Skip to content
LUMA Creative · Bratislava A website in 5 working days · an e-shop in 10 8.10.2026 Luma Creative s.r.o. is born +421 911 030 090 peter.kapusnik@lumacreative.online
iLUMA Creative

We also do · Software Security

Security built into the code, not bolted on.

We check your website, shop or app: a code and configuration audit, OWASP vulnerability testing, GDPR data protection and a clear, prioritised fix plan.

What we do

What will we do for you?

We agree scope and price on the first call, based on what you already have and what you need. You can pick one step or all of them.

  • Code and configuration audit

    We go through source code, dependencies, servers and headers, looking for what attackers try most often: weak logins, data leaks and outdated libraries.

  • Vulnerability testing

    We test the application from the outside against the OWASP Top 10, with your written consent and within an agreed scope. Every finding comes with a description, impact and steps to reproduce.

  • Data protection

    We check where personal data is stored, who can access it, how it is encrypted and backed up, and whether that matches GDPR and what your privacy policy promises.

  • Fix plan and monitoring

    You get a list of fixes ranked by risk, readable without a technical background. We can carry out the fixes ourselves and set up regular checks.

Fit

Who is it for?

The situations people most often bring to us — and what they have in hand when we are done.

  • You come with…

    • An e-shop taking payments You handle orders, addresses and payments and want to know they are safe.
    • An app before launch A check before customers see it — and attackers do.
    • An older system A site or app nobody has touched in years and nobody quite knows what’s inside.
  • You leave with…

    • Report with findings ranked by risk
    • A management summary without jargon
    • Step-by-step fixes for developers
    • A re-test after the fixes

Process

How does it work?

Four steps. At each one you know what comes next, and Peter is your single point of contact throughout.

  1. 01

    Scope

    What we test, when and how — in writing and with your consent.

  2. 02

    Audit

    Code, dependencies, servers and settings from the inside.

  3. 03

    Testing

    Tests from outside, the way an attacker would go about it, without disrupting operations.

  4. 04

    Fixes

    Report, fixes and a check that the holes are really closed.

Questions

What people ask

Will testing take the site down?

No. Anything that could affect operations runs on a copy or at an agreed time.

Do you test sites you didn’t build?

Yes, but always and only with the system owner’s written consent.

How often should it be repeated?

After every major change and at least once a year. We can automate regular checks.

Next step

Tell us what
you’re working on.

A half-hour call, free of charge. We reply within 24 hours.