[Consulting Services]

> The engineers who build our products, available by the day

consulting.sh
~./expertise --list

Amsterdam Technologies consults in software engineering and cybersecurity: Go performance work, penetration testing, incident response, code audits, threat modeling and reverse engineering. The consultants are the same engineers who build and operate our own products.

~Status: ACCEPTING ENGAGEMENTS
[0x0]

> Go Engineering

Go development and performance work: profiling, concurrency debugging and production troubleshooting.

  • >Performance optimization and bottleneck analysis using pprof and advanced profiling techniques
  • >Memory leak detection and resolution in production environments
  • >Concurrency pattern analysis and race condition elimination
  • >Architectural guidance and code review for Go projects
  • >Security vulnerability assessment and remediation
[0x1]

> Penetration Testing

Infrastructure and web application testing, from reconnaissance through manual exploitation to remediation.

  • >Infrastructure security audits with passive and active reconnaissance
  • >Web application security testing aligned with OWASP Top 10 and ASVS standards
  • >Attack surface mapping and automated vulnerability scanning
  • >Manual exploitation and validation of security findings
  • >Business logic flaw detection and authorization bypass testing
  • >Detailed remediation guidance with prioritized recommendations
[0x2]

> Incident Response

Containment, forensics and recovery support when something has already gone wrong.

  • >Incident assessment aligned with NIST SP 800-61 framework
  • >Breach containment and threat eradication procedures
  • >Forensic evidence collection and chain of custody maintenance
  • >Impact analysis and compromised data identification
  • >Recovery planning and service restoration guidance
  • >Post-incident review and security posture improvement recommendations
[0x3]

> Code Auditing

Manual review backed by SAST, looking for vulnerabilities and design flaws rather than lint noise.

  • >Static Application Security Testing (SAST) across the full codebase
  • >Manual code review for complex vulnerability detection
  • >Identification of anti-patterns and architectural weaknesses
  • >Dependency analysis and third-party library security assessment
  • >Secure coding practice evaluation and recommendations
[0x4]

> System Design

Architecture reviews and threat modeling, done before the design hardens.

  • >Threat modeling using STRIDE and similar methodologies
  • >Defense in depth architecture design
  • >Secure defaults implementation and least privilege enforcement
  • >Cloud-native security architecture planning
  • >Zero-trust network design principles
  • >Security requirements specification and validation
[0x5]

> Security Training

Training for engineering teams: secure SDLC, defensive coding, OSINT awareness and travel security.

  • >Secure software development lifecycle training for engineering teams
  • >Defensive coding techniques and vulnerability prevention
  • >Social engineering awareness and recognition training
  • >Data protection guidelines for mobile and traveling workforce
  • >Physical security assessment and countermeasure training
  • >OSINT awareness and attack surface reduction strategies
[0x6]

> Risk Assessment

Quantified risk analysis that tells you which security investment to make first.

  • >Threat modeling for products and infrastructure
  • >Risk quantification aligned with NIST SP 800-30 or FAIR frameworks
  • >Likelihood and impact assessment for identified threats
  • >Security investment prioritization guidance
  • >Compliance gap analysis and remediation roadmap
[0x7]

> Reverse Engineering

Disassembly and runtime analysis of binaries: malware, undocumented protocols, hidden behaviour.

  • >Static analysis using industry-standard disassemblers (Ghidra, IDA Pro)
  • >Dynamic analysis and runtime behavior observation
  • >Malware analysis and threat intelligence extraction
  • >Competitive analysis and technology assessment
  • >Binary vulnerability research and exploitation analysis

> Expert network

Engagements are not limited to our own headcount. We work with a network of independent specialists — Go engineers, penetration testers, reverse engineers, incident responders — and bring the right people onto an engagement when the work calls for expertise or capacity beyond the core team.

You contract with Amsterdam Technologies throughout: one contract, one point of contact, and one party accountable for delivery.

Before any engagement begins, everyone we bring onto it is contractually bound to your confidentiality, data protection and non-disclosure requirements. Our engagement terms require it.

Work on contract yourself? We keep a database of independent consultants and get in touch when a project matches what you do — ask to be added.

~./engage --service "consulting"

Scope your engagement

A first call establishes what you need, whether we are the right people for it, and what it will cost.

>Schedule Consultation