Security for your applications and websites
Security reviews and hardening for websites, web apps and mobile apps, plus a security baseline in everything we build.

Overview
Most breaches at small and mid-sized businesses come from ordinary gaps: an outdated plugin, a leaked key, an admin account nobody removed, a form with no validation. We find those gaps in your code and configuration, fix them, and leave you with a clear record of what changed.
- Typical timeline
- 1 to 3 weeks
- Quote
- Fixed, in writing, within 2 business days
- Payment
- 50% deposit to start
Signs it is time.
- Your site runs on plugins nobody has updated in months
- Former staff or agencies may still have access
- You collect personal information and are unsure about POPIA
- A client or insurer has asked about your security practices
What you get, and what you do not.
Included
- Review against the OWASP Top 10
- Dependency and known-vulnerability scan
- Search for exposed secrets and keys
- Security headers, HTTPS and cookie configuration
- Access review for hosting, domains and admin accounts
- Form, API and authentication hardening
- Backup and recovery check
- Written report with severity, fixes and next steps
Not included
- Certified penetration testing for formal compliance (we help you prepare for one)
- Testing of systems you do not own or have permission to test
- 24/7 incident response
Typical stack
OWASP ASVS, Dependency scanning, Secret scanning, CSP and security headers, Cloudflare Turnstile
Security: common questions.
Is this a penetration test?
No. It is a code and configuration review with fixes. If you need a certified penetration test for compliance, we will tell you, and help you fix the obvious issues first so the test is worth the money.
Can you review a site or app someone else built?
Yes, provided you own it and can give us access to the code and hosting. We start with a short review and tell you plainly whether to fix it or rebuild parts of it.
Does every Thannlab build include security?
Yes. Every project ships with HTTPS, security headers, input validation, spam protection on forms, current dependencies and accounts in your name. The security service is for existing systems or deeper reviews.
Will this make us POPIA compliant?
It covers the technical side: how personal information is collected, stored, accessed and protected. POPIA also has legal and process requirements, so for a full compliance opinion you should involve your information officer or legal adviser.
Tell us what you are building.
A few lines and a rough budget is enough. We will come back with questions and a call time, then send a fixed written quote within two business days.
What happens next
- 1We read your enquiry and reply within one business day.
- 2A free 30 minute call to understand the project.
- 3A fixed, written quote within two business days.