Web · Mobile · Cybersecurity · France · USA · Tunisia

WE BUILD
SOFTWARE.
WE BREAK IT FIRST.

A web & mobile app development agency with an in-house offensive security team. Custom web applications, SaaS platforms and iOS/Android apps for companies in France and the United States — pentested before launch, not after the breach.

6–12 wk
MVP to production
100%
Shipped products pentested
0
Client breaches to date
Ship Log
SHIPPEDFintech onboarding app — React Native, iOS + Android
PENTESTPre-launch test on SaaS billing API — 3 findings fixed
SHIPPEDB2B marketplace — Next.js + Laravel, multi-tenant
GDPRData-mapping & RGPD compliance review for health-tech client
SHIPPEDHeadless e-commerce storefront — 98 Lighthouse
RED TEAMAdversary simulation for logistics platform — report delivered
SHIPPEDFintech onboarding app — React Native, iOS + Android
PENTESTPre-launch test on SaaS billing API — 3 findings fixed
SHIPPEDB2B marketplace — Next.js + Laravel, multi-tenant
GDPRData-mapping & RGPD compliance review for health-tech client
SHIPPEDHeadless e-commerce storefront — 98 Lighthouse
RED TEAMAdversary simulation for logistics platform — report delivered
01 / What We Do

BUILD. SHIP.
SECURE.

Three practices, one team. Your developers and your security testers sit in the same room — so you don't discover the vulnerabilities after launch.
02

MOBILE APPS

iOS and Android apps in React Native, Flutter, Swift and Kotlin. Fintech, health, marketplaces and field-service apps — with secure storage, hardened APIs and App Store / Play Store submission handled for you.

iOSAndroidReact NativeFlutterNative
Mobile App Development
03

CYBERSECURITY

The same offensive team that tests our own builds, available for yours: penetration testing (VAPT), red teaming, 24/7 threat detection & response, vulnerability management and PCI ASV scans. SOC 2, ISO 27001, GDPR readiness.

PentestRed TeamMDRGDPR / SOC 2
Cybersecurity Services
02 / How We Ship

SECURITY AT
EVERY STAGE.

Most agencies bolt security on at the end — if at all. Ours is a gate at every step, run by the same people who find bugs in other people's products for a living.
01

Discovery & Scope

Free 30-min call, then a written scope, timeline and fixed-price estimate within 48h.

▌ THREAT MODEL DRAFTED
02

Design & Architecture

UX flows, data model, stack decision. Auth, payments and data privacy designed in — not patched in.

▌ SECURE DESIGN REVIEW
03

Build in Sprints

Two-week sprints, weekly demos, staging environment you can click through from day one.

▌ SAST + DEPENDENCY AUDIT
04

Pentest & Hardening

Our red team attacks the release candidate. Findings fixed by the developers who wrote the code.

▌ MANUAL PENETRATION TEST
05

Launch & Support

Zero-downtime deploy, monitoring, SLA-backed maintenance and optional 24/7 detection & response.

▌ CONTINUOUS MONITORING
03 / Stack

TOOLS WE TRUST.

Boring, proven, well-documented. We choose the stack your future engineers will thank us for.
webLaravelwebNext.js / ReactwebTypeScriptwebNode.jswebPostgreSQL mobileReact NativemobileFluttermobileSwiftmobileKotlin infraAWSinfraVercelinfraDockerinfraGitHub Actions secBurp SuitesecOWASP ZAPsecSemgrepsecWazuh SIEM
04 / Why Evosec

ENGINEERS WHO
THINK LIKE ATTACKERS.

Founded in 2019 by Iheb Ennachet (Iheb Nachet) — developer first, penetration tester second, and never one without the other.

Most development agencies have never seen a real exploit. Most security firms have never shipped a product. We've done both — on the same codebase, in the same week.

That is the whole pitch. When we build your web app or mobile app, the people writing the authentication flow are the same people who spend their other days breaking authentication flows for banks and SaaS companies. Nothing gets to production without our red team trying to get in first.

We work with founders and product teams in France and the United States who need software that will pass a security questionnaire, a GDPR audit, or a SOC 2 review — without paying two vendors to argue with each other.

OWASP ASVS GDPR / RGPD SOC 2 Ready PCI DSS HIPAA ISO 27001
50+
Products & engagements
▲ web · mobile · security
3
Core markets
▌ France · USA · Tunisia
0
Client breaches to date
▌ our only vanity metric
48h
Scope & fixed quote
▲ after first call
05 / Where We Work

FRANCE. USA. TUNISIA.
YOUR TIME ZONE.

Remote-first, nearshore for Europe, awake when your US team is — and on the ground in Tunisia. Contracts in English, French or Arabic; invoicing in EUR, USD or TND.
🇫🇷

France

Agence de développement web & mobile pour startups et PME françaises. Same time zone as Paris, French-speaking team, RGPD and NIS2 built into every delivery.

CET · FRANÇAIS · EUR INVOICING · RGPD
🇺🇸

United States

Product engineering and application security for US startups and mid-market companies. Daily overlap with East Coast hours, SOC 2 / HIPAA / CCPA awareness, USD contracts.

EST OVERLAP 9AM–1PM · ENGLISH · USD INVOICING
🇹🇳

Tunisia

Headquartered in Sousse. Web & mobile development, penetration testing and managed security for Tunisian startups, banks, telecoms and SMEs — on-site when it matters, in Arabic, French or English.

HQ SOUSSE · ON-SITE AVAILABLE · AR · FR · EN · TND INVOICING
🌍

Worldwide

Fully remote delivery for clients across the EU, UK, MENA and North America. Same process, same security gates, wherever you are.

REMOTE · EN · FR · AR · 24/7 EMERGENCY LINE
06 / FAQ

STRAIGHT ANSWERS.

The questions every founder and CTO asks us on the first call.
What does Evosec Consulting do?

We are a web and mobile app development agency with an in-house cybersecurity team. We design and build custom web applications, SaaS platforms, e-commerce sites and iOS/Android apps — and every product we ship is penetration-tested by our own security engineers before launch. We also sell those security services on their own: pentesting, red teaming, 24/7 detection & response, vulnerability management and PCI ASV scans.

Do you work with companies in France and the United States?

Yes — that's most of our client base. We work on Central European Time (Paris) with a daily overlap window for US East Coast teams, communicate fluently in English and French, and deliver every engagement remotely. Contracts and invoices in EUR or USD.

How much does it cost to build a web or mobile app?

A focused MVP typically starts around $15,000–$40,000 (≈ 14k–37k €) and ships in 6–12 weeks. Larger products with native mobile apps, complex integrations or compliance requirements are scoped individually. Every quote is fixed-price per milestone and includes a security review.

Which technologies do you use?

Web: Laravel, Next.js/React, Node.js, TypeScript, PostgreSQL. Mobile: React Native and Flutter for cross-platform; Swift and Kotlin when native is the right call. Infrastructure: AWS, Vercel, Docker and hardened CI/CD pipelines.

Can you audit an app another agency built?

Yes. Our security team pentests and code-reviews existing web and mobile applications regardless of who built them. You get a prioritised report with CVSS scores and a remediation plan — and our developers can fix the findings if you want a single vendor.

How do we start?

Book a free 30-minute call. You'll talk to a senior engineer, not a salesperson. Within 48 hours you receive a written scope, timeline and fixed-price estimate.

07 / Start

TELL US WHAT
YOU'RE BUILDING.

30 minutes with a senior engineer. No commitment, no pitch deck. We'll tell you what we'd build, how long it takes, and what it costs.
Project Brief
Web App / SaaS Mobile App Pentest / Security Not sure yet
Reply within one business day.
WhatsApp: +216 55 737 390