When you need it
Your pipelines can change production, and more people and tools can change your pipelines than anyone planned. One malicious pull request, a hijacked third-party action or a leaked CI variable could open a path into your cloud, and nobody has checked how easily.
What sets the quote
- One CI platform per check: GitHub Actions, GitLab CI/CD, Azure Pipelines, Jenkins, Bitbucket Pipelines, Google Cloud Build or AWS CodePipeline and CodeBuild.
- Organisation settings and repository rules for up to 25 repositories.
- Up to 10 pipelines reviewed in depth, chosen with you from those that can reach production.
- Hosted runners, plus up to 2 self-hosted runner or agent pools.
- Deployments to up to 3 environments.
- Larger estates, or a second CI platform, are quoted after the call.
What changes
- You know every path from a pull request to production, and which ones an attacker could use.
- You know whether each release deploys exactly what was tested, built once and promoted by digest.
- Every finding comes with evidence and a fix, so your team can act without investigating again.
- You have a 90-day plan ordered by risk and effort, ready for your backlog.
What you get
- Findings report with severity, affected repositories and pipelines, evidence and the fix
- Each finding mapped to the OWASP Top 10 CI/CD Security Risks (CICD-SEC-1 to CICD-SEC-10)
- The SLSA Build level of your main builds today, and the steps to the next level
- List of cloud keys stored in CI, each with its OIDC replacement
- One-page summary of the ten biggest risks for management
- 90-day roadmap ordered by risk and effort
- All findings as a CSV file for your ticket system
- A 90-minute readout with your team
What we cover on each platform
| Area | GitHub Actions | GitLab CI/CD | Azure Pipelines |
|---|---|---|---|
| Access and repository rules | SSO and enforced 2FA, rulesets and branch protection, required reviews, CODEOWNERS | SSO and enforced 2FA, protected branches, merge request approval rules, Code Owners | Entra ID sign-in with MFA, branch policies, required reviewers by path |
| Untrusted input | pull_request_target and workflow_run triggers, event data used in run steps | Merge request pipelines from forks, variables expanded in scripts | Pull request builds from forks, variables settable at queue time |
| Third-party code | Actions pinned by commit SHA, allowed-actions policy | include files and CI/CD components pinned to a SHA or version | Marketplace tasks and extensions, templates from other repositories |
| Runners | GitHub-hosted and self-hosted runners, runner groups, ephemeral runners | GitLab-hosted and self-managed runners, protected runners | Microsoft-hosted agents, self-hosted agent pools and their pipeline permissions |
| Secrets and cloud access | Organisation, repository and environment secrets, GITHUB_TOKEN permissions, OIDC | Protected and masked variables, ID tokens for OIDC, job token scope | Variable groups, Key Vault links, service connections with workload identity federation |
| Gates, approvals and audit | Required status checks, environments with required reviewers, audit log streaming | Merge request approval policies, protected environments with deployment approvals, audit events | Build validation, environment approvals and checks, auditing and audit streaming |
Jenkins, Bitbucket Pipelines, Google Cloud Build and AWS CodePipeline/CodeBuild are checked in the same six areas, using each platform’s own settings.
Not included
- Fixing the findings (quoted separately, often as keyless pipelines and secrets cleanup or a secure CI/CD pipeline)
- Penetration testing or live attacks on your pipelines (we can refer you to a certified partner)
- Application code review
- Compliance certification or audit opinions
What we need from you
- Read access to the repositories and pipeline definitions in scope, for example the Read role on GitHub, Reporter on GitLab or the Readers group in Azure DevOps.
- A 60-minute screen-share with a CI platform admin for the organisation, runner and secret settings that read-only roles cannot see.
- Read-only access to the cloud roles your pipelines use: SecurityAudit on AWS, Reader plus Entra Global Reader on Azure, or Viewer and Security Reviewer on Google Cloud.
- Two 60-minute interviews: your platform or DevOps owner and your security owner.
How it works
Free 30-minute call, then a written fixed quote based on your repository, pipeline and runner counts.
Automated and manual checks of organisation settings and pipeline files in up to 25 repositories.
In-depth review of up to 10 pipelines, their runners and secrets, and the cloud roles they use.
Report, roadmap and a 90-minute readout.
At a glance
- Duration
- 1 week
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
DevSecOps gap check
In 1–2 weeks, a check of how your teams build and ship software, scored against OWASP SAMM and NIST SSDF, ending in a gap list and a 90-day plan.
Keyless pipelines and secrets cleanup
Your pipelines move from long-lived cloud keys to short-lived federated tokens, with secret scanning and dependency gates that stop new leaks and risky dependencies before merge.
Secure CI/CD pipeline
A pipeline that scans every change, builds each image once, promotes it by digest and asks for approval before production, for one app in 2–3 weeks or up to 10 repositories in 4–5 weeks.