Palisadium

Web development and cybersecurity, in one relationship

Palisadium builds the site and stays after it launches.

We design and build the web product, harden it before it goes live, then keep it monitored, patched and current. Security is worked into the build rather than audited in afterwards, and a written launch gate defines what “secure” means before anything ships.

  • What we buildMarketing sites, client portals, booking and payment flows, small web applications.
  • What we keepDependency updates, uptime monitoring, tested backups and a written incident response path.
  • VerificationOWASP ASVS Level 1, wherever a project has an application surface to verify against.
  • Base and reachDelivered from Lahore, Pakistan. Working with clients across markets.

Build and care

One provider for the build, and for the years after it.

Most firms hand you a launch. Palisadium hands you a launch and then keeps working. The build, the hardening and the ongoing care sit in the same relationship, with the same point of accountability.

01

Build

Your site or web app

A considered design and maintainable engineering, built around your actual content and workflow. Not a template with your logo on it.

  • Design direction and prototype
  • Development and content integration
  • Testing against acceptance criteria
  • Launch and handover documentation

Care plans available from the day it goes live.

02

Care

Monthly, on a schedule you can see

The work that keeps a product credible after launch: dependency updates, uptime monitoring, backups you can actually restore from, and small changes as the business moves.

  • Monthly dependency updates and patching
  • Uptime and error monitoring
  • Backups with tested restores
  • A written incident response contact

Quarterly review of coverage, costs and what changed.

03

Defend

Periodic testing, when it is worth it

Deeper work for products with real stakes: application testing, periodic penetration testing with your own explicit authorisation, and remediation carried through to a finished state.

  • Application testing and remediation
  • Periodic penetration testing, separately authorised
  • Compliance readiness support
  • Priority incident response

Offered to qualified projects, within agreed scope.

What secure means

A project is not “secure” until this is done.

Palisadium works through a written security baseline as a launch gate, not an afterthought. Every item maps to a line in the project record, and a signed copy is retained as the audit trail behind the label.

01

Applied during the build

Hardening is part of development, not a review bolted on at the end. Controls exist before launch because they were written while the code was written.

02

Every item accounted for

Checked, or marked not applicable with a one-line reason. Nothing is silently skipped, and nothing is described as done before it is.

03

Findings remediated, not logged

Critical and high findings are fixed, not recorded in a spreadsheet and left open. The gate closes on closure, not on documentation.

04

Signed before you hear the word

The baseline is signed off internally before the project is told it is launch-ready. Timeline pressure changes the deadline, never the bar.

05

You receive a plain summary

A readable summary of what was done, and what remains your own responsibility. The full technical record stays with us as the audit trail.

Work

Three ways this shows up in practice.

Every piece below is concept work — a project shape we would build to, written out so the scope is visible. No client projects have shipped yet, and we would rather be explicit about that than dress these up as case studies.

01

A site for a small B2B consultancy

Marketing site Concept work

“We are a twelve-person consultancy. The site looks like a template, and half of it has not been touched since we started.”

Most small practices have no design resource and no one to hand the site to afterwards. So the site and its ongoing care are designed as one engagement, not two invoices.

Built from the practice’s own materials rather than a stock layout: the actual services offered, real writing in their own voice, case material that exists, and an enquiry path that reaches a person. The design system is written down so a future edit does not restart from scratch.

Included

Deliverable
Marketing site, mobile-first, in one maintainable codebase
Baseline at launch
Transport security, security headers, dependency scanning, tested backups
Manual review
OWASP Top 10 walkthrough for a site with no application surface
Care
Monthly updates, uptime monitoring, and a written incident response path
Indicative build
3–4 weeks, quoted to scope

No live build and no client have been delivered for this piece. Scope and figures are indicative, not a quote.

02

A client portal for a professional service

Web application Concept work

“We handle client documents, invoices and case notes. Right now it is email and a shared drive, and we would not know if something went wrong.”

Portals are where a small firm’s data risk becomes real: documents, invoices and personal information sit behind a login that often barely exists. This shape puts the security surface in the same conversation as the build, instead of discovering it at launch.

The same domain carries a secure authenticated surface: sessions and access control designed first, then the interface built around them. What a client can see is decided before any screen is drawn.

Baseline coverage at launch

AreaWhat is in place
Encryption and sessionsArgon2id at cost 12, hardened session flags, bounded lifetime
TransportTLS 1.2 minimum with 1.3 preferred, HSTS enabled
Admin accessMFA enforced, least-privilege roles, server-side authorisation
DependenciesScanned at build and on every change, before release
OperationsSecurity event logging, tested restores, written response path
VerificationBuilt to OWASP ASVS Level 1, with evidence retained

Indicative build 4–6 weeks, depending on integrations and data migration. Any penetration test requires separate written authorisation and is not part of the build.

03

Keeping an existing site secure and current

Ongoing care Concept work

“The site works. We would just rather not be surprised by it.”

Care work is not a vague “we will look after it”. It is a named set of jobs on a named cadence, each one recorded, with a defined path when something actually goes wrong.

  • Week 1Discovery: audit the existing site, map dependencies, identify what is nobody’s responsibility
  • Week 2Baseline setup: monitoring, backups with a tested restore, and the written incident response path
  • Week 3First patch cycle, dependency review, and a documented report of what changed and why
  • Week 4Handover: what you now receive monthly, what is still yours, and what we would recommend next

Care plans are offered on their own for sites Palisadium did not build. Retainer terms, response coverage and capacity are agreed in writing before they start.

Verification, priced separately

One security deliverable you can buy on its own.

from £1,200*

A one-time verification of an application against OWASP ASVS Level 1: approximately 70 requirements, reviewed, tested and reported.

Quoted at cost for larger applications, additional environments, or a re-test after remediation. Net of VAT for VAT-registered business clients, which accounts for it under the reverse charge.

  • Security review against ASVS L1 v5.0.0
  • Black-box testing of the application surface
  • Remediation guidance for each finding
  • Plain-language summary, plus the evidence retained

* Estimated at 6–10 hours for a typical small application. That estimate has not yet been timed against a real project, so larger scope is quoted at cost rather than billed on a fixed figure. This is a floor, not a fixed fee.

This is the one item Palisadium offers as a standalone purchase. Full pricing is quoted per project, and penetration testing is always separately authorised.

About

A founder-led firm. Built like one.

Palisadium combines web development and cybersecurity in a single accountable relationship: build the product, harden it, then keep it maintained and defended. The commercial aim is project work followed by recurring care, rather than disconnected builds and separate security engagements.

The firm is founder-led, with Mustafa at the point of accountability for design, engineering and the security bar. The work is delivered from Lahore and offered to clients across markets. International targeting is confirmed; the specific first segment is still being narrowed, and the plan is to establish a credible offer and a working enquiry path before increasing any outreach.

There is a written security baseline behind every use of the word “secure”, and a documented service boundary on every engagement. Both are deliberate. A claim you cannot point to evidence for is not worth making on a website.

  • Founded byMustafa, founder
  • BaseLahore, Pakistan
  • ScopeSmall businesses and professional practices
  • ApproachBuild, then care for it, on a named cadence
  • StandardOWASP ASVS L1, where the surface exists
  • StatusPre-launch. No client work published yet.

Contact

Describe the project. Get a written proposal.

Tell us what you are trying to do, roughly what it costs you today, and when you need it. You will receive a scoped proposal with deliverables, exclusions, responsibilities and a delivery date — not a generic reply.

sh.mustafa.5967@gmail.com

This is a temporary address. When the main site moves to its own domain it will carry a palisadium address, and enquiries will route there instead.

Send the project description and we will reply with a written scope. We aim to acknowledge every enquiry within one working day and to send a proposal within five.

What to include

The problem you are trying to solve, the users or clients involved, anything currently in place, an indicative budget, and the date you are working towards.

What you will get back

A written scope: deliverables, what is excluded, what you supply, a delivery date and the care option afterwards. Founder review before anything is sent.