SERVICES / CI CD SECURITY

CI/CD & supply-chain security

We assess the permissions, secrets and approvals that can turn a code change into a production incident, then show the controls that need attention first.

WHAT WE TEST
·Build injection and poisoned dependencies
·Runner and executor isolation
·Artefact signing and provenance
·Infrastructure as code review
·Secrets in pipelines and repositories
BOOKED AS
Basalt Pipeline
10 days · from €9 000

Includes the role chains that connect CI/CD to your cloud.

Discuss this assessment
EVERY ENGAGEMENT

Signed authorization before technical work · public standards (PTES, OWASP, NIST, ATT&CK) · report reviewed by a second engineer · retest within 30 days included · engagement data destroyed 30 days after closure · delivery date and 10% late-delivery discount stated in the contract.