Ask HN: Security audit for startup / OSS projects
I run a startup whose code is public and I'd like to have the code audited for vulnerabilities, does anyone know of services that exist to do this that aren't enterprise focused? Even HackerOne has gone full-enterprise in recent years, but it's not only large companies that need these services.
8 comments
Check out a company which audited TrueCrypt.
https://vaultinfosec.com/contact.php
We are young energetic team, who had already done secure Code review to many startup's.
We are young energetic team, who had already done secure Code review to many startup's.
[deleted]
https://www.hackerone.com/company/open-source-community
HackerOne has a free offering for open source projects. ^^
Let me know if you have any questions (I manage it). :-)
HackerOne has a free offering for open source projects. ^^
Let me know if you have any questions (I manage it). :-)
Thanks, unfortunately we're using BSL in order to monetize, it's not an OSI license
You can find indy security people on Upwork.
But really if you have a ci cd pipeline you should look at automating a lot of this. Devsecops.
If you post a link and I get time I can take a look.
But really if you have a ci cd pipeline you should look at automating a lot of this. Devsecops.
If you post a link and I get time I can take a look.
Ask on the infosec.exchange mastodon. There are plenty folks there contracting.