Skip to main content

What our clients say

Rather than a wall of one-line quotes, here is one engagement in full.

A faith-based charitable organisation
Kuala Lumpur · charitable, non-profit
Signed letter of reference

On the security assessment

“What could easily have been an intimidating technical report instead became a usable roadmap.”

“As a charitable organisation, protecting the trust of the communities we serve is non-negotiable. … The assessment gave us genuine confidence that our systems, and the people who depend on them, are being looked after responsibly.”

“Risks were named plainly, recommendations were practical, and solutions were easily digestible. That clarity made it possible for both our technical contacts and our committee to engage meaningfully and act decisively.”

“We came out of the engagement not just more secure, but more capable.”

On the digital build

“One of the most worthwhile decisions we’ve made.”

“This has materially expanded how our supporters can give, removing friction for donors and opening up a channel that simply didn’t exist for us before.”

“… guidance that was practical and aligned with how we actually work.”

“… less like an external consultant and more like a trusted partner invested in our mission.”

President of the society · quoted from a signed letter of reference, with identifying details withheld at our own choice.

The engagement

What the engagement involved

They approached us to review the security of their WordPress site. That work led to a second engagement, building the donation system it now runs.

Vulnerability Assessment & Penetration Testing

A full review of the website, with every finding given a severity rating, a plain-language explanation of the risk, and a remediation step their team could act on themselves.

Online donation form

Built and implemented on their building fund page, with payment processing integrated so the society can accept contributions digitally for the first time.

Ongoing advisory

Guidance across broader digital questions, delivered in language their committee could follow, so decisions could be made by the people accountable for them.

Where we looked

The areas covered in the assessment of their platform.

  • OWASP WSTG Testing Methodology
  • Web Hygiene
  • Business Logic (e.g., Donation form abuse vectors)
  • Email Security Hardening
  • WordPress Security Hardening

Let’s talk

Tell us a little about what you’re working on and we’ll get back to you.