All servicesBuild

Infrastructure & security

Infrastructure described as code, and Zero Trust access that does not rest on a text message.

Deliverable
Infrastructure reproducible from the repository, and admin access with no shared password.
Typical duration
3 to 6 weeks
From
€8,000 per project

The problem

A product’s security is not decided at launch. It is decided in how the infrastructure is described, how access is granted and how secrets travel.

We describe infrastructure as code — what is not in the repository does not exist — and replace standing access with identity verified on every request. One-time codes over SMS are never the answer: a number can be hijacked, and silently.

What is included

  • Infrastructure described as code, reproducible from one environment to the next
  • Zero Trust access: identity verified on every request, not a perimeter crossed once
  • Authentication with hardware keys or passkeys — never a one-time code over SMS
  • Secrets managed outside the repository, distinct per environment
  • Backups verified by an actual restore, not by the presence of a file

How it works

  1. 01

    Map

    What exists, who reaches it and through where. The surprises are here, not in the target state.

  2. 02

    Describe

    Infrastructure moves into code. What is not in the repository does not exist.

  3. 03

    Close

    Standing access becomes verified access. SMS leaves the authentication path.

  4. 04

    Prove

    A restore is run for real. A backup never restored is not a backup.

Frequently asked

Why rule out SMS codes?

Because a phone number can be hijacked at the carrier, and that hijack leaves no trace on the victim's side. A passkey or hardware key resists phishing; an SMS does not.

Do we have to migrate everything at once?

No, and that would be the surest way to fail. We move perimeter by perimeter, keeping a way back at every step.

Can you work with our current host?

Yes. Changing host is a separate decision, made on its own merits and not in passing.

Other services

Act

Dark themePin the site's appearancesetTheme({theme:"dark"})
Light themePin the site's appearancesetTheme({theme:"light"})
System themeFollow the system preference againsetTheme({theme:"system"})
Switch the site to FrenchFrançaissetLocale({locale:"fr"})
Labs — ProductFilter Labs by typefilterLabs({type:"Produit"})
Labs — PrototypeFilter Labs by typefilterLabs({type:"Prototype"})
Labs — ResearchFilter Labs by typefilterLabs({type:"Recherche"})
Labs — Reset filtersClear every Labs filterfilterLabs({reset:true})
Journal — EngineeringFilter the Journal by categoryfilterJournal({category:"Ingénierie"})
Journal — SecurityFilter the Journal by categoryfilterJournal({category:"Sécurité"})
Journal — Agent-NativeFilter the Journal by categoryfilterJournal({category:"Agent-Native"})
Journal — StudioFilter the Journal by categoryfilterJournal({category:"Studio"})
Journal — Reset filtersClear every Journal filterfilterJournal({reset:true})

Services

DiscoveryFrame the product before the first line of code, so the budget builds instead of correcting.openService({service:"discovery"})
Product designAn interface that holds together, carried by a design system your developers can keep alive without us.openService({service:"design"})
Web developmentA fast web application that holds up over time, with the tests and delivery chain to match.openService({service:"web"})
Mobile developmentAn iOS and Android app from a single codebase, published on both stores.openService({service:"mobile"})
Infrastructure & securityInfrastructure described as code, and Zero Trust access that does not rest on a text message.openService({service:"infrastructure"})
Maintenance & evolutionA product kept current, watched and fixed, with someone who answers when it breaks.openService({service:"maintenance"})
Agent-Native Architecture AdvisoryMake an existing product agent-operable without rewriting it — and without opening more than it should.openService({service:"agent-native"})

Go to

YorroProduct engineering studio in Abidjan and Paris. We design, we build, we ship.navigate({page:"home"})
ServicesBuild a product end to end, or advise a team on its agent-native architecture.navigate({page:"services"})
LabsWhat the studio has built: products, prototypes and research, with where each one actually stands.navigate({page:"labs"})
TutorialsStep-by-step guides drawn from real projects, grouped into tracks by topic.navigate({page:"tutorials"})
JournalThe studio's notes and positions.navigate({page:"journal"})
ContactDescribe your project; you get a framing back, not a boilerplate quote.navigate({page:"contact"})
AboutWho runs the studio, how it works, and what it turns down.navigate({page:"about"})
↑↓ move↵ runesc closeOne Actions layer