and access disappears automatically when someone leaves.

Take back control of rights in your software

List the applications you use and the links between them. We will tell you which end of the tidy-up to start from.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.