SERVICES / CI CD SECURITY

CI/CD & supply-chain security

The build system deploys to production by design — which makes it the quietest way in. We test the pipeline as an attack surface: what it stores, what it signs, and who can make it build the wrong thing.

WHAT WE TEST
·Build injection and poisoned dependencies
·Runner and executor isolation
·Artefact signing and provenance
·Infrastructure as code review
·Secrets in pipelines and repositories
BOOKED AS
Basalt Pipeline
10 days · from €9 000

Includes the role chains that connect CI/CD to your cloud.

Book a scoping call
EVERY ENGAGEMENT

Signed authorization first · public standards (PTES, OWASP, NIST, ATT&CK) · report reviewed by a second engineer · retest within 30 days included · your data destroyed in 30 days · late report = 10% off, in the contract.