SECFORITFree assessment
SECFORIT · Offensive Security/Est. 2019 · Arad, RO

We find the gaps — and help you close them.

Security engineers who would rather fix a problem than write a report about it. Penetration testing, application security, DevSecOps, and vulnerability work — done hands-on, around how your environment actually runs.

46.1867°N · 21.3123°EArad, România · Serving Europe

File — CapabilitiesActive
  • 01Pen Testing
  • 02Web & API Security
  • 03Secure Code Review
  • 04DevSecOps
  • 05Vuln Management
  • 06Red Team
// Track record2019 — 2026
0+Years in cybersecurity
0+Security assessments
0+Organisations secured
0hResponse time
0%Client confidentiality
[01·Services]

Ten disciplines, one practice

From the code your developers write to the network it runs on — we test, break, and harden real systems, and we stay until every finding is closed. Take one discipline or the whole chain.

01

Penetration Testing

Hands-on, goal-driven testing against your systems. We go after real objectives the way an attacker would, then hand you the proof, the impact, and a clear path to closing each finding.

InternalExternalWebExploitation
02

Web Application & API Security

We test the things that break in the real world: broken authentication, access-control gaps, injection, and business-logic flaws that only show up when you push the app somewhere it did not expect to go.

OWASP Top 10API SecurityAuthFuzzing
03

Secure Code Review

We read the code behind the app, not just the responses it returns. Auth and session handling, input trust boundaries, unsafe deserialization, and the quiet mistakes a scanner will never flag.

OWASPManual ReviewSASTDeserialization
04

DevSecOps

We move security into the build, so problems get caught before they ship. Scanning, secrets handling, and policy checks wired into your pipeline — without slowing your developers down.

CI/CDSASTSCAIaC
05

Software Supply Chain Security

Most of your codebase is somebody else's. We map what you actually ship — dependencies, build steps, and artifacts — then make it verifiable with SBOMs, signing, and a trust chain you can prove.

SBOMCycloneDXArtifact SigningSecrets
06

Vulnerability Management & Analysis

Scanners hand you thousands of findings. We tell you which ones actually matter in your environment, what can wait, and what to fix today — so your team works a short list, not a 400-page export.

TenableQualysTriagePrioritisation
07

Cloud & Identity Security

Identity is the new perimeter and most breaches walk through it. We review how access is granted across your cloud and directory, then harden the paths that let one account become all of them.

AzureAWSSSO / IAMPKI
08

Network Assessment

We map what is really on your network — not what the diagram claims — and find the misconfigurations, soft spots, and forgotten boxes an attacker would use to get a foothold.

ReconSegmentationActive DirectoryMisconfig
09

Red Team Assessments

A full-scope test of how your people, tooling, and defences hold up against a determined adversary. Quiet and realistic, built to answer one question: would you catch us?

Adversary SimEvasionLateral MovementMITRE ATT&CK
10

Web Development & Design

Most sites get secured after they are built. We work the other way round: designed and built with hardened defaults, clean dependencies, and no attack surface the site never needed — delivered through our studio, WEBFORIT.

Next.jsSecure DefaultsHardened HostingSEO
We ship fixes, not just reports.

Every finding comes with a remediation path we have tested — and we retest after you fix, because a closed ticket should mean the problem is actually gone.

RemediationRetestingKnowledge Transfer
[02·Method]

A four-phase engagement

Structured, transparent, and designed to deliver measurable outcomes — aligned with ISO 27001, NIST, and SOC 2.

01Phase

Discovery & Assessment

We audit your posture, map your infrastructure, and identify gaps against ISO 27001, NIST, and SOC 2. You get a prioritised risk register.

02Phase

Threat Modelling

Vulnerability scanning, attack-surface mapping, and threat modelling tailored to how real adversaries would target your organisation.

03Phase

Implementation

We deploy controls, SIEM configurations, Zero Trust policies, and DevSecOps pipelines — working alongside your team, not around it.

04Phase

Continuous Protection

Ongoing monitoring, quarterly compliance reporting, and incident response planning. Your posture improves continuously, not just at audit time.

[03·The Practice]

A small practice that does the work

We started in Arad in 2019 on a simple principle: stay small enough that you always know exactly who is on your account. No layers of account managers, no handing your project to whoever happens to be free — the engineer who scopes your work is the one who runs it, start to finish.

We test, script, and break things for a living. When we hand you a finding, it comes with proof and a fix we have actually tried — not a line copied out of a scanner. That is the whole point of working with people instead of a tool.

That holds whether you are a five-person startup shipping your first product, an agency that needs a build reviewed before it goes live, or an established team wanting a second pair of eyes on a programme you already run.

Exhibit A — Client register⌀ Access denied

Some things stay redacted. NDA by default.

SECFORIT SRL · 46.1867°N · 21.3123°E
We do the work

The engineer who scopes your test is the one who runs it. No handoffs.

Solutions, not reports

Every finding comes with a fix we have tested — not just a severity score.

We stay till it holds

We retest after you remediate, so a closed ticket actually means closed.

Quiet and confidential

NDA on request. What we find stays between us.

[04·Qualification]

Who signs the report

Security advice is only worth the experience behind it. So here is the person behind it — no stock photos, no anonymous “our experts”.

// PrincipalSignatory

Adrian-Răzvan Lișman

Founder & Security Engineer

Security engineer working across both sides of the discipline — building the pipelines and identity infrastructure software ships through, and testing systems from the attacker's side to find where they break.

Based
Arad, România — serving Europe
Speaks
Romanian — native · English — C1
// RecordEducation & research
  1. M.Sc.

    Cybersecurity Engineering

    Technical University of Cluj-Napoca
    Faculty of Computer Science · EQF Level 7

    Research on insecure deserialization in web applications — OWASP A08:2025, Software & Data Integrity Failures.

  2. B.Sc.

    Informatics

    “Aurel Vlaicu” University of Arad
    Graduated 9.5 / 10
// Instrument list
Application Security
  • OWASP Top 10
  • Secure code review
  • API testing
  • Auth & session
  • Injection
  • Deserialization
Pipelines & Supply Chain
  • GitLab CI/CD
  • SAST / SCA
  • SBOM
  • Artifact signing
  • Secrets management
  • Policy as code
Cloud & Identity
  • Azure
  • AWS
  • SSO & IAM
  • PKI / HSM
  • Zero Trust
  • Hardening
Offensive & Assessment
  • Burp Suite
  • Nmap
  • Metasploit
  • MITRE ATT&CK
  • Recon
  • Exploitation
Vulnerability Operations
  • Tenable
  • Qualys
  • Defender XDR
  • CISA KEV
  • EPSS
  • Remediation tracking
Automation & Infrastructure
  • Python
  • Bash
  • Terraform
  • Ansible
  • Docker
  • Linux
// Cross-reference
WEBFORITPowered by SECFORIT

Web design & development — built secure from the first commit.

Our web design and development studio. Same engineers, the other side of the desk — building sites and web applications with hardened hosting, dependency hygiene, and secure defaults from the first commit, instead of bolting security on after launch.

  • Web design
  • Web development
  • Secure hosting
  • Performance
[05·Queries]

Questions on file

The things people ask before the first call. If yours is not here, just send it — we answer within 24 hours.

Ask us directly
01

What does SECFORIT do?

SECFORIT provides hands-on cybersecurity consulting — penetration testing, application and API security, secure code review, DevSecOps integration, cloud and identity hardening, and vulnerability management. We are based in Arad, Romania and serve clients across Europe.

02

Do you offer a free initial assessment?

Yes. Every engagement starts with a no-obligation discovery call where we listen, assess your security posture, and propose a tailored plan. Response within 24 hours.

03

What industries and company sizes do you work with?

We work with organisations of all sizes across Europe — startups shipping their first product, agencies and SaaS teams, and established companies with existing security programmes. Our methodology adapts to your environment, compliance requirements, and risk appetite, so a small team gets the same engineering attention as an enterprise.

04

What is your testing methodology?

We follow a proven four-phase model: Discovery & Assessment, Threat Modelling, Implementation, and Continuous Protection. Structured, transparent, and designed for measurable outcomes aligned with ISO 27001, NIST, and SOC 2.

05

Do you review source code, or only test running systems?

Both. We test running systems the way an attacker would, and we read the code behind them. Secure code review is OWASP-aligned and covers authentication and session handling, injection, access control, unsafe deserialization, and the dependency and build chain that ships the code.

06

Can you secure our CI/CD pipeline and software supply chain?

Yes. We wire security into the build itself — SAST and SCA gates, secrets management, infrastructure-as-code scanning, SBOM generation with CycloneDX or SPDX, and artifact signing and trust chains — so problems are caught before they ship rather than after.

07

Who actually does the work?

The engineer who scopes your engagement is the one who runs it. SECFORIT is led by Adrian-Răzvan Lișman, a security engineer with an M.Sc. in Cybersecurity Engineering, working across offensive testing, DevSecOps, and vulnerability management. There are no handoffs to junior staff and no account-manager layer between you and the person testing your systems.

08

Do you also build websites and applications?

Yes — through WEBFORIT, our web design and development studio at webforit.ro. It is the same engineering practice on the build side: sites and web applications developed with hardened hosting, dependency hygiene, and secure defaults from the first commit.

// Contact — free assessment
[06·Contact]

Let's discuss your security posture

Every engagement starts with a no-obligation discovery call. We listen, assess, and propose a tailored plan — no generic checklists, no upselling. Response within 24 hours.

Security First. Protection by Default.