VXSec is a systems engineering and security company.

Modern businesses run on connected applications, APIs, infrastructure, identities, data, and increasingly AI. VXSec works across those systems to build what is missing, fix what is failing, and secure the boundaries that matter.

What VXSec does

Four ways to hire VXSec, each with a written plan before work starts. Build and integrate when something is missing: an internal application, an AI workflow, or a connection between the tools you already run. Repair and improve when a system you depend on is failing, slow, or fragile, including the cloud, infrastructure and identity underneath it: hosting and deployments, migrations, databases, access, OAuth, and DNS and TLS. Ongoing engineering when the systems exist and nobody owns them month to month. Security review and hardening when a system touches customer data, money, or email: a scoped review of access, credentials, authorization and release controls, with evidence-backed findings and remediation. Fixes are implemented and rechecked where included in the agreed plan.

Access is part of the engineering. Where AI agents and automations are involved, most of their problems are permission problems: what the agent can read, what it can send, what it can delete, and who approved that. Security checks are built into the work based on the system's access and risk.

How VXSec works

  • Written plan before work. The problem comes in writing. Within two business days you get a written reply with the next step: for a defined job, a plan and a fixed price.
  • A spec you approve. Goal, acceptance criteria, and boundaries, agreed before anything is built.
  • Evidence before "done". Results are verified on real data and the evidence is part of the handoff.
  • Security matched to the risk. Where a system handles customer data, money or email, the work covers what it may read, change and send, how credentials are held, and a human gate before production.
  • A handoff you own. Code, prompts, docs, an access map, and a runbook. Ongoing engineering is optional.

Experience

Applications, integrations, infrastructure and security, delivered.

RayInTheDark, an ecommerce marketing agency: systems engineering for its internal operations platform. The work covers the application and data foundations, the tools staff use every day, connected Meta, Shopify and Discord systems, operational AI, the release process, and security, on Next.js, TypeScript and PostgreSQL. One release connected advertising and store data with reconciled totals, visible account-access states, and explicit missing-data states.

Ingersoll Support Services: Google Workspace access rebuilt, with Shared Drive architecture by department, role-based access through Google Groups, personal-drive migrations, and a documented provisioning workflow.

Gabriel Service and Repair: a QuickBooks to Mailchimp customer sync that stopped on expired OAuth tokens, rebuilt with token refresh and persistent storage so it runs without hand re-authorization.

Classlete: a PHP Laravel platform and its SQL database moved from Azure to OVH with minimal downtime, including SSL, DNS, Windows VM replication, and load balancing.

The delivery records

How VXSec handles access

  • Least access that does the job, granted by you, and requested only for what the plan lists.
  • Listed in the plan before it is granted: which systems, which roles, for how long.
  • Logged and reported. Admin actions are recorded where the systems allow it and summarized in the handoff.
  • Removed at handoff unless you keep VXSec on for ongoing engineering.
  • Credentials stay in your systems. Secrets are kept out of prompts, documents and repositories.

The company

VXSec is a systems engineering and security company based in Toronto, working remotely with businesses across the US and Canada. Its experience covers production applications, AI and agentic systems, APIs and integrations, identity and access, cloud infrastructure and migrations, with security designed in from the start.

Yusuf leads the technical work. Work starts with a written plan and an agreed price, with checks set up front and results verified on real data before handoff. The work itself is on the selected work page.

Based
Toronto, Canada
Serving
United States and Canada, remote
To start
Send the problem in writing. Within two business days you get a written reply with the next step

What needs building or fixing?

Tell VXSec what the system does, what you want to change, and what is getting in the way. Include links if you have them. Within two business days you get a written reply with the next step.

Or email [email protected] directly.

  • You send: what should happen, what happens now, and the systems involved. No diagnosis needed.
  • You get back: a written reply with the next step. For a defined job, a plan and a fixed price.
  • Then: the work, verified and handed over in writing.