Security isn't a department we hand things off to. One named person is accountable for it, and you can reach them directly.
Who's responsible
Blake Pritchett, Owner & security lead
security@peaksolutions.tech
Blake has 16 years of experience in security and is responsible for the security of everything Peak Solutions builds and runs, from the first line of code to the infrastructure it's deployed on.
How we work
Pentest lab
We maintain our own penetration testing lab and use it to attack our work the way a real adversary would before it reaches production, so problems are found by us rather than by someone else.
Secure development
Security is part of how we design and write software, not a review bolted on at the end. That means validating input at every trust boundary, keeping secrets out of source code, keeping dependencies to a minimum and up to date, and reviewing changes with security in mind.
Access-control hardening
People and systems get only the access they need, for as long as they need it. We lock down accounts, admin panels and cloud resources, and we review access when projects or roles change.
Networks and internal servers
Security doesn't stop at the application. We harden the networks and internal servers your software depends on: segmenting networks so one compromised machine can't reach everything, closing ports and services that don't need to be exposed, putting remote access behind VPN or zero-trust gateways, enforcing key-based SSH and multi-factor authentication, keeping operating systems patched, and encrypting traffic between internal systems as well as to the outside world.
Network and infrastructure pentesting
We test networks and servers the same way we test applications. With your written authorization and an agreed scope, we scan for exposed services, look for misconfigurations and weak credentials, and try to move laterally the way an attacker who got a foothold would. You get a report of what we found, how serious it is and how to fix it, and we retest once the fixes are in.
Reporting a vulnerability
If you think you've found a security issue in this site or in something we've built, please email security@peaksolutions.tech with enough detail for us to reproduce it. We'll acknowledge your report, keep you updated, and let you know when it's fixed.
When testing, please:
- only test against systems you own or are clearly ours;
- don't access, change or delete other people's data;
- don't run denial-of-service attacks, spam or social engineering;
- give us reasonable time to fix the issue before you share it publicly.
If you act in good faith and follow these guidelines, we won't pursue legal action against you for your research. Our contact details are also published at /.well-known/security.txt.
Start a project