Graphite & Moss

Victoria, BC · Victoria

Services / 03

Cybersecurity

The technical, hands-on side of security. We lock down your servers and cloud accounts, watch for trouble so a break-in is caught in hours rather than months, check your code for known weak spots, and write a plan for the day something goes wrong — including the new risks AI brings, like a chatbot that can be tricked into leaking data.

Etched topographic lines converging across dark mineral.

This is the technical side of security: engineers working on your systems — hardening, monitoring and detection, and being ready for an incident — rather than writing policy about them.

The work

  • Cloud security — identity and access on least privilege, logging and guardrails across AWS, Google Cloud and Azure accounts, and the misconfigurations that turn a storage bucket into a headline.
  • Detection — logs pulled somewhere they can be searched, detections written for the threats you actually face, and alerts that reach a person, so a compromise is found in hours rather than months.
  • Code and supply chain — scanning in the pipeline for vulnerable dependencies, leaked secrets and risky code before it ships.
  • Hardening — servers, containers, WordPress and the edge in front of them: least privilege, rate limits, the headers and rules that close the common doors.
  • Patch discipline — knowing what you run, what’s out of date and what’s actually exposed, and a cadence that keeps it that way.
  • Incident response — a written plan before you need it, and hands on keyboards when you do.
  • AI and LLM security — prompt injection, data leakage through a model, agents with more access than their job needs. The attack surface is new; the discipline isn’t.

Who does it

Our security work is led by CISSP- and ISSMP-certified engineers who have run security for platforms with millions of users — see the track record. The same practice goes into a five-person business: it’s scaled down, not watered down.

Where the line is

We do the engineering: the hands-on work on your systems. If you need someone to lead your security program — a part-time head of security, often called a virtual CISO — that’s our sister company, Signal & Soil. They also handle policies, risk registers, audits and board reporting. Need both? One scope, two invoices. When a customer or an auditor asks about SOC 2 (a common security audit for software companies), our part is the technical controls.


Contact

Start something.

Tell us what you need built, moved or secured — an app, a cloud setup, a security check. You get scope, cost and timeline in writing within two business days.

Get a scoped estimate