
What a security review actually looks at
You bought a firewall plugin, a malware scanner and an uptime monitor. Yet nobody can list which of your systems are reachable from the internet.
7 minute read
Netcraft, s.r.o. · Bratislava
Netcraft builds and improves websites and e-commerce systems, reviews existing infrastructure and removes unnecessary complexity. We use proven tools that fit the job instead of adding subscriptions, servers and software you don't need.

Six ways in. They share one idea: use only as much technology as the problem requires.
Build and improve online shops, catalogues, checkout flows and the integrations behind them — starting with what actually needs replacing, which is often less than you think.
Business websites and web applications built around what they actually have to do, from a lightweight static site to a PHP application with real logic.
What does this site cost to operate, and why? We find where it is unnecessarily expensive, slow or complicated, and recommend the smallest useful set of changes.
Review the exposed services, dependencies, access points and hosting, then remove unnecessary attack surface before adding more security products.
Review the software, hosting and services you already pay for, and identify where simpler or lower-cost tools do the same job reliably.
Automation put into work you already do, with a human check-step left in where being wrong would matter. We don't sell AI for its own sake.
Hosting accumulates. SaaS subscriptions accumulate. Plugins, monitoring services, dashboards and integrations accumulate. Eventually nobody remembers why half of them are there, and the monthly total is nobody's job to question.
We look at the system as a whole and remove what isn't earning its place. Sometimes that means rebuilding something; more often it means switching a few things off.
Fewer licences, services and unnecessary infrastructure.
Fewer exposed systems and dependencies to maintain.
Infrastructure another competent developer can actually take over.
What does it need to do, what does it cost now, and what has to be maintained afterwards? We don't arrive with a preferred stack.
The fixed-fee review produces scope, sequence and price. If no change is warranted, the plan records that conclusion.
Repository, content, domain and accounts stay yours. If you stop working with us, nothing is locked to us.

You bought a firewall plugin, a malware scanner and an uptime monitor. Yet nobody can list which of your systems are reachable from the internet.
7 minute read

Quotes for an unsupported Drupal site can differ sharply because extended support, a Drupal rebuild and a move to another platform are different jobs.
7 minute read

Four internal registries agreed. Twelve published pages still used a value Keystatic rejected.
5 minute read
Send a URL or a rough list of what you pay for each month. We'll reply within one working day and tell you whether a review would be useful.