07
Web application securityin the Philippines
Most breaches are not clever. They are a dependency nobody updated, a role that could see more than it should, or a key committed once and never rotated. The work here is unglamorous and mostly preventative, which is why it tends to get skipped until the week it cannot be.
What the work covers
- Access control and role review
- Dependency and supply-chain review
- Secrets handling and key rotation
- Hardening of the deployment and its surface
- Smart contract review where the project is on-chain
What it is built with
Solidity
OpenZeppelin
SlitherRust
Docker
NGINX
Linux
Work in this area
SecurityPribado
Self-sovereign key manager. API keys sit in client-side encrypted vaults, proxied through a hardware enclave and rotated on a schedule.
Tech: Rust, WebAssembly, Hardware Enclaves, Encryption
Opens in a new tab
Web3StarBoarDB
A database that reads and writes to the chain itself, with no server in between.
Tech: Solidity, Web3.js, Smart Contracts, EVM
Opens in a new tab
Questions
- Is this a penetration test?
- No. This is review and hardening of a codebase and its deployment — access control, dependencies, secrets and configuration. A formal pentest is a separate engagement with a different scope.
- Do you review smart contracts?
- Yes, where a project is on-chain. The toolchain is Solidity with OpenZeppelin and Slither for static analysis, and the shipped work includes on-chain projects.
- Can you review something you did not build?
- Yes. Reviewing an existing codebase is a common way to start, and it is usually cheaper than waiting for the thing it would have caught.
Other services
RFX Studios is a web development company in the Philippines. We build websites, mobile apps, backends and AI automations for growing brands, shipped in a week.