Tenth Floor Labs

Secure — Cloud & Application Security

Cloud and application security from engineers who build software

We review your AWS, Azure or GCP setup, check your code for security flaws and build security checks into your release pipeline. We also secure AI chatbots and LLM features against prompt injection and data leaks. It suits product teams shipping fast on the cloud.

Mon–Sat · 9am–8pm IST
Starting from
₹37.5k
one-time · fixed price
Timeline
1–4 weeks
typical
After launch
Optional monthly cloud posture monitoring
Maulik Gupta, Founder & Lead Engineer
Maulik Gupta
Founder & Lead Engineer · you'll talk to me

Sound familiar?

"We moved fast on AWS, and now nobody is sure who has admin access to what."

  • Our cloud grew over years, with old keys, open buckets and too many admins.
  • Security only gets checked once a year, after the code is already live.
  • We added an AI chatbot and don't know what it could leak if someone tricks it.
  • Developers want to write secure code but have no checks or guidance in the pipeline.
  • Our cloud bill and our attack surface both keep growing, and nobody owns either.

Built for

SaaS and product companies running on AWS, Azure or GCPStartups preparing for SOC 2, ISO 27001 or enterprise reviewsTeams launching AI chatbots, agents or LLM featuresFintech and health-tech apps with sensitive data in the cloudEngineering teams wanting security in CI/CD without slowing downCompanies that inherited code or cloud from an agency or old team

What we do

What's included in Cloud & Application Security.

01

AWS Security Review

A review of IAM, S3, networking, logging, encryption and key management against CIS Benchmarks, using AWS Security Hub and manual checks.

02

Azure & GCP Security Review

The same depth for Azure and Google Cloud: identities, storage, network rules, logging and organisation policies.

03

IAM & Access Review

We find unused accounts, old access keys, over-powered roles and missing MFA, then help you move to least privilege.

04

Secure Code Review

Manual and tool-assisted review of your code for injection, broken access control, secrets in code and unsafe dependencies.

05

DevSecOps & Secure SDLC

Secret scanning, dependency checks, static analysis and container scanning added to your CI/CD, tuned so it doesn't block every build.

06

AI & LLM Security

Testing of chatbots and LLM features for prompt injection, data leaks and unsafe tool use, following the OWASP Top 10 for LLM Applications.

Who delivers this

Senior security people, not juniors.

Every engagement is led and advised by our security team — a serving CISO with 31+ years in technology, and a partner with security experience across India, Europe and the USA.

Security & Compliance Partner

Leads this service
India · Europe · USA

A hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.

3 continentsCloud & privacy securityPublished IoT security researcherAzure security certified

GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC

Principal Security Advisor

Advises
Serving CISO · 31+ years in technology

A serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.

Serving CISO31+ years in technologyMulti-country security governanceBoard-level risk reporting

ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance

Pricing

Transparent packages. Fixed quotes.

Your final quote is fixed after a 20-minute call — no surprise bills.

Cloud Review

₹1L
one-time · per account · 1–2 weeks
  • AWS, Azure or GCP configuration review
  • IAM and access review
  • Logging and monitoring check
  • Security headers and hardening review
  • Prioritised fix list with commands
Get this quote

Secure Code Review

from ₹37.5k
one-time · 1–3 weeks
  • Manual review of critical code paths
  • Static analysis and dependency scan
  • Secrets-in-code check
  • Findings with code-level fix examples
  • Walkthrough with your developers
Get this quote
Recommended

DevSecOps Setup

₹2L+
one-time · 3–4 weeks
  • Everything in Cloud Review (one account)
  • Security checks added to your CI/CD pipeline
  • Secret, dependency and container scanning
  • Secure SDLC guidelines for your team
  • AI/LLM feature security review
  • Two weeks of tuning after go-live
Get this quote

Ongoing costs after launch

No surprises: here's everything you may pay every month, stated upfront.

With us

Optional monthly cloud posture monitoring

See all ongoing plans
Paid to third parties, at cost, no markup

Cloud provider security tools (often included in your plan)

  • —Cloud-native security services (for example, AWS Security Hub, GuardDuty or Defender for Cloud) are billed by your cloud provider.
  • —Commercial scanning tools, if you choose them over open-source, are paid directly by you.
  • —Large-scale fixes or re-architecture are quoted separately.
  • —LLM API usage during AI security testing is billed at cost.

Want a quick estimate for your exact project? Try the cost estimator.

Process

From first message to launch.

Clear stages, a live preview link every week, and payments tied to milestones you approve.

  1. Step 01Days 1–2

    Scoping call

    We agree accounts, repos and features in scope, sign the NDA and set read-only access. Fixed price.

  2. Step 021–2 weeks

    Review

    Automated scans plus manual review by senior engineers, focused on what attackers would really use.

  3. Step 033–5 days

    Report & fixes

    Clear findings with copy-paste fixes. We can apply them for you, since we build on these platforms daily.

  4. Step 041–2 weeks

    Build it in

    Optional: we add checks to your pipeline so new issues are caught before release, not a year later.

Technology

Tools we trust.

AWS Security HubAWS GuardDutyMicrosoft Defender for CloudGoogle Security Command CenterCIS BenchmarksProwlerSemgrepTrivyGitleaksGitHub Advanced SecurityOWASP Top 10 for LLM ApplicationsOWASP ASVS

Our promises

Working with us is low-risk.

Fixed quote

A clear, fixed price after a 20-minute call. No surprise bills.

Pay in milestones

Projects: 40% to start, 30% on design approval, 30% at launch.

You own everything

Code, domain, ad accounts, WhatsApp number and data — in your name.

Weekly previews

See real progress on a live link every week, not just status updates.

30 days of free fixes

Anything not working as agreed after launch, we fix at no cost.

Talk to the builder

No account managers. You speak with the engineers doing the work.

FAQ

Questions, answered.

What decides the cost?+

For cloud, the number of accounts and services in use. For code, the size of the codebase and how many critical flows we review. For DevSecOps, your CI/CD tools and how many repos we cover.

How long does it take?+

A cloud review takes 1–2 weeks per account. Code reviews take 1–3 weeks depending on size. A DevSecOps setup usually takes 3–4 weeks including tuning.

How is this different from a penetration test?+

A pentest attacks your app from outside like a hacker would. This service looks from the inside at your cloud settings, code and pipeline. Together they give the fullest picture, and many clients do both.

Will you need admin access to our cloud?+

No. We use read-only security audit roles for reviews. We only ask for write access if you want us to apply fixes, and we remove it when done.

Will you sign an NDA? Is our code safe with you?+

Yes, we sign an NDA first. We review code in your repository or a secure copy, never paste it into public AI tools, and delete any local copies at the end.

Can you fix the issues, not just report them?+

Yes. That's our main difference. We build websites, apps and automation every day, so we can fix cloud settings and code ourselves or pair with your developers.

What results should we expect?+

Fewer admins and old keys, no open storage, secrets out of code and a pipeline that flags new issues before release. You also get evidence that helps with SOC 2, ISO 27001 and customer questionnaires.

Let's scope your project.

One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.

Call WhatsApp us