Product security · templates · consulting

Security that does not
slow you down.

We help software teams implement their product security requirements in a structured and traceable way - with risk-based reviews, practical templates and a coaching approach that keeps your team capable in the long run.

Request a security assessmentOther services
Three packages

From a compact review to full audit support.

Choose the depth that matches your maturity - we honestly recommend what you actually need.
Level 1

Quick assessment

A one-day review of your product. You get a prioritised report - which measures can be implemented internally and where external support makes sense.

  • 1 day on site or remote
  • Report within 5 working days
  • 30 min walkthrough call
from €2,400
Level 2Popular

Templates & coaching

Three weeks alongside your team. We deliver threat models, secure SDLC templates and pull request checklists - and enable your team to carry them forward independently.

  • Threat model workshops
  • PR templates & linters
  • Pen-test preparation
  • Team training 2x4h
from €6,800
Level 3

ISO support

Structured preparation for ISO 27001. We map your reality onto the standard, write alongside you, support audits - and stay available for follow-up audits.

  • Gap analysis
  • ISMS setup
  • Audit support
  • Re-certification
Fixed price after scoping
What is inside the templates

Maintainable security building blocks instead of static documents.

All templates arrive as maintainable Markdown files or TRA tool files in your repository. Versioned, auditable, and your development team can adapt them itself.
01
Threat model (STRIDE)
Per feature/service. Tied to your architecture and your code.
Included in level 2 & 3
02
Secure coding guidelines
Per language: TS, C#, SQL, Bash. Including linter configs.
Included in level 2 & 3
03
PR review checklist
Checkpoints for pull requests before the merge.
Included in level 2 & 3
04
Incident response playbook
Who does what and when, if something is on fire.
Included in level 2 & 3
05
SBOM + SCA pipeline
Auto-generated in CI. Supplier risks made visible.
Included in level 2 & 3
06
Secret hygiene
Pre-commit hooks, secret scanning, vault setup.
Included in level 2 & 3
07
Pen-test briefing
Information, scope and access for an efficient penetration test.
Included in level 2 & 3
● Security · 2026

Threat & risk analysis for a cloud integration.

Threat modelling, CRA & NIS2

Product threat analysis with customer advisory and a secure operation concept. Backed by experience from security and compliance projects.

Let us talk

One idea. One coffee.
One clear next step.

30 minutes, no strings attached - in German or English, on site in NRW or remote. We listen, give you an honest assessment, and sometimes say: “Don't build that.”

Arrange a meeting
info@huelake.com