# Security

> Selected Engineer ApS work demonstrating Security — the achievements that prove it.

- [Improved team communication and collaboration by implementing Slack, Mattermost, 1Password, and Jira, saving 8,000 hours of labor.](https://advisory.engineer.company/portfolio/improved-team-communication-and-collaboration-by-implementing-slack-34/)
- [Set the platform's founding decisions in the weeks after the repository opened in November 2025 — the layering, database‑first data access and the zero‑warnings bar — and they still hold nine months on.](https://advisory.engineer.company/portfolio/set-the-platform-s-founding-decisions-in-november-2025-80/)
- [Automated team collaboration, password management, task and time management, and built a semi‑automatic project‑showcase system, raising team productivity.](https://advisory.engineer.company/portfolio/automated-team-collaboration-password-management-task-and-time-89/)
- [Built the payments and entitlements layer — Stripe alongside Apple and Google in‑app purchase — gating the directory, search and export through an 11‑table access model checked on the server.](https://advisory.engineer.company/portfolio/built-the-payments-and-entitlements-layer-96/)
- [Built company ownership claims end to end — a user claims a company, an administrator adjudicates, and an approval rewrites the authorization graph that decides who is allowed to edit what.](https://advisory.engineer.company/portfolio/built-company-ownership-claims-end-to-end-103/)
- [Established a continuous security programme — code scanning, DAST, dependency and vulnerability checks, SBOM generation, secret scanning and SHA‑pinned actions — alongside 21 written security audits.](https://advisory.engineer.company/portfolio/established-a-continuous-security-programme-104/)
- [Wrote a scope rule into the repository after a restructure carried another company's inventory, firewall allowances and prose into it — and kept the quarantined residue under the secret scanner rather than excluding it.](https://advisory.engineer.company/portfolio/wrote-a-scope-rule-after-a-credential-leak-124/)
- [Wrote a parser that reads the real 7,308‑line C header and verifies every call site, every enum constant and that every pointer‑owning class is final, after a hand‑written placeholder header let calls to three removed functions compile, link and crash.](https://advisory.engineer.company/portfolio/wrote-a-parser-that-verifies-every-ffi-call-site-157/)
- [Rewrote the application's error messages against a written tone standard after a refused sign‑in blamed the user for mistyping when the provider actually required an app‑specific password, and covered it with a test that names the provider.](https://advisory.engineer.company/portfolio/rewrote-the-error-messages-against-a-tone-standard-162/)

<https://advisory.engineer.company/categories/security/>
