[Tech and AI Partner]

Elevate the security level of your applications and infrastructure

Galadrim audits your code and infrastructure, tests your defences in real conditions, then provides you with a prioritised correction plan, estimated in recovery time.
Your vulnerabilities corrected, attested by a counter-audit report
150+ security audits and penetration tests conducted
5 application security engineers, supported by 140+ senior tech profiles
Two Galadrim consultants reviewing around a laptop
+800 organisations entrust us with their tech and AI projects
Two Galadrim engineers in a code review
Code, cloud configurations, and attack methods are constantly evolving, and even the most carefully developed applications eventually present blind spots. To continuously advance your security level, the challenge is not only to identify your vulnerabilities through an external perspective but to provide you with concrete and prioritised means to correct them.
Robin BaraudHead of Cybersecurity
[Our offerings]

We measure the actual security of your applications and infrastructure, then correct the flaws and attest to their disappearance.

Application security audit

Application security audit

Analysis of your code and its configuration: authentication, access rights, data exposure, secrets, and dependencies. With or without source code access, according to your choice.
Penetration Testing

Penetration Testing

Controlled attack on your web application, your APIs, your mobile application or your network, within a scope agreed with you. Each exploited vulnerability is accompanied by its proof of impact.
Cloud Infrastructure Audit

Cloud Infrastructure Audit

Review of your cloud environments' architecture and configuration. It covers identities, network segmentation, encryption, and hardening, according to CIS Benchmarks.
Remediation and Counter-Audit

Remediation and Counter-Audit

Correction of vulnerabilities by your teams or ours, followed by a counter-audit that verifies their disappearance and confirms it in writing.
Continuous Protection and Incident Response

Continuous Protection and Incident Response

Application firewall operated by our teams, with regular reports on your exposure.
[Our support]

Our Method for Measuring and Correcting Your Vulnerabilities

  • Framing
    Step 01

    Framing

    We agree with you on the scope, access mode, and schedule, prior to any signature.
  • Audit
    Step 02

    Code Audit and Penetration Testing

    We conduct both aspects in parallel, using auditors external to the teams that built the application, and report vulnerabilities to you throughout the audit.
  • Reports
    Step 03

    Audit Reports

    We describe each vulnerability, classify it according to the CVSS standard, and include an estimated correction time.
  • Debrief
    Step 04

    Debrief

    We present the findings to your technical teams and management during a debrief, and translate the report into a compliance roadmap with ANSSI recommendations.
  • Remediation
    Step 05

    Remediation and Counter-Audit

    Your teams or ours correct the vulnerabilities, then a counter-audit verifies their disappearance and attests to it in a report.
01/05
[Projects]

They entrusted us with the cybersecurity of their most sensitive software

Wealth ManagementPraemia REIM

Have the extranet of a manager with 33 Md€ in assets under management validated by an independent pentest

Praemia REIM allows wealth management consulting firms to monitor the entire lifecycle of their clients' SCPI investments, including assets under management, subscriptions, taxation, and commissions. Galadrim designed and developed this extranet: multi-strategy authentication including enterprise single sign-on, server-side permissions, encrypted secrets in the deployment pipeline, four segmented environments. The client commissioned a specialist firm for a penetration test followed by a counter-audit, which concluded the highest level of security in its evaluation grid.
33 Md€in assets under management
61funds monitored
Highest levelin third-party counter-audit
Praemia REIM Logo
TelecommunicationsIliad

Present 12,000 employees with their remuneration and free shares under strict access control

Iliad, owner of the Free operator, wanted to provide each employee with a view of their overall remuneration, social protection, and free share allocation plan. Galadrim developed both applications with a fine-grained role-playing system, which determines what each employee, manager, and administrator can consult. Legal share transfer documents pass through the platform.
12 000users
+1 Mdata rows
2distinct applications
PharmacyLeadersanté

Centralise the identities and access rights of a group of 900 pharmacies

Leadersanté's teams were working on about twenty business applications with as many identifiers. Galadrim developed the group's single sign-on portal: each satellite application connects to it, and identity and rights management is centralised at one point. The ecosystem is hosted in an approved environment for health data.
900+pharmacies in the group
~20applications behind a single access
8 yearscontinuous support
Leadersanté Logo
ObservabilityDatadog

Integrate the monitoring of a network security component into an American vendor's catalogue

Datadog, a cloud infrastructure monitoring and analysis platform, wanted to integrate Calico's metrics into its ecosystem. Calico is the open-source component that provides routing, network access control, and the enforcement of security policies on Kubernetes containers. Galadrim developed the Python collection agent and its test coverage, working in English with the vendor's teams. The code was then incorporated into Datadog's Core repository.
10k+users of the integration
2,7 Md$in 2024 turnover
They talk about us
[Why Galadrim?]

Why work with our cybersecurity teams?

Auditors who know how to fix

An auditing firm stops at the report. Our auditors are Software Engineers: each vulnerability is quantified in correction time, and our development teams perform the remediation, then have it verified by counter-audit.

A strict separation of roles

The audit of an application, including one developed by Galadrim, is entrusted to engineers external to the project. Each report is reviewed by a second auditor before being sent.

A security requirement applied to our own developments

Our repositories are subject to code reviews, automated detection of vulnerable dependencies, and an internal audit programme. Our deliverables regularly undergo penetration tests that our clients commission from third-party firms.

A security research practice

Our team conducts independent research activities, up to the publication of new vulnerabilities and their coordinated correction with vendors. Your defences are tested with offensive research methods.

Galadrim supports you with the security of your applications and infrastructures, from penetration testing to verified remediation.

Chat with an expert
[FAQ]

Some frequently asked questions from our clients

You choose. With code access, the audit covers a larger surface area for the same duration. In black-box mode, the test simulates the conditions of an external attacker. Both modes are offered for each mission, and the choice is made during the scoping phase.
A typical engagement combines code audit and penetration testing over 5 to 10 days, depending on the number of applications and the depth of the test. The scope is agreed with you before signing.
A summary for your directors, followed by each vulnerability described and classified according to the CVSS standard, with proof of impact and an estimated remediation time. The compliance roadmap with ANSSI recommendations and the risk model are also included.
Yes. The audit is entrusted to engineers external to the project, and the reports are reviewed by a second auditor. If your insurer or client requires an auditor who is completely independent of our structure, we will inform you transparently and direct you to the right partner.
Yes. The review covers the architecture and configuration of your AWS, Azure, GCP or OVH environments: identity management, network segmentation, storage, encryption, and hardening according to CIS Benchmarks.
Your teams or ours. The report is designed to remain usable by any service provider, and our engineers will carry out the remediation if you entrust it to us.
We support the technical aspect of compliance through regular audits and training for your teams. The certification itself is the responsibility of an accredited body.
Confidentiality is the rule: no audit engagement is publicly cited, even anonymously. You benefit from the same discretion.
Yours. Reports, proofs of impact, and documentation belong to you with each delivery. The transfer of rights is contractual from the outset.
Each engagement is sized according to your scope, access mode, and the depth of testing chosen. Describe your context to us, and we will get back to you within 24 h with an initial assessment.
[Contact us]

Let's bring your project to life together

We work with all types of clients, across all sectors. Whether you're an entrepreneur or managing a large organisation, a tailored team will meet your needs.

Over 800 companies have trusted us to create their web, mobile, and AI products

Your enquiry

We'll get back to you within 1 hour.