Cybersecurity and compliance engineering
Tankar builds security into how software is made and hosted, and helps teams get ready for the reviews they will face. That covers a secure development lifecycle, access control, environment separation, dependency and secret management, logging, and preparation for ISO/IEC 27001 or a customer's security questionnaire. Tankar holds ISO/IEC 27001 certification itself, so the controls described here are ones the company operates rather than ones it has read about.

Controls that are enforced, not documented
A policy in a folder does not stop a leaked key. Review rules, dependency scanning, secret detection, short-lived credentials and environment separation are built into the pipeline and the infrastructure, so the control holds whether or not anyone remembers it.
Evidence as a by-product
Audits and customer security reviews ask for proof. Where the control runs in the pipeline, the evidence is produced automatically, which is the difference between a two-week scramble and an export.
What Tankar does not do
Tankar does not issue certificates and does not audit its own remediation work. Certification comes from an accredited body, and penetration testing is done by a firm that did not build the system.
Typical engagements
What this service usually produces, as deliverables rather than adjectives.
- A secure development lifecycle set up in your repositories, with review rules, dependency scanning and secret detection
- Access control and environment separation across development, staging and production, described as code
- ISO/IEC 27001 readiness work, including the policies, evidence and control mapping an auditor asks for
- Coordination of an independent penetration test, with the remediation work planned and tracked
- A security review of an existing application, with findings ranked by exploitability and business effect
- Data protection engineering for GDPR, UK GDPR, the India DPDP Act 2023 or the Saudi PDPL, covering consent, retention and deletion
How it runs
The stages this service goes through, and what you see at each one.
Discovery
What you hold, who can reach it, where it is hosted, and which review or certification is coming. Written estimate within 48 hours of the scoped call.
The written estimate follows within 48 hours of the scoped call.
Assessment
Code, pipeline, cloud configuration and access reviewed against a control set, with findings ranked by exploitability and business effect rather than by tool severity.
Plan
A remediation plan with owners and dates, separating what must be fixed before the audit or launch from what is a longer programme.
Implement
Controls built into the pipeline and the infrastructure so they are enforced rather than documented, with evidence produced automatically where possible.
Verify
Retest of the findings, an independent penetration test where the scope justifies one, and a written report of what changed.
Operate
Monitoring, alerting, an incident response runbook that has been rehearsed, and a review cadence for access and dependencies.
- Team shape
- A senior engineer who owns the control set and the evidence, a DevOps engineer for pipeline and cloud work, and a project manager who runs the audit timeline.
Stack for this service
The technologies this work is usually built on, and why each one is used here.
| Technology | Why we use it here |
|---|---|
| GitHub Advanced Security or equivalent | Dependency alerts, code scanning and secret detection run on every pull request rather than in a quarterly report. |
| Terraform | Network, access and environment separation described as code, so a control can be reviewed and cannot be quietly changed in a console. |
| OpenID Connect and short-lived credentials | Removes long-lived cloud keys from pipelines and laptops, which is where most credential leaks come from. |
| A managed secrets store | Secrets are held outside the repository with rotation and an access log, rather than in environment files passed around a team. |
| Centralised logging and alerting | An incident you cannot reconstruct is an incident you cannot report on, and reporting deadlines under data-protection law are short. |
Selected work
Case studies where this service carried the engagement. Only outcomes with a source are shown.
Own productGovernment and public sectorTenderBazaar: tender discovery and alerts for Indian SMEs
A tender discovery platform that collects listings from central, state and municipal portals into one searchable feed with daily alerts.Services: SaaS product development, Mobile app development and 1 moreRead the case study
Own productTravel and hospitalityTripBNG: a B2B travel booking platform for agents
A booking platform that gives travel agents supplier inventory, quotes, credit limits and settlement reports in one account.Services: SaaS product development, API development and integrations and 1 moreRead the case study
Engagement models that fit
An assessment against a defined scope is fixed price; remediation and readiness programmes run on time and materials.
- Fixed priceA defined scope with a clear end state: an MVP, a website, a well-specified module or an integration.
- Time and materialsEvolving products, research-heavy work such as AI features, and engagements where the backlog is set sprint by sprint.
- Retainer and supportLive products that need maintenance, monitoring, small improvements and a response commitment after launch.
Questions buyers ask
What buyers ask most about this service, answered before the first call.
Tell us what you are building.
NDA on request. Written estimate within 48 hours of a scoped call. Reply within one business day.