Our Process
Rietta follows a rigorous, documented process for every engagement we take on, whether it’s a security assessment, a digital accessibility audit, or an independent attestation review. See Practice Areas for the specifics of each; the shared methodology behind all of them, plus our development and maintenance processes, is below.
1. Understand Your Environment
Every engagement starts with understanding your specific environment and compliance obligations, not a one-size-fits-all checklist. We take the time up front to know what you’ve actually built and what you’re actually obligated to.
2. Apply the Right Standard
We tailor recognized, external standards, OWASP’s ASVS and MASVS for application security, OWASP SAMM for security program maturity, NIST 800-63B for authentication, ADA Title II and WCAG for digital accessibility, to what actually applies to your system, excluding requirements that don’t.
3. Open-Book Review
We work directly with your source code, infrastructure, or document corpus. There’s nothing closed-door about it: you see exactly what we looked at and how we got to our findings.
4. Documented Findings, Signed Attestation
You get a detailed report with actionable recommendations your team can act on, and when appropriate, a signed attestation or bridge letter, independent documented evidence of your compliance posture that’s suitable for your own customers’ or regulators’ security inquiries.
5. Continuous, Where It Matters
For programs where compliance is ongoing, like our Metadata Minder-powered digital accessibility audits, review isn’t a one-time project but a continuous practice, since new documents and new code keep shipping after the assessment ends.
Follow-Up Training
For an additional modest fee, we provide follow-up developer training and lunch-and-learns, with quizzes and certificates available for clients who need to document that training was delivered to their team.
New Development Using Agile
For new custom software builds, we follow a proven agile process: a vision and strategy discussion, a two-day workshop to write user stories, a working minimum viable product, and iteration hand-in-hand with you from there, delivering high-value results early and often instead of disappearing for months at a time. That work is handled by our web application development division, Atlanta Ruby Developer. Read the full write-up on their New Development Process.
Maintenance & Support Onboarding
Bringing an existing Rails application under our care, whether it was built by a previous contractor, an in-house developer who’s since moved on, or a team that’s grown past what the codebase can support, is different work from building something new, so we follow a dedicated process for it: due diligence and fit determination, a pre-project code review and security assessment, containerizing the application for long-term support, a test plan that starts with smoke tests for any legacy code with no coverage at all, then working through a prioritized roadmap of security and maintenance fixes before settling into continuous blue team support. That work is also handled by Atlanta Ruby Developer. Read the full write-up on their Maintenance & Support Onboarding Process.
Next Steps
If you'd like to discuss your specific requirements, feel free to schedule a free consultation. We'll provide detailed information about our services and tailor a plan to meet your unique needs. We're based in Alpharetta, GA and serve Metro Atlanta and clients nationwide: +1 (770) 623-2059.