Services
Insecure Lab is published by Pashyaa Technologies, a senior-led Java/Spring engineering company. Pashyaa modernizes, secures and extends business-critical Java/Spring applications. Application security and practical AI/RAG are two of its four capabilities, and they are the ones that matter most to readers here, so those engagements are listed below. The full catalogue, including the Java & Spring Boot Modernization Assessment (From $900), is on pashyaa.com.
Pentest reports don't fix themselves
Security firms deliver a findings PDF and leave. Someone still has to fix each item inside a Spring Boot codebase without breaking production. We do the fixing, not the testing.
What we don't do: we don't run penetration tests, offensive engagements, or attack simulations. We remediate findings, review code, and design secure integrations. If you need testing, we'll tell you and you should hire a specialist for it.
How engagements start
- Assess. A bounded review of an existing Java/Spring application: prioritized findings, a modernization roadmap and a recommended next workstream. Java & Spring Boot Modernization Assessment (From $900)
- Deliver a defined sprint or workstream. Pashyaa owns one scoped outcome — an upgrade, an integration, stabilization work, security remediation or a practical AI/RAG feature — with scope and acceptance criteria agreed first. All sprints and workstreams
- Continue with managed engineering. Where it makes sense, the work continues as managed Java/Spring engineering, quoted per engagement. How ongoing engineering works
Every engagement is scoped before it is priced. Published prices are indicative — final scope, timeline and price are agreed in writing before work begins. Prices are in USD, with INR alongside.
Security Audit Remediation
You have a report full of findings and nobody free to fix them. We close them out inside your Spring Boot codebase.
What you get
- Triage of every finding: real, duplicate, or false positive
- Fixes implemented in your codebase, reviewed and tested
- Regression checks so remediation does not change production behavior
- Evidence pack mapping each fix to its original finding, ready for retest
Java/Spring Boot Secure Code Review
A focused read of your Java codebase for the security defects that scanners rank low and attackers rank high.
What you get
- Manual review of authentication, access control, and data-handling paths
- Findings written against your actual code, not a generic checklist
- Severity-ranked remediation plan with the concrete fix for each item
- Walkthrough session with your engineers
LLM/RAG Integration Security Design Review
A security review of an AI feature you have already built or are about to ship — prompt injection, retrieval boundaries, and what the model can reach.
What you get
- Threat model for your retrieval and tool-calling paths
- Prompt injection and data-exfiltration review against the OWASP LLM Top 10
- Secrets, auth, and tenant-isolation boundaries checked
- Prioritized fixes, with design changes separated from code changes
RAG Reliability & Evaluation Pilot
A focused review of a RAG feature in a Java/Spring system — whether it retrieves the right material, grounds its answers, and fails safely — with an evaluation approach your team can keep running.
For Spring Boot (including Spring AI) and PostgreSQL/pgvector RAG systems. Implementation quoted separately.
What you get
- Document ingestion and chunking review
- PostgreSQL/pgvector retrieval, relevance and reranking review
- Grounding and citation behavior, checked against real questions
- Failure and abstention behavior when retrieval is weak
- A practical test and evaluation approach for retrieval quality
- API integration and production-readiness findings, prioritized
Start a conversation
Tell us what you're dealing with — a findings report, a codebase, or a feature you're planning.
The principal engineer who scopes and architects an engagement remains accountable through delivery. Implementation may be supported by additional engineers, while architecture, review and client communication remain senior-led.