lumora 0%

lumora.codes

با لومورا،در لبه‌ی تکنولوژیحرکت کنید. Move at theedge of technologywith Lumora.

شریک فناوری سازمان‌ها و برندها — هوشمندسازی فرایندها، تست نفوذ اصولی، و بازطراحی تجربه‌ی دیجیتال در تراز جهانی. The technology partner for organizations and brands — process automation, rigorous penetration testing, and world-class digital redesign.

چرا لوموراWhy Lumora

امنیت، طراحی و هوشمندسازی را معمولاً سه پیمانکار جدا انجام می‌دهند. در لومورا هر سه زیر یک سقف است — تا وبسایتی که طراحی می‌کنیم از روز اول امن باشد و سیستمی که خودکار می‌کنیم، قابل اعتماد. Security, design and automation are usually three separate vendors. At Lumora all three sit under one roof — so the website we design is secure from day one, and the systems we automate can be trusted.

  • استانداردهای مرجعReference standards
  • OWASP WSTG
  • OWASP ASVS
  • PTES
  • NIST CSF
  • CVSS v3.1
  • ISO/IEC 27001

آنچه ارائه می‌دهیمWhat we deliver

خدماتServices

01

هوشمندسازی و اتوماسیون فرایندهاIntelligent process automation

درخواست ارزیابی فرایندهاRequest a process assessment

فرایندهای تکراری و زمان‌بر سازمان را شناسایی می‌کنیم و با ترکیب هوش مصنوعی، یکپارچه‌سازی سامانه‌ها و گردش‌کارهای خودکار، آن‌ها را به سیستم‌هایی دقیق، سریع و قابل اندازه‌گیری تبدیل می‌کنیم.We identify the repetitive, time-consuming processes in your organization and turn them into precise, fast and measurable systems by combining AI, system integration and automated workflows.

  • دستیارهای هوشمند مشتریCustomer assistantsپاسخ‌گویی شبانه‌روزی در وبسایت، تلگرام، واتساپ و بله؛ متصل به پایگاه دانش و سامانه‌ی سفارش.Round-the-clock support on your website, Telegram, WhatsApp and Bale, connected to your knowledge base and order system.
  • اتوماسیون گردش‌کارWorkflow automationاتصال CRM، فروشگاه، حسابداری و فرم‌ها؛ حذف ورود دستی داده و ارجاع خودکار وظایف.Connect CRM, store, accounting and forms; remove manual data entry and route tasks automatically.
  • هوش تجاری و داشبورد مدیریتیBI & executive dashboardsیکپارچه‌سازی داده‌های پراکنده در گزارش‌های لحظه‌ای برای تصمیم‌گیری مدیران.Scattered data unified into live reports that support management decisions.
  • پردازش هوشمند اسنادDocument processingاستخراج خودکار اطلاعات از فاکتورها، قراردادها و فرم‌ها با دقت بالا.Automatic extraction of data from invoices, contracts and forms.
  • پیشنهاددهی و شخصی‌سازیPersonalizationپیشنهاد محصول و محتوا متناسب با رفتار هر کاربر برای افزایش فروش.Product and content recommendations tailored to each user’s behavior.
  • استقرار امن مدل‌های زبانیSecure LLM deploymentمدل‌های زبانی روی داده‌های داخلی سازمان، با کنترل دسترسی و حفظ محرمانگی.Language models on your internal data, with access control and confidentiality preserved.
خروجیDeliverables
نقشه‌ی فرایندها، پیاده‌سازی عملیاتی، داشبورد پایش، مستندات و آموزش تیمProcess map, production rollout, monitoring dashboard, documentation and training
زمان معمولTypical timeline
۴ تا ۱۲ هفته4–12 weeks
مناسب برایBest for
تیم‌های فروش، پشتیبانی، عملیات و مالیSales, support, operations and finance teams
02

تست نفوذ و ارزیابی امنیتPenetration testing & security assessment

درخواست تست نفوذRequest a penetration test

پیش از آنکه مهاجمان نقاط ضعف را پیدا کنند، ما آن‌ها را با مجوز رسمی شما و بر پایه‌ی متدولوژی‌های بین‌المللی شناسایی و اولویت‌بندی می‌کنیم و برای رفع هر کدام راهکار مشخص می‌دهیم.Before attackers find your weaknesses, we identify and prioritize them under your formal authorization, following international methodologies, with a specific fix for each one.

  • تست نفوذ وب‌اپلیکیشنWeb application testingارزیابی جامع بر اساس OWASP WSTG و Top 10؛ ترکیب ابزار خودکار و آزمون دستی.Comprehensive assessment based on OWASP WSTG and Top 10, combining tooling with manual testing.
  • امنیت API و سرویس‌هاAPI securityاحراز هویت، کنترل دسترسی، نشت داده و منطق کسب‌وکار در REST و GraphQL.Authentication, access control, data exposure and business logic in REST and GraphQL.
  • زیرساخت و پیکربندیInfrastructure & configurationسرور، DNS، SSL/TLS، هدرهای امنیتی، سرویس‌های در معرض اینترنت و پنل‌های مدیریت.Servers, DNS, SSL/TLS, security headers, exposed services and admin panels.
  • بازبینی امن کدSecure code reviewتحلیل کد منبع برای یافتن آسیب‌پذیری‌ها پیش از انتشار نسخه‌ی جدید.Source code analysis to catch vulnerabilities before a release ships.
  • ارزیابی مهندسی اجتماعیSocial engineeringسنجش آگاهی کارکنان با سناریوهای فیشینگ کنترل‌شده و آموزش هدفمند پس از آن.Staff awareness measured with controlled phishing scenarios, followed by training.
  • تست مجدد و پایش دوره‌ایRetesting & monitoringبررسی دوباره پس از اصلاحات و پایش منظم برای جلوگیری از بازگشت آسیب‌پذیری‌ها.Verification after fixes and regular monitoring so issues don’t return.
خروجیDeliverables
گزارش مدیریتی، گزارش فنی با امتیاز CVSS، راهنمای اصلاح، گواهی تست مجددExecutive summary, technical report with CVSS, remediation guide, retest letter
زمان معمولTypical timeline
۱ تا ۴ هفته1–4 weeks
مناسب برایBest for
فروشگاه‌های آنلاین، فین‌تک‌ها و سامانه‌های سازمانیOnline stores, fintechs and enterprise systems
03

بازطراحی وبسایت و تجربه‌ی کاربریWebsite redesign & user experience

درخواست ممیزی وبسایتRequest a website audit

وبسایت، ویترین دیجیتال برند شماست. با پژوهش کاربر، طراحی دقیق و پیاده‌سازی مهندسی‌شده، تجربه‌ای می‌سازیم که اعتماد ایجاد کند و به نتیجه‌ی تجاری برسد.Your website is your brand’s digital storefront. Through user research, careful design and solid engineering, we build an experience that earns trust and delivers business results.

  • پژوهش و ممیزی تجربه‌ی کاربریUX research & auditتحلیل رفتار کاربران، نقشه‌ی حرارتی، مصاحبه با مشتریان و بررسی رقبا.Behavior analytics, heatmaps, customer interviews and competitor review.
  • معماری اطلاعاتInformation architectureساختاردهی محتوا و مسیرها تا کاربر در کمترین زمان به هدفش برسد.Content and flows structured so users reach their goal in the fewest steps.
  • طراحی رابط کاربریInterface designطراحی اختصاصی و هماهنگ با هویت بصری و ارزش‌های برند شما.Bespoke design aligned with your visual identity and brand values.
  • سیستم طراحیDesign systemکتابخانه‌ی اجزای یکپارچه برای توسعه‌ی سریع و یکدست در آینده.A unified component library for faster, consistent development later.
  • پیاده‌سازی و عملکردEngineering & performanceکد واکنش‌گرا، سریع، دسترس‌پذیر و آماده‌ی سئو با امتیاز بالای Core Web Vitals.Responsive, fast, accessible, SEO-ready builds with strong Core Web Vitals.
  • بهینه‌سازی نرخ تبدیلConversion optimizationآزمون A/B و بهبود مستمر بر پایه‌ی داده‌ی واقعی کاربران.A/B testing and continuous improvement driven by real user data.
خروجیDeliverables
گزارش ممیزی، فایل‌های طراحی و پروتوتایپ، سیستم طراحی، وبسایت و تحویل کامل کدAudit report, design files and prototype, design system, website with full code handover
زمان معمولTypical timeline
۶ تا ۱۴ هفته6–14 weeks
مناسب برایBest for
برندهایی که وبسایتشان قدیمی، کند یا کم‌بازده استBrands with a dated, slow or underperforming site
04

مشاوره‌ی تخصصی و تحول دیجیتالConsulting & digital transformation

رزرو جلسه‌ی مشاورهBook a consulting session

پیش از سرمایه‌گذاری روی ابزار، تیم یا پروژه‌ی جدید، تصویری روشن از مسیر داشته باشید. مشاوره‌ی ما بر داده، تجربه‌ی اجرایی و شناخت دقیق بازار ایران استوار است.Get a clear picture of the road ahead before investing in new tools, hires or projects. Our advice is grounded in data, delivery experience and close knowledge of the local market.

  • نقشه‌ی راه تحول دیجیتالTransformation roadmapارزیابی وضعیت فعلی، تعیین اهداف و برنامه‌ی گام‌به‌گام اجرایی.Current-state assessment, clear goals and a step-by-step plan.
  • انتخاب معماری و فناوریTechnology selectionمشاوره در انتخاب زیرساخت، پلتفرم، سرویس‌دهنده و تأمین‌کننده.Guidance on infrastructure, platforms, hosting and vendors.
  • راهبرد امنیت اطلاعاتSecurity strategyتدوین سیاست‌ها، مدیریت ریسک و همسویی با استانداردهایی مانند ISO/IEC 27001.Policies, risk management and alignment with standards such as ISO/IEC 27001.
  • حاکمیت داده و هوش مصنوعیData & AI governanceچارچوب استفاده‌ی مسئولانه و امن از ابزارهای هوش مصنوعی در سازمان.A framework for responsible, secure use of AI tools in your organization.
  • آموزش و توانمندسازیTeam enablementکارگاه‌های تخصصی امنیت، اتوماسیون و محصول برای کارکنان.Specialist workshops on security, automation and product.
  • مدیر فنی پاره‌وقتFractional CTOهمراهی مستمر در تصمیم‌های فنی کلیدی، بدون هزینه‌ی استخدام تمام‌وقت.Ongoing support on key technical decisions without a full-time hire.
خروجیDeliverables
ارزیابی بلوغ دیجیتال، نقشه‌ی راه و برآورد بودجه، اسناد سیاست و فرایندDigital maturity assessment, roadmap and budget, policy and process documents
زمان معمولTypical timeline
از یک جلسه تا قرارداد سالانهFrom one session to an annual retainer
مناسب برایBest for
مدیران عامل، مدیران فناوری و تیم‌های در حال رشدCEOs, CTOs and growing teams

امنیت کاربردیActionable security

گزارشی که می‌شود با آن تصمیم گرفتA report you can make decisions with

خروجی تست نفوذ ما فهرستی طولانی از هشدارهای خودکار نیست. هر یافته با شدت، محل دقیق، شواهد و راه اصلاح ارائه می‌شود؛ قابل فهم برای مدیران و قابل اجرا برای تیم فنی.Our penetration test output isn’t a long list of automated warnings. Every finding has a severity, exact location, evidence and fix, clear to leadership and actionable for engineers.

جعبه‌سیاهBlack box
بدون اطلاعات قبلی، از نگاه یک مهاجم بیرونی.No prior knowledge, as an outside attacker sees you.
جعبه‌خاکستریGray box
با دسترسی کاربر عادی، برای سنجش خطر از داخل حساب‌ها.With user-level access, to measure risk from inside accounts.
جعبه‌سفیدWhite box
با دسترسی به کد و معماری، برای عمیق‌ترین سطح ارزیابی.With code and architecture access, for the deepest review.
  • هر تست فقط با قرارداد رسمی و محدوده‌ی مکتوب انجام می‌شود.Every test runs under a formal contract with a written scope.
  • توافق‌نامه‌ی عدم افشا پیش از دریافت هر اطلاعاتی امضا می‌شود.An NDA is signed before we receive any information.
  • داده‌ها و شواهد پس از تحویل، از سامانه‌های ما حذف می‌شوند.Data and evidence are deleted from our systems after handover.
CONFIDENTIAL

Penetration Test Report

Web Application & API Assessment

Reference
LM-SEC-0142
Method
Gray box · OWASP WSTG
Findings
19
Critical1
High3
Medium6
Low9
IDFindingCVSS
F-01SQL injection in search endpoint9.1
F-02Broken access control on /api/orders8.1
F-03Admin panel exposed without 2FA7.5
F-04Missing Content-Security-Policy5.3
Page 3 of 24lumora.codes
نمونه‌ی ساختار گزارش؛ داده‌ها واقعی نیستند.Sample report structure; data is illustrative.

نمونه پروژه‌هاSelected work

پروژه‌های زیرساختی و امنیتی که اجرا کرده‌ایمInfrastructure & security projects we have delivered

از مدیریت دسترسی ممتاز تا Zero Trust، ضد DDoS و DNS تحریم‌شکن — هر پروژه با معماری، پیاده‌سازی، سخت‌سازی و تحویل عملیاتی کامل همراه بوده است.From privileged access to Zero Trust, anti-DDoS and sanctions-aware DNS — each engagement covered architecture, implementation, hardening and full operational handover.

01عملیاتیLive

Privileged Access Management

سامانه PAM برای کنترل کامل دسترسی‌های ممتازPAM platform for full control of privileged access

  • حوزه: امنیت هویتDomain: Identity security
  • خروجی: Vault + Session + AuditOutput: Vault + Session + Audit
  • وضعیت: عملیاتیStatus: Production

دسترسی ادمین، روت، دیتابیس و سرویس‌اکانت‌ها معمولاً پراکنده، بدون چرخش رمز و بدون ردپای دقیق است. در این پروژه یک لایه PAM طراحی و پیاده‌سازی شد تا هیچ دسترسی ممتازی خارج از کنترل، بدون زمان‌بندی و بدون ثبت نشست باقی نماند.Admin, root, database and service-account access is often scattered, without password rotation or a clear audit trail. This project designed and delivered a PAM layer so no privileged access stays uncontrolled, unscheduled or unrecorded.

چه مشکلی را حل کردیم؟What problem did we solve?

  • رمزهای مشترک روی سرورها و سوییچ‌هاShared passwords on servers and network gear
  • عدم شفافیت اینکه چه کسی، کی، به کدام سیستم وصل شدهNo clarity on who connected where and when
  • ریسک نشت credential پیمانکاران و تیم‌های بیرونیCredential leakage risk from contractors and external teams

چه پیاده‌سازی شد؟What was implemented?

  • گاوصندوق مرکزی رمز و کلید (Credential Vault) با چرخش خودکارCentral credential vault with automatic rotation
  • دسترسی Just-In-Time و تأیید چندمرحله‌ای برای ورود ممتازJust-in-time privileged access with multi-step approval
  • ضبط و بازپخش نشست‌های SSH / RDP / Web AdminRecording and playback of SSH / RDP / web-admin sessions
  • یکپارچه‌سازی با Active Directory / LDAP و SIEMIntegration with Active Directory / LDAP and SIEM
  • گزارش‌گیری ممیزی برای تیم امنیت و انطباقAudit reporting for security and compliance teams

نتیجه برای سازمانBusiness outcome

سطح حملهٔ دسترسی ممتاز به‌شدت کوچک شد، رمزهای ایستا حذف شدند و در رخداد امنیتی، مسیر پیگیری دقیق نشست‌ها در دسترس تیم SOC قرار گرفت.The privileged attack surface shrank sharply, static passwords disappeared, and the SOC gained a precise session trail for incident response.

02عملیاتیLive

Zero Trust Network Access

ZTNA؛ جایگزینی امن برای VPN سنتیZTNA — a secure replacement for legacy VPN

  • حوزه: دسترسی از راه دورDomain: Remote access
  • خروجی: Agent + Gateway + PolicyOutput: Agent + Gateway + Policy
  • وضعیت: عملیاتیStatus: Production

VPN کلاسیک معمولاً کاربر را داخل شبکه می‌اندازد و بعد تازه کنترل می‌کند. در مدل Zero Trust، هویت، دستگاه و زمینهٔ درخواست قبل از هر دسترسی بررسی می‌شود و کاربر فقط به همان اپلیکیشن یا سرویس مجاز می‌رسد — نه کل شبکه.Classic VPN often drops a user onto the network and controls access afterwards. With Zero Trust, identity, device and request context are checked before every connection — and the user reaches only the allowed app or service, not the whole network.

چه مشکلی را حل کردیم؟What problem did we solve?

  • گستردگی بیش از حد دسترسی دورکاری روی VPNOver-broad remote access through VPN
  • ریسک حرکت جانبی مهاجم پس از نفوذ به یک اکانتLateral-movement risk after one account is compromised
  • تجربهٔ ضعیف کاربران و قطعی‌های مکرر تونلPoor user experience and frequent tunnel drops

چه پیاده‌سازی شد؟What was implemented?

  • دروازه‌های ZTNA برای اپ‌های وب، SSH و سرویس‌های داخلیZTNA gateways for web apps, SSH and internal services
  • سیاست مبتنی بر هویت، گروه، دستگاه و موقعیتPolicies based on identity, group, device and context
  • حذف تدریجی VPN پهن برای تیم‌های عملیاتی و پیمانکارانPhased retirement of broad VPN for ops teams and contractors
  • لاگ اتصال، کنترل نشست و قطع خودکار دسترسی پرریسکConnection logs, session control and auto-kill for risky access
  • هم‌ترازی با IAM و MFA سازمانیAlignment with corporate IAM and MFA

نتیجه برای سازمانBusiness outcome

دورکاری امن‌تر شد، سطح دیده‌شدن شبکه داخلی از اینترنت کاهش یافت و تیم امنیت کنترل دقیق per-app به‌جای «کل تونل» به‌دست آورد.Remote work became safer, internal network exposure dropped, and security gained precise per-app control instead of an all-or-nothing tunnel.

03عملیاتیLive

Identity & Access Management

IAM سازمانی؛ هویت یکپارچه از ورود تا خروجEnterprise IAM — identity from join to leave

  • حوزه: هویت دیجیتالDomain: Digital identity
  • خروجی: Lifecycle + RBAC + AuditOutput: Lifecycle + RBAC + Audit
  • وضعیت: عملیاتیStatus: Production

بدون IAM منسجم، هر سامانه حساب جدا، نقش مبهم و دسترسی فراموش‌شده دارد. این پروژه لایهٔ هویت مرکزی ساخت: تعریف کاربر، نقش، دسترسی، تأیید، بازبینی دوره‌ای و قطع خودکار هنگام خروج از سازمان.Without coherent IAM, every system has separate accounts, fuzzy roles and forgotten access. This project built a central identity layer: users, roles, entitlements, approvals, periodic access reviews and automatic offboarding.

چه مشکلی را حل کردیم؟What problem did we solve?

  • حساب‌های یتیم پس از جابه‌جایی یا ترک نیروOrphan accounts after transfers or exits
  • اعطای دستی و کند دسترسی در سامانه‌های متعددSlow manual provisioning across many systems
  • نبود مدل نقش استاندارد (RBAC/ABAC)No standard role model (RBAC/ABAC)

چه پیاده‌سازی شد؟What was implemented?

  • منبع حقیقت هویت و همگام‌سازی با HR / DirectoryIdentity source of truth synced with HR / directory
  • مدل نقش‌ها، گروه‌ها و سیاست حداقل دسترسیRoles, groups and least-privilege policies
  • Provisioning / Deprovisioning خودکار به اپ‌های کلیدیAutomated provisioning and deprovisioning to key apps
  • بازبینی دسترسی دوره‌ای برای مدیران و ممیزیPeriodic access reviews for managers and auditors
  • داشبورد مالکیت دسترسی و هشدار انحراف از سیاستAccess-ownership dashboards and policy-drift alerts

نتیجه برای سازمانBusiness outcome

آنبوردینگ سریع‌تر، خروج امن‌تر، و برای امنیت دیدی واحد از «چه کسی به چه چیزی دسترسی دارد» ایجاد شد.Faster onboarding, safer offboarding, and one clear view for security of who can reach what.

04عملیاتیLive

Anti-DDoS & Availability Shield

لایه Anti-DDoS برای پایداری سرویس در اوج حملهAnti-DDoS layer for service survival under attack

  • حوزه: دسترس‌پذیریDomain: Availability
  • خروجی: Edge Filter + RunbookOutput: Edge filter + runbook
  • وضعیت: عملیاتیStatus: Production

حملهٔ DDoS فقط «ترافیک زیاد» نیست؛ ترکیبی از سیلاب حجمی، اگزوز منابع اپلیکیشن و درخواست‌های به‌ظاهر معتبر است. برای این پروژه سپر چندلایه از لبهٔ شبکه تا لایهٔ اپلیکیشن طراحی شد تا سایت و API در اوج حمله زنده بمانند.DDoS is not just “lots of traffic” — it mixes volumetric floods, application exhaustion and seemingly valid requests. This project built a multi-layer shield from network edge to application so sites and APIs stay up under attack.

چه مشکلی را حل کردیم؟What problem did we solve?

  • از دسترس خارج شدن سرویس در کمپین‌های تبلیغاتی یا رخدادهای سیاسی/رقابتیOutages during campaigns or competitive/political attack windows
  • اشباع لینک، فایروال و سرورهای originSaturation of links, firewalls and origin servers
  • نبود Runbook واکنش سریع برای تیم عملیاتNo rapid-response runbook for operations

چه پیاده‌سازی شد؟What was implemented?

  • فیلترینگ حجمی و رفتاری در لبه (L3/L4/L7)Volumetric and behavioral filtering at the edge (L3/L4/L7)
  • Rate limit هوشمند، چالش ربات و محافظت از endpointهای حساسSmart rate limits, bot challenges and protection for sensitive endpoints
  • Anycast / DNS failover و جداسازی ترافیک پاک از آلودهAnycast / DNS failover and clean-vs-dirty traffic separation
  • مانیتورینگ حملات، هشدار و داشبورد وضعیت لحظه‌ایAttack monitoring, alerts and live status dashboards
  • تمرین میزقرمز و Runbook فعال‌سازی سپرTabletop drills and shield-activation runbooks

نتیجه برای سازمانBusiness outcome

زمان ازکارافتادگی ناشی از سیلاب به‌شدت کاهش یافت و تیم عملیات به‌جای واکنش دستی پراکنده، فرایند مشخص دفاع و بازیابی دارد.Flood-driven downtime dropped sharply, and operations moved from ad-hoc firefighting to a clear defend-and-recover process.

05عملیاتیLive

TahrimShecan DNS

DNS تحریم‌شکن برای دسترسی پایدار سازمان به سرویس‌های جهانیSanctions-aware DNS for reliable access to global services

  • حوزه: DNS و اتصالDomain: DNS & connectivity
  • خروجی: Resolver + Policy + HAOutput: Resolver + policy + HA
  • وضعیت: عملیاتیStatus: Production

بسیاری از سرویس‌های توسعه، ابری و تجاری برای کاربران ایرانی در لایهٔ DNS یا مسیر پاسخ دچار اختلال می‌شوند. پروژهٔ TahrimShecan یک Resolver سازمانی ساخت که با سیاست شفاف، کش هوشمند و مسیرهای جایگزین، نام‌ها را پایدار resolve کند — بدون اینکه کل ترافیک سازمان بی‌ضابطه باز شود.Many developer, cloud and commercial services break for Iranian users at the DNS or response path. TahrimShecan built an enterprise resolver with clear policy, smart caching and alternate paths — resolving names reliably without turning the whole network into an uncontrolled open tunnel.

چه مشکلی را حل کردیم؟What problem did we solve?

  • شکست resolve برای پکیج‌ها، رجیستری‌ها، CDNها و APIهای بین‌المللیBroken resolution for packages, registries, CDNs and global APIs
  • وابستگی تیم‌ها به DNSهای عمومی ناپایدار و غیرممیزیTeams relying on unstable, unaudited public DNS
  • نبود کنترل سیاستی روی اینکه کدام دامنه مجاز استNo policy control over which domains are allowed

چه پیاده‌سازی شد؟What was implemented?

  • Resolver داخلی با High Availability و health-checkInternal resolver with high availability and health checks
  • کش چندلایه، negative caching کنترل‌شده و به‌روزرسانی سریع رکوردهاMulti-layer cache, controlled negative caching and fast record refresh
  • لیست مجاز/مسدود و سیاست per-OU برای واحدهای سازمانAllow/deny lists and per-OU policies for business units
  • لاگ پرس‌وجو، داشبورد مصرف و هشدار اختلال بالادستQuery logs, usage dashboards and upstream-outage alerts
  • یکپارچه با فایروال و مسیرهای خروجی کنترل‌شدهIntegration with firewalls and controlled egress paths

نتیجه برای سازمانBusiness outcome

تیم‌های فنی به سرویس‌های ضروری با پایداری بالاتر دسترسی پیدا کردند و همزمان حاکمیت DNS و قابلیت ممیزی برای امنیت حفظ شد.Engineering regained more reliable access to essential services while security kept DNS governance and auditability.

06عملیاتیLive

SSO · MFA · Federation

ورود یکپارچه سازمانی با SSO و MFA اجباریEnterprise SSO with mandatory MFA

  • حوزه: احراز هویتDomain: Authentication
  • خروجی: IdP + App FederationOutput: IdP + app federation
  • وضعیت: عملیاتیStatus: Production

کاربران ده‌ها رمز جدا برای ایمیل، CRM، گیت، پنل‌های ابری و ابزار داخلی داشتند. این پروژه Identity Provider مرکزی با SSO (SAML/OIDC) و MFA اجباری برای نقش‌های حساس پیاده کرد تا ورود یک‌باره، امن و قابل قطع‌کردن باشد.Users juggled separate passwords for email, CRM, git, cloud consoles and internal tools. This project delivered a central identity provider with SSO (SAML/OIDC) and mandatory MFA for sensitive roles — one secure, revocable sign-in.

دامنهٔ اتصالFederation scope

  • ایمیل سازمانی، پرتال منابع انسانی، CRM و هلپ‌دسکCorporate email, HR portal, CRM and helpdesk
  • Git، CI/CD، پنل ابری و ابزار مانیتورینگGit, CI/CD, cloud consoles and monitoring tools
  • VPN/ZTNA و پنل‌های مدیریتی حساس با MFA سختVPN/ZTNA and sensitive admin panels with hard MFA

نتیجهOutcome

حملات مبتنی بر رمز دزدیده‌شده کاهش یافت، پشتیبانی IT از ریست رمز کمتر شد و قطع دسترسی یک کاربر در همهٔ سامانه‌ها در چند دقیقه ممکن شد.Credential-stuffing risk dropped, IT password resets fell, and revoking one user across all systems became a minutes-long operation.

07عملیاتیLive

SOC · SIEM · Detection

راه‌اندازی SOC سبک با SIEM و detection کاربردیLean SOC with SIEM and practical detection

  • حوزه: عملیات امنیتDomain: Security operations
  • خروجی: Log Pipeline + Use CasesOutput: Log pipeline + use cases
  • وضعیت: عملیاتیStatus: Production

لاگ‌ها بودند اما دیده نمی‌شدند. این پروژه خط لولهٔ متمرکز لاگ، همبستگی رویداد و use-caseهای تشخیص (bruteforce، دسترسی غیرعادی PAM، ناهنجاری DNS، تغییرات بحرانی) را برای یک SOC سبک اما واقعی پیاده کرد.Logs existed but were invisible. This project built a centralized log pipeline, event correlation and detection use-cases (bruteforce, abnormal PAM access, DNS anomalies, critical changes) for a lean but real SOC.

اجزای کلیدیKey building blocks

  • جمع‌آوری از فایروال، IdP، PAM، سرورها، WAF و DNSIngest from firewall, IdP, PAM, servers, WAF and DNS
  • داشبوردهای شیفت، severity و وضعیت تیکتShift dashboards, severity views and ticket status
  • Playbook واکنش به حادثه برای ۱۰ سناریوی پرتکرارIncident playbooks for the ten most common scenarios
  • نگهداری لاگ مطابق سیاست نگهداری و نیاز ممیزیLog retention aligned with policy and audit needs

نتیجهOutcome

میانگین زمان تشخیص و پاسخ کوتاه‌تر شد و امنیت از حالت «بعد از حادثه» به پایش فعال روزانه رسید.Mean time to detect and respond shortened, and security moved from after-the-fact reaction to daily active monitoring.

08عملیاتیLive

WAF · API Gateway · Edge

WAF و API Gateway برای سپر لایهٔ اپلیکیشنWAF and API gateway as an application-layer shield

  • حوزه: امنیت وب و APIDomain: Web & API security
  • خروجی: Policy Set + ObservabilityOutput: Policy set + observability
  • وضعیت: عملیاتیStatus: Production

تست نفوذ آسیب‌پذیری را نشان می‌دهد؛ WAF و API Gateway جلوی بهره‌برداری روزمره را می‌گیرند. در این پروژه ترافیک وب و API از یک لبهٔ کنترل‌شده عبور کرد: قوانین OWASP، schema validation، محدودیت متد/نرخ، و جداسازی سرویس‌های عمومی از داخلی.Pentests show vulnerabilities; WAF and API gateways blunt everyday exploitation. This project put web and API traffic behind a controlled edge: OWASP rules, schema validation, method/rate limits, and separation of public vs internal services.

قابلیت‌های تحویل‌شدهCapabilities delivered

  • مجموعه قوانین سفارشی برای اپ و APIهای سازمانCustom rule sets for the organization’s apps and APIs
  • محافظت در برابر SQLi، XSS، bot abuse و اسکن انبوهProtection against SQLi, XSS, bot abuse and mass scanning
  • JWT/OAuth introspection در Gateway و قطع توکن‌های نامعتبرJWT/OAuth introspection at the gateway; reject invalid tokens
  • مشاهده‌پذیری: لاگ بلاک، false-positive tuning، داشبورد حملهObservability: block logs, false-positive tuning, attack dashboards

نتیجهOutcome

نویز اسکنر و سوءاستفاده‌های ابتدایی قبل از رسیدن به origin فیلتر شد و تیم توسعه فرصت پچ پایدار گرفت بدون آتش‌نشانی روزانه.Scanner noise and basic abuse were filtered before origin, giving engineering time for durable patches instead of daily firefighting.

برای پروژه مشابه صحبت کنیمTalk about a similar project بازگشت به خدماتBack to services

حوزه‌های تخصصیFocus areas

صنایعی که با آن‌ها کار می‌کنیمIndustries we work with

هر صنعت ریسک‌ها، الزامات و فرصت‌های خودش را دارد. راهکارهای ما از دل همین تفاوت‌ها طراحی می‌شوند.Every industry has its own risks, requirements and opportunities. Our work is shaped around those differences.

  • 01

    تجارت الکترونیک و خرده‌فروشیE-commerce & retail

    امنیت پرداخت و حساب کاربران، پشتیبانی خودکار سفارش‌ها، بهینه‌سازی نرخ تبدیل.Payment and account security, automated order support, conversion optimization.

  • 02

    مالی، بانکی و فین‌تکFinance & fintech

    تست نفوذ API، همسویی با الزامات نظارتی، هوشمندسازی احراز هویت.API penetration testing, regulatory alignment, smarter identity verification.

  • 03

    سلامت و درمانHealthcare

    حفاظت از داده‌ی بیماران، نوبت‌دهی هوشمند، یکپارچه‌سازی سامانه‌ها.Patient data protection, smart scheduling, system integration.

  • 04

    آموزشEducation

    پلتفرم‌های یادگیری پایدار و امن، اتوماسیون ثبت‌نام، پشتیبانی دانشجویان.Reliable learning platforms, enrollment automation, student support.

  • 05

    صنعت و تولیدManufacturing

    داشبوردهای عملیاتی، اتوماسیون زنجیره‌ی تأمین، امنیت سامانه‌های داخلی.Operational dashboards, supply-chain automation, internal systems security.

  • 06

    رسانه و استارتاپ‌هاMedia & startups

    زیرساخت مقیاس‌پذیر، توسعه‌ی سریع محصول، رشد مبتنی بر داده.Scalable infrastructure, fast product development, data-driven growth.

نحوه همکاریHow we engage

مدل‌های همکاریEngagement models

بسته به هدف و بودجه، یکی از این سه شیوه را انتخاب می‌کنیم. در جلسه‌ی اول کمکتان می‌کنیم مناسب‌ترین را پیدا کنید.Depending on your goal and budget, we work in one of three ways. We’ll help you choose in the first meeting.

01

ارزیابی سریعAssessment sprint

شناخت وضعیت و اولویت‌هاUnderstand where you stand

مدتDuration
۱ تا ۲ هفته1–2 weeks
قیمت‌گذاریPricing
ثابتFixed
گزارش‌دهیReporting
گزارش نهایی یافته‌هاFinal findings report
پشتیبانیSupport
یک جلسه‌ی پرسش و پاسخOne Q&A session

03

همراهی مستمرOngoing retainer

تیم فنی و امنیتی در کنار شماA tech & security team on call

مدتDuration
ماهانه، حداقل ۳ ماهMonthly, 3-month minimum
قیمت‌گذاریPricing
ماهانه با ساعات مشخصMonthly, set hours
گزارش‌دهیReporting
گزارش ماهانه و پایش مداومMonthly report, continuous monitoring
پشتیبانیSupport
در طول قراردادThroughout the contract

فرآیندProcess

روش کار ماHow we work

  1. ۱1

    شناختDiscovery

    جلسه‌ی رایگان برای درک اهداف، چالش‌ها و محدودیت‌ها.A free session on your goals, challenges and constraints.

    خلاصه‌ی نیازهاNeeds brief
  2. ۲2

    ارزیابیAssessment

    بررسی فنی وضعیت فعلی، فرصت‌ها و ریسک‌ها.Technical review of the current state, opportunities and risks.

    گزارش ارزیابیAssessment report
  3. ۳3

    پیشنهاد و قراردادProposal

    راهکار، زمان‌بندی و هزینه‌ی دقیق؛ امضای قرارداد و NDA.Solution, timeline and cost; contract and NDA signed.

    پیشنهاد فنی و مالیTechnical & commercial proposal
  4. ۴4

    اجراDelivery

    اجرا در فازهای کوتاه با گزارش منظم و بازبینی در هر مرحله.Short phases with regular reporting and review at each step.

    نسخه‌های قابل بررسیReviewable releases
  5. ۵5

    تحویل و پشتیبانیHandover

    تحویل کامل، مستندسازی، آموزش تیم و پشتیبانی.Full handover, documentation, training and support.

    مستندات و آموزشDocumentation & training

اصول حرفه‌ایPrinciples

تعهدات ما به هر مشتریOur commitments to every client

محرمانگی قراردادیContractual confidentiality

اطلاعات شما تحت توافق‌نامه‌ی رسمی محافظت می‌شود و نام هیچ مشتری‌ای بدون اجازه منتشر نمی‌شود.Your information is protected by formal agreement, and no client is named without permission.

نتیجه‌ی قابل اندازه‌گیریMeasurable outcomes

شاخص‌های موفقیت پیش از شروع تعیین می‌شود و پروژه با همان شاخص‌ها سنجیده می‌شود.Success metrics are agreed before we start, and the project is judged against them.

شفافیت در هزینهTransparent pricing

قیمت ثابت برای پروژه‌ها، بدون هزینه‌ی پنهان؛ هر تغییر محدوده پیش از اجرا تأیید می‌شود.Fixed prices for projects, no hidden costs; any scope change is approved first.

انتقال کامل دانشFull knowledge transfer

کد، مستندات و دسترسی‌ها کامل تحویل می‌شود تا به هیچ پیمانکاری، حتی ما، وابسته نباشید.Code, documentation and access are handed over in full, so you depend on no vendor, including us.

دانش و راهنماInsights

مقالات تخصصی برای تصمیم‌گیری بهترExpert guides for better decisions

راهنماهای عملی درباره‌ی تست نفوذ، هوشمندسازی، بازطراحی وبسایت و تحول دیجیتال — نوشته‌شده برای مدیران و تیم‌های فنی.Practical guides on penetration testing, automation, redesign and digital transformation — written for leaders and technical teams.

مشاهده همه‌ی مقالاتView all articles

پاسخ‌هاAnswers

پرسش‌های متداولFrequently asked questions

پاسخ پرسشتان اینجا نیست؟ با ما تماس بگیریدQuestion not answered here? Contact us

آیا تست نفوذ باعث اختلال در سرویس ما می‌شود؟Will penetration testing disrupt our service?

خیر. محدوده و زمان تست پیش از شروع توافق می‌شود و آزمون‌های سنگین‌تر در ساعات کم‌ترافیک یا روی نسخه‌ی آزمایشی انجام می‌گیرد. در طول تست یک کانال ارتباطی مستقیم با تیم فنی شما باز است.No. Scope and timing are agreed in advance, and heavier tests run during low-traffic hours or on staging. A direct line to your technical team stays open throughout.

برای هوشمندسازی باید سامانه‌های فعلی را کنار بگذاریم؟Do we need to replace our systems to automate?

معمولاً نه. اتوماسیون را روی همان ابزارهایی پیاده می‌کنیم که امروز استفاده می‌کنید؛ از وبسایت و فروشگاه تا CRM، حسابداری و پیام‌رسان‌ها.Usually not. We build on the tools you already use, from your website and store to CRM, accounting and messengers.

داده‌های ما در پروژه‌های هوش مصنوعی کجا نگهداری می‌شود؟Where is our data stored in AI projects?

بسته به حساسیت داده، راهکار روی زیرساخت داخلی شما یا سرویس‌دهنده‌ی مورد تأییدتان مستقر می‌شود. سطح دسترسی و مدت نگهداری داده پیش از شروع مکتوب می‌شود.Depending on sensitivity, we deploy on your infrastructure or a provider you approve. Access levels and retention are documented before work begins.

یک پروژه‌ی بازطراحی چقدر زمان می‌برد؟How long does a redesign take?

بسته به اندازه و پیچیدگی وبسایت، معمولاً ۶ تا ۱۴ هفته. زمان‌بندی دقیق در پیشنهاد رسمی اعلام می‌شود.Usually 6 to 14 weeks depending on size and complexity. The exact timeline is in the formal proposal.

هزینه‌ی خدمات چگونه تعیین می‌شود؟How is pricing determined?

برای پروژه‌های مشخص، پیشنهاد قیمت ثابت می‌دهیم. همراهی مستمر به‌صورت قرارداد ماهانه با ساعات مشخص تنظیم می‌شود.Defined projects get a fixed-price proposal. Retainers run monthly with set hours.

پس از تحویل پروژه چه اتفاقی می‌افتد؟What happens after handover?

هر پروژه یک دوره‌ی پشتیبانی دارد. پس از آن می‌توانید همراهی مستمر را ادامه دهید یا با مستندات کامل، کار را به تیم داخلی بسپارید.Every project includes a support period. After that, continue on a retainer or hand over to your in-house team with full documentation.

شروع همکاریGet started

یک قدم جلوتر از تکنولوژی بمانید.Stay a step ahead of technology.

فرم را تکمیل کنید؛ ظرف یک روز کاری برای هماهنگی جلسه‌ی رایگان اولیه با شما تماس می‌گیریم.Complete the form and we’ll contact you within one business day to arrange a free first meeting.

ایمیلEmail
hello@lumora.codes
ساعات کاریBusiness hours
شنبه تا چهارشنبه، ۹ تا ۱۸Sat–Wed, 9:00–18:00 Tehran
حوزه‌ی مورد نیازWhat do you need?

درخواست جلسهBook a meeting