Resync Independent QA
Independent Security Testing
for NZ Programmes.
OWASP compliance, API security, cloud configuration, and authentication testing — independently verified before go-live.
Security Programmes Fail Quietly — Until Go-Live
These are the failure modes that reach production when quality assurance is left to the delivery team.
OWASP Top 10 in Production
The most common application vulnerabilities — injection flaws, broken authentication, insecure APIs — are preventable. They persist in production because security requirements are written down but never independently verified before go-live.
API Security Gaps
Modern applications expose dozens of REST APIs. Without dedicated API security testing, authentication flaws, missing rate limiting, and over-exposed data endpoints reach production and remain there until exploited.
Cloud Misconfiguration
AWS S3 buckets, Azure storage accounts, and IAM policies are configured once and forgotten. Misconfigured cloud resources are a leading cause of data breaches — and they are testable before go-live.
The Resync Approach
Resync provides independent quality assurance of security controls as part of your testing lifecycle. We don’t replace your penetration tester or security team — we work alongside them, providing independent evidence that security requirements are actually met before go-live. Our security testing covers web applications, REST and SOAP APIs, cloud infrastructure configuration, and identity and access management — all tested against OWASP criteria, NZ government security standards, and your programme’s own security requirements.

What We Test
Independent QA across all components — end to end.
OWASP Top 10 Testing
Systematic validation against OWASP Top 10 — injection flaws, broken authentication, insecure deserialization, security misconfiguration, and more. Documented evidence of compliance.
API Security Testing
REST and SOAP API authentication (OAuth 2.0, JWT, API keys), authorisation, rate limiting, input validation, and data exposure — tested against OWASP API Security Top 10.
Cloud Security Configuration
AWS, Azure, and GCP security posture validation against CIS benchmarks. S3 and storage account exposure, IAM policy review, and security group misconfiguration testing.
NZ Government Security Standards
Testing against NZISM controls and GCIO security requirements for government programmes. System classification, access control verification, and audit logging validation.
Security Regression Testing
Automated security checks integrated into your CI/CD pipeline. Prevent security regressions from reaching staging or production with every deployment.
Authentication & Access Control Testing
SSO, MFA, and RBAC testing. Identity provider integration (Microsoft Entra ID, Okta, Auth0). Privilege escalation and session management validation.
We Don’t Sell Tools. We Don’t Have Delivery Targets.
Resync has no financial relationship with any tool vendor. We recommend whichever approach best fits your technology landscape and programme context — full stop.
Why Resync for Security?
Common Questions about Security Testing
Everything you need to know before engaging Resync.
Is Resync a penetration testing firm?
No. Resync provides quality assurance of security controls as part of the testing lifecycle — functional security testing, OWASP compliance validation, and security requirement verification. We work alongside your penetration tester or security team, providing independent evidence that security requirements are actually met before go-live.
What is the NZISM and how does Resync test against it?
The New Zealand Information Security Manual (NZISM) is the government’s baseline for information security. Resync has experience validating security controls in systems subject to NZISM requirements — from system classification through to access control and audit logging verification.
Can Resync test our APIs for security vulnerabilities?
Yes. API security testing is a core Resync capability, covering authentication (OAuth 2.0, API keys, JWT), authorisation (RBAC, attribute-based access), rate limiting, input validation, and data exposure. We test REST and SOAP interfaces against OWASP API Security Top 10 criteria.
When in the delivery lifecycle should security testing happen?
As early as possible. Resync embeds security testing into functional test phases — not as a last-gate activity. Finding an authentication flaw in UAT is a 1-day fix. Finding it two weeks before go-live is a programme risk.
Ready to Protect Your Security Programme?
Talk to a Resync specialist. We’ll give you an honest assessment of where your quality risks sit — no obligation, no sales pitch.
