A free security assessment of how your software is built, shipped and run.
We look at your infrastructure, your CI/CD pipeline, how secrets move between development and production, and how your GitHub organisation is locked down. You get a short written report and a call that ranks the fixes, at no cost and with no obligation to hire us.
The breaches in this year’s headlines mostly did not need a clever exploit. A token sat in a CI log. A developer’s laptop held production credentials. A GitHub Action pulled a third-party script by tag, and the tag was moved. A staging database was a copy of production with the same password and an open port. Each of these is a habit, not a single mistake, and habits are what a review can find.
So we review the path your code takes, end to end. Who can push to the main branch, and whether a review is required. Which secrets your pipeline can read, how long they live and where they are printed. Whether development, staging and production share accounts, keys or data. What runs on the server, what is open to the internet, and whether anyone would notice a login at three in the morning.
Most breaches start with a habit, not an exploit. Habits are what a review can find.
The report is written for the developers who will act on it, ranked by what an attacker would reach first. Each item says what we found, why it matters to you and the exact setting, policy or line of config that fixes it. Some fixes take ten minutes, like branch protection or turning on secret scanning; others, like moving to short-lived cloud credentials in CI, take a sprint. We say which is which.
Security changes that slow developers down get switched off within a month. We run our own products on GitHub Actions, AWS, Google Cloud and cPanel servers, so the advice is the version we live with: pre-commit secret checks that are quick, required reviews that do not block a hotfix, and environment rules a new hire can follow on day one.
What we look at
- 01
Infrastructure and environments
Identity and access, exposed ports and storage, logging, backups, and how cleanly development, staging and production are separated: accounts, credentials, data and who can reach each one.
Cloud · servers · dev / prod - 02
CI/CD and secrets
Where secrets are stored, which jobs can read them, whether they leak into logs or build artefacts, pinned versus floating third-party actions, and whether deploys use long-lived keys or short-lived OIDC credentials.
Pipelines · tokens · .env - 03
GitHub hardening and developer habits
Branch protection and rulesets, required reviews and status checks, CODEOWNERS, two-factor sign-in, secret scanning and push protection, Dependabot, org and repo permissions, and a short list of habits your team can adopt without losing pace.
Branches · reviews · 2FA
In every assessment
- Infrastructure, network exposure and access review
- Development, staging and production separation
- Secrets and .env handling across laptops, CI and servers
- CI/CD pipeline permissions, third-party actions and deploy keys
- GitHub branch protection, rulesets, 2FA and secret scanning
- Developer workflow changes ranked by effort and risk
- A written report and a walk-through call, free
- An NDA signed before we see anything, if you want one
Before you book
- Is the assessment really free?
- Yes. The review, the written report and the walk-through call cost nothing, and there is no obligation afterwards. If you want help making the fixes, we quote that separately and in writing. Many teams make the fixes themselves from the report, and that is fine with us.
- What access do you need?
- As little as possible. Most of the review works from a call, screenshots of your settings, and read-only access you grant and can revoke: a read-only cloud role, or viewer access to your GitHub organisation. We never ask for production passwords or secret values, only where they are kept and who can read them.
- Is this a penetration test?
- No. We review how your systems and pipelines are configured, with your permission, from the inside. A penetration test attacks from the outside and is a separate, paid engagement with its own written authorisation. If your situation calls for one, we will say so.
- What does GitHub hardening cover?
- Branch protection or rulesets on main and release branches, required pull-request reviews and status checks, CODEOWNERS for sensitive paths, two-factor sign-in for every member, secret scanning with push protection, Dependabot alerts, least-privilege repo and org roles, and workflow permissions set to read-only by default.
- How do we book it?
- Fill in the form below or message us on WhatsApp. We reply within one working day with a few meeting times in your time zone and a short list of what to have ready. The review itself usually takes about a week from that first call.
Tell us your company and what you run.
Your stack, where it is hosted, how you deploy, and anything already worrying you. We reply within one working day with meeting times in your time zone. Prefer WhatsApp? Message us there.
Lattice Nepal Pvt. Ltd. · Bharatpur · Kathmandu · info@latticenepal.com