SECFORITFree assessment
SECFORIT · Security Engineering/Est. 2019 · Arad, RO

We find the gaps — and help you close them.

Security engineers who would rather fix a problem than write a report about it. Vulnerability Management, DevSecOps, and Security Engineering — done hands-on, around how your environment actually runs.

46.1867°N · 21.3123°EArad, România · Serving Europe

File — CapabilitiesActive
  • 01Vuln Management
  • 02DevSecOps & Automation
  • 03Application & API
  • 04Cloud & Infrastructure
  • 05Pen Testing
  • 06Supply Chain
// Track record2019 — 2026
Years in cybersecurity
Security assessments
Organisations secured
Response time
Client confidentiality
[01·Services]

Six disciplines, one practice

From reliable vulnerability operations to the code, pipelines, and infrastructure behind them — we prioritise exposure, automate controls, validate risk, and stay through remediation.

01

Vulnerability Management

We help organisations operate vulnerability management end to end — from authenticated scanning and Tenable, Nessus, Qualys, or Microsoft Defender platform administration to risk-based prioritisation using CISA KEV, NVD, and EPSS. We coordinate and track remediation, report posture trends, and integrate security tooling through APIs so exposure is reduced measurably.

Tenable / NessusQualys / DefenderCISA KEV / EPSSRemediation
02

DevSecOps & Security Automation

We build practical security gates into GitLab CI/CD and infrastructure as code using SAST, SCA, DAST, SBOMs, Terraform, Ansible, Docker, Vault, and secrets management. Python and API automation connect the controls to the way engineering teams already ship.

GitLab CI/CDSAST / SCA / DASTTerraform / AnsiblePython / APIs
03

Application & API Security

Web and API assessments combine OWASP-aligned testing, secure code review, SAST and DAST evidence, and hands-on vulnerability validation. Findings cover authentication, access control, injection, and business logic, with remediation guidance tied to the code and configuration that must change.

OWASPWeb / APISecure Code ReviewValidation
04

Cloud & Infrastructure Security

We review and harden AWS, Azure, Linux, Docker, networks, and identity configurations against practical security baselines. The work covers IAM, PKI, Vault and secrets, segmentation, and the configuration paths that let one exposed service or account become a wider compromise.

AWS / AzureLinux / DockerIAM / PKIVault / Baselines
05

Penetration Testing

Hands-on testing validates exploitable paths across external, internal, web, API, and network scope. Where relevant, we validate lateral movement and control effectiveness, then provide proof of impact and a clear, testable remediation path.

Internal / ExternalWeb / APIExploitationLateral Movement
06

Software Supply Chain Security

We map dependencies, build steps, and artifacts, then strengthen the chain with SBOMs, SCA, signing, provenance, secrets controls, and verifiable release policies. The result is a build process whose inputs and outputs can be traced and checked.

SBOMSCAArtifact SigningProvenance
We ship fixes, not just reports.

Every finding comes with a remediation path we have tested — and we retest after you fix, because a closed ticket should mean the problem is actually gone.

RemediationRetestingKnowledge Transfer
[02·Method]

A four-phase engagement

Structured, transparent, and designed to deliver measurable outcomes — informed by recognised security frameworks, including ISO 27001 and NIST.

01Phase

Discovery & Assessment

We assess your posture, map your infrastructure, and identify gaps using recognised security controls and frameworks, including ISO 27001 and NIST. You get a prioritised risk register.

02Phase

Threat Modelling

Vulnerability scanning, attack-surface mapping, and threat modelling tailored to how real adversaries would target your organisation.

03Phase

Implementation

We deploy controls, SIEM configurations, Zero Trust policies, and DevSecOps pipelines — working alongside your team, not around it.

04Phase

Continuous Protection

Ongoing monitoring, quarterly compliance reporting, and incident response planning. Your posture improves continuously, not just at audit time.

[03·The Practice]

A small practice that does the work

We started in Arad in 2019 on a simple principle: stay small enough that you always know exactly who is on your account. No layers of account managers, no handing your project to whoever happens to be free — the engineer who scopes your work is the one who runs it, start to finish.

We test, script, and break things for a living. When we hand you a finding, it comes with proof and a fix we have actually tried — not a line copied out of a scanner. That is the whole point of working with people instead of a tool.

That holds whether you are a five-person startup shipping your first product, an agency that needs a build reviewed before it goes live, or an established team wanting a second pair of eyes on a programme you already run.

Exhibit A — Client register⌀ Access denied

Some things stay redacted. NDA by default.

SECFORIT SRL · 46.1867°N · 21.3123°E
We do the work

The engineer who scopes your test is the one who runs it. No handoffs.

Solutions, not reports

Every finding comes with a fix we have tested — not just a severity score.

We stay till it holds

We retest after you remediate, so a closed ticket actually means closed.

Quiet and confidential

NDA on request. What we find stays between us.

[04·Qualification]

Technical credibility, on record

Security advice is only worth the experience behind it. Named engineering expertise, relevant qualifications, and the tools used in delivery — without an account-management layer.

// PrincipalSignatory

Adrian-Răzvan Lișman

Principal Security Engineer

Principal Security Engineer working across vulnerability management, DevSecOps, and security engineering — operating security platforms, automating controls, and validating exposure through hands-on testing.

Based
Arad, România — serving Europe
Speaks
Romanian — native · English — C1
// RecordEducation & research
  1. M.Sc.

    Cybersecurity Engineering

    Technical University of Cluj-Napoca
    Faculty of Computer Science · EQF Level 7

    Research on insecure deserialization in web applications — OWASP A08:2025, Software & Data Integrity Failures.

  2. B.Sc.

    Informatics

    “Aurel Vlaicu” University of Arad
    Graduated 9.5 / 10
// Instrument list
Application Security
  • OWASP Top 10
  • Secure code review
  • API testing
  • Auth & session
  • Injection
  • Deserialization
Pipelines & Supply Chain
  • GitLab CI/CD
  • SAST / SCA
  • SBOM
  • Artifact signing
  • Secrets management
  • Policy as code
Cloud & Identity
  • Azure
  • AWS
  • SSO & IAM
  • PKI / HSM
  • Zero Trust
  • Hardening
Offensive & Assessment
  • Burp Suite
  • Nmap
  • Metasploit
  • MITRE ATT&CK
  • Recon
  • Exploitation
Vulnerability Operations
  • Tenable
  • Qualys
  • Defender XDR
  • CISA KEV
  • EPSS
  • Remediation tracking
Automation & Infrastructure
  • Python
  • Bash
  • Terraform
  • Ansible
  • Docker
  • Linux
// Cross-reference
WEBFORITPowered by SECFORIT

Web design & development — built secure from the first commit.

Our web design and development studio. Same engineers, the other side of the desk — building sites and web applications with hardened hosting, dependency hygiene, and secure defaults from the first commit, instead of bolting security on after launch.

  • Web design
  • Web development
  • Secure hosting
  • Performance
[05·Queries]

Questions on file

The things people ask before the first call. If yours is not here, just send it — we answer within 24 hours.

Ask us directly
01

What does SECFORIT do?

SECFORIT provides hands-on Vulnerability Management, DevSecOps and security automation, application and API security, cloud and infrastructure security, penetration testing, and software supply chain security. We are based in Arad, Romania and serve clients across Europe.

02

Do you offer a free initial assessment?

Yes. Every engagement starts with a no-obligation discovery call where we listen, assess your security posture, and propose a tailored plan. Response within 24 hours.

03

What industries and company sizes do you work with?

We work with organisations of all sizes across Europe — startups shipping their first product, agencies and SaaS teams, and established companies with existing security programmes. Our methodology adapts to your environment, compliance requirements, and risk appetite, so a small team gets the same engineering attention as an enterprise.

04

What is your testing methodology?

We follow a proven four-phase model: Discovery & Assessment, Threat Modelling, Implementation, and Continuous Protection. Structured, transparent, and designed for measurable outcomes. Assessments can be mapped against recognised controls and frameworks, including ISO 27001 and NIST.

05

Do you review source code, or only test running systems?

Both. We test running systems the way an attacker would, and we read the code behind them. Secure code review is OWASP-aligned and covers authentication and session handling, injection, access control, unsafe deserialization, and the dependency and build chain that ships the code.

06

Can you secure our CI/CD pipeline and software supply chain?

Yes. We wire security into the build itself — SAST and SCA gates, secrets management, infrastructure-as-code scanning, SBOM generation with CycloneDX or SPDX, and artifact signing and trust chains — so problems are caught before they ship rather than after.

07

Who actually does the work?

The engineer who scopes your engagement is directly involved in delivery. Adrian-Răzvan Lișman is a Principal Security Engineer with an M.Sc. in Cybersecurity Engineering, working across vulnerability management, DevSecOps, and security engineering. There are no unnecessary handoffs or account-manager layers between you and the technical work.

08

Do you also build websites and applications?

Yes — through WEBFORIT, our web design and development studio at webforit.ro. It is the same engineering practice on the build side: sites and web applications developed with hardened hosting, dependency hygiene, and secure defaults from the first commit.

// Contact — free assessment
[06·Contact]

Let's discuss your security posture

Every engagement starts with a no-obligation discovery call. We listen, assess, and propose a tailored plan — no generic checklists, no upselling. Response within 24 hours.

Security First. Protection by Default.