01What does SECFORIT do?
SECFORIT provides hands-on Vulnerability Management, DevSecOps and security automation, application and API security, cloud and infrastructure security, penetration testing, and software supply chain security. We are based in Arad, Romania and serve clients across Europe.
02Do you offer a free initial assessment?
Yes. Every engagement starts with a no-obligation discovery call where we listen, assess your security posture, and propose a tailored plan. Response within 24 hours.
03What industries and company sizes do you work with?
We work with organisations of all sizes across Europe — startups shipping their first product, agencies and SaaS teams, and established companies with existing security programmes. Our methodology adapts to your environment, compliance requirements, and risk appetite, so a small team gets the same engineering attention as an enterprise.
04What is your testing methodology?
We follow a proven four-phase model: Discovery & Assessment, Threat Modelling, Implementation, and Continuous Protection. Structured, transparent, and designed for measurable outcomes. Assessments can be mapped against recognised controls and frameworks, including ISO 27001 and NIST.
05Do you review source code, or only test running systems?
Both. We test running systems the way an attacker would, and we read the code behind them. Secure code review is OWASP-aligned and covers authentication and session handling, injection, access control, unsafe deserialization, and the dependency and build chain that ships the code.
06Can you secure our CI/CD pipeline and software supply chain?
Yes. We wire security into the build itself — SAST and SCA gates, secrets management, infrastructure-as-code scanning, SBOM generation with CycloneDX or SPDX, and artifact signing and trust chains — so problems are caught before they ship rather than after.
07Who actually does the work?
The engineer who scopes your engagement is directly involved in delivery. Adrian-Răzvan Lișman is a Principal Security Engineer with an M.Sc. in Cybersecurity Engineering, working across vulnerability management, DevSecOps, and security engineering. There are no unnecessary handoffs or account-manager layers between you and the technical work.
08Do you also build websites and applications?
Yes — through WEBFORIT, our web design and development studio at webforit.ro. It is the same engineering practice on the build side: sites and web applications developed with hardened hosting, dependency hygiene, and secure defaults from the first commit.