Our Approach

Security is an important consideration for every project, regardless of its age. As your technical partner, we guide and advise both new and existing clients to ensure their websites, applications, and digital platforms remain secure.

We aim to follow not only the most widely recognized security best practices, including the OWASP guidelines, but also go a step further by implementing additional precautionary measures. We continuously monitor projects and their dependencies automatically for vulnerabilities (CVEs), strive for an A+ rating on the Mozilla Security Observatory, and apply internal security measures to prevent vulnerabilities and data leaks.

OWASP

OWASP is a community of security experts that documents best practices and common security issues. These range from well-known vulnerabilities to more complex and less obvious security risks.

OWASP has created a Top 10 list of the most common security issues, which our developers always keep in mind when building and maintaining your project.

Automated vulnerability checks (CVE)

CVE (Common Vulnerabilities and Exposures) is a database where publicly known security vulnerabilities are documented. Occasionally, vulnerabilities are discovered in software libraries that we use, after which a so-called “CVE” is published.

At Inventis, we have automated security checks in place based on these vulnerabilities. This allows us to be notified automatically when a potential issue is detected, so we can address it as quickly as possible and prevent websites from remaining vulnerable to issues we were previously unaware of.

Mozilla Security Observatory

The Mozilla Security Observatory is a tool developed by Mozilla, the organization behind the Firefox browser, that scans websites and provides a security score based on how well they comply with its guidelines.

A high score is not a guarantee of complete security, but it does provide additional confidence, as the highest ratings require strict security measures that make different types of vulnerabilities significantly more difficult to exploit.

We always aim for the highest score of A+ for our projects. We would like to make this an absolute guarantee, but security criteria can change over time. Some technologies you want to use may also be incompatible with these requirements. If that happens, we will proactively inform you, allowing you to make an informed decision about whether you still want to accept that risk.

Internal security measures

Security is not only considered during development; everyone at Inventis contributes to maintaining a secure working environment. Some examples of our internal measures:

  • We use two-factor or multi-factor authentication for sensitive accounts.
  • We never share passwords through less secure channels such as email, chat, or our ticketing system. Instead, we use password managers and secure, expiring links.
  • We do not reuse passwords. Instead, we generate unique, strong passwords for every account or website, including accounts and credentials created for your website.
  • We never store passwords or other sensitive information directly in our code. Instead, these are kept separately, ensuring that code can safely be reviewed or shared with third parties if needed.
  • We avoid using production data in testing environments by working with test data whenever possible, removing sensitive information first, or deleting copied data as soon as it is no longer needed (for example, when reproducing an issue).

What if my project is getting older?

The security principles described above apply not only to new projects, but also to existing platforms that we continue to maintain.

Technology, security standards, and potential threats evolve continuously. That is why we actively monitor older projects as well. This can result in small improvements that we implement proactively, or when more substantial changes are required, recommendations and advice on how to improve the current situation.

With Inventis as your technical partner, you can rely on ongoing attention to security throughout the entire lifecycle of your project.

Beveiliging is belangrijk voor alle projecten, oud en nieuw. Als technische partner begeleiden en adviseren we zowel nieuwe als bestaande klanten hierin.