Melius Praxis

Independent · Senior-led · Bangkokอิสระ · นำโดยผู้เชี่ยวชาญอาวุโส · กรุงเทพฯ

Cybersecurity, IT audit, and smart-contract assurance.ความมั่นคงปลอดภัยไซเบอร์ การตรวจสอบไอที และการรับรองสัญญาอัจฉริยะ

Melius Praxis is a small, independent practice. We assess security, audit IT and smart contracts, and dispose of data — then document the evidence to a standard that holds up under scrutiny, whether the reader is a regulator, a client, or an attacker.Melius Praxis เป็นบริษัทที่ปรึกษาอิสระเฉพาะทาง เราให้บริการประเมินความมั่นคงปลอดภัยไซเบอร์ ตรวจสอบระบบไอทีและสัญญาอัจฉริยะ รวมถึงการกำจัดข้อมูลอย่างปลอดภัย พร้อมจัดทำรายงานหลักฐานตามมาตรฐานสากลที่สามารถตรวจสอบได้ ไม่ว่าผู้ประเมินผลจะเป็นหน่วยงานกำกับดูแล ลูกค้า หรือผู้ไม่ประสงค์ดี

Servicesบริการ

Four lines of work.บริการหลัก 4 ด้าน

Each engagement is led hands-on by a certified practitioner — not scoped by one team and delivered by another.ทุกโครงการดำเนินการโดยตรงจากผู้เชี่ยวชาญที่ได้รับการรับรอง โดยไม่มีการส่งผ่านงานจากทีมประเมินขอบเขตไปยังทีมปฏิบัติการอื่น

Securityความมั่นคงปลอดภัย

Cybersecurity & infosec consultingที่ปรึกษาความมั่นคงปลอดภัยไซเบอร์และสารสนเทศ

Security assessments, architecture and cloud review, and advisory — from threat modelling to board-level risk. Findings are practical and ranked by real exposure, not by a scanner's severity score. Penetration testing is delivered with vetted specialist partners, scoped and overseen by us.การประเมินความมั่นคงปลอดภัย การทบทวนสถาปัตยกรรมและระบบคลาวด์ และการให้คำปรึกษา ตั้งแต่การจำลองภัยคุกคาม (Threat Modelling) ไปจนถึงการบริหารความเสี่ยงระดับคณะกรรมการบริหาร ผลการประเมินสามารถนำไปประยุกต์ใช้ได้จริง และจัดลำดับความสำคัญตามความเสี่ยงที่แท้จริง ไม่ใช่เพียงอ้างอิงจากระดับความรุนแรงของเครื่องมือสแกนเนอร์ ทั้งนี้ บริการทดสอบเจาะระบบ (Penetration Testing) ดำเนินการร่วมกับพันธมิตรผู้เชี่ยวชาญเฉพาะทางที่เราคัดสรร ภายใต้การกำหนดขอบเขตและกำกับดูแลโดยเรา

threat modelling · cloud · assessments · advisory
Auditการตรวจสอบ

IT auditการตรวจสอบไอที

Independent audit of controls, processes, and compliance posture against the frameworks your stakeholders care about — ISO 27001, NIST, PCI DSS, and Thai regulatory requirements. Clear evidence, defensible conclusions.การตรวจสอบการควบคุม กระบวนการ และความสอดคล้องตามมาตรฐานอย่างเป็นอิสระ โดยอ้างอิงจากกรอบการทำงานที่ผู้มีส่วนได้ส่วนเสียของคุณให้ความสำคัญ — ISO 27001, NIST, PCI DSS และข้อกำหนดของหน่วยงานกำกับดูแลไทย พร้อมแสดงหลักฐานที่ชัดเจนและข้อสรุปที่สมเหตุสมผลและปกป้องได้ทางกฎหมาย

ISO 27001 · NIST · PCI DSS · controls
Web3Web3

Smart-contract auditการตรวจสอบสัญญาอัจฉริยะ

Line-by-line review of Solidity and on-chain logic: reentrancy, access control, and economic and integer flaws. Written up so both your developers and your investors can act on it before you ship.การทบทวนซอร์สโค้ด Solidity และตรรกะการทำงานบนบล็อกเชน (On-chain Logic) อย่างละเอียดแบบบรรทัดต่อบรรทัด: reentrancy การควบคุมสิทธิ์ และช่องโหว่เชิงเศรษฐศาสตร์และจำนวนเต็ม พร้อมจัดทำรายงานข้อเสนอแนะที่นักพัฒนาและนักลงทุนสามารถนำไปพิจารณาก่อนการเปิดตัวระบบจริง

solidity · reentrancy · access-control · gas
Dataข้อมูล

Secure data disposalการทำลายข้อมูลอย่างปลอดภัย

Verifiable decommissioning and destruction of data and media, with the chain-of-custody documentation and certificates of destruction your obligations — and your clients — require.การปลดระวางและกำจัดข้อมูลรวมถึงสื่อบันทึกในรูปแบบที่สามารถตรวจสอบได้ พร้อมจัดทำเอกสารสายการควบคุม (Chain of Custody) และใบรับรองการทำลายข้อมูลตามที่ภาระผูกพันของคุณ — และลูกค้าของคุณ — กำหนด

sanitisation · chain-of-custody · certificates

How we workวิธีการทำงาน

Every engagement, the same discipline.ทุกโครงการ ดำเนินการด้วยมาตรฐานเดียวกัน

01 — Scope01 — ขอบเขต

Scopeกำหนดขอบเขต

We agree exactly what's in scope, what "good" looks like, and how findings will be reported — before any work starts.เราร่วมกันตกลงขอบเขตงานที่ชัดเจน กำหนดมาตรฐานผลลัพธ์ที่คาดหวัง และรูปแบบการรายงานผล ก่อนเริ่มปฏิบัติงานทุกครั้ง

02 — Assess02 — ประเมิน

Assessประเมิน

Hands-on testing and review by the person who signs the report. Nothing is quietly handed down to a junior team.ดำเนินการทดสอบและทบทวนโดยผู้เชี่ยวชาญที่เป็นผู้ลงนามในรายงานโดยตรง ไม่มีการส่งต่อภาระงานให้ทีมงานระดับเริ่มต้นรับผิดชอบแทน

03 — Report03 — รายงาน

Reportรายงาน

Findings in plain language, ranked by real risk, each with reproducible evidence and specific, actionable remediation.รายงานข้อค้นพบด้วยภาษาที่เข้าใจง่าย จัดลำดับตามความเสี่ยงที่แท้จริง พร้อมแสดงหลักฐานที่สามารถพิสูจน์ซ้ำได้ (Reproducible Evidence) และเสนอแนะแนวทางแก้ไขที่ชัดเจนและนำไปปฏิบัติได้จริง

04 — Assure04 — รับรอง

Assureรับรอง

We re-test the fixes and, where you need it, provide the attestation your clients or regulators are asking for.เราดำเนินการทดสอบซ้ำหลังการแก้ไข (Re-test) และพร้อมออกหนังสือรับรองผลตามที่ลูกค้าหรือหน่วยงานกำกับดูแลของท่านต้องการ

Credentialsคุณสมบัติ

The person you brief is the person who does the work.ผู้ที่คุณร่วมปรึกษา คือผู้เชี่ยวชาญที่ลงมือปฏิบัติงานจริง

Melius Praxis is led by a practitioner certified across security, audit, and privacy, with a master's in information security from Royal Holloway, University of London — one of the field's longest-standing research centres.Melius Praxis นำโดยผู้เชี่ยวชาญที่ได้รับการรับรองด้านความมั่นคงปลอดภัย การตรวจสอบ และความเป็นส่วนตัวของข้อมูล พร้อมปริญญาโทด้าน Information Security จาก Royal Holloway, University of London ซึ่งเป็นหนึ่งในศูนย์วิจัยที่เก่าแก่ที่สุดของสาขานี้

CISSP — Security CISM — Security management CISA — Audit CDPSE — Data privacy MSc — Information Security, Royal Holloway
CISSP — ความมั่นคงปลอดภัย CISM — การบริหารความมั่นคงปลอดภัย CISA — การตรวจสอบ CDPSE — ความเป็นส่วนตัวของข้อมูล MSc — Information Security, Royal Holloway

Selected workผลงานที่เลือก

A security assessment and smart-contract review for a Thailand-based digital finance platform, ahead of a major release — surfacing access-control and contract-level issues in time to fix them before launch.การประเมินความมั่นคงปลอดภัยและการทบทวนสัญญาอัจฉริยะให้แพลตฟอร์มการเงินดิจิทัลในไทย ก่อนการเปิดตัวครั้งสำคัญ — ค้นพบปัญหาด้านการควบคุมสิทธิ์และในระดับสัญญาได้ทันเวลาแก้ไขก่อนเปิดตัว

Described in general terms · client named on request with consentอธิบายในลักษณะทั่วไป · เปิดเผยชื่อลูกค้าเมื่อได้รับความยินยอม

Aboutเกี่ยวกับ

Chagardpon Chimpongฉกาจพล ฉิมพงษ์

Founder and Authorized Directorผู้ก่อตั้งและกรรมการผู้มีอำนาจ

Melius Praxis is deliberately small — that's the point, not a limitation.Melius Praxis ตั้งใจดำเนินงานในรูปแบบองค์กรขนาดกะทัดรัด — ซึ่งถือเป็นจุดแข็งที่ช่วยให้เราคงมาตรฐานสูงสุดได้ ไม่ใช่ข้อจำกัด

Chagardpon Chimpong is a cybersecurity and IT-audit practitioner with sixteen years across Thailand's most heavily regulated industries — from banking and insurance to SEC-licensed digital-asset brokerages.ฉกาจพล ฉิมพงษ์ เป็นผู้เชี่ยวชาญด้านความมั่นคงปลอดภัยไซเบอร์และการตรวจสอบไอที ด้วยประสบการณ์ 16 ปีในอุตสาหกรรมที่มีการกำกับดูแลเข้มงวดที่สุดของไทย ตั้งแต่ธนาคารและประกันภัย ไปจนถึงผู้ประกอบธุรกิจสินทรัพย์ดิจิทัลที่ได้รับใบอนุญาตจากสำนักงาน ก.ล.ต.

He has led security as a chief technology officer, security architect, and operations and compliance manager — building institutional-grade security and custody frameworks, running security operations for platforms serving millions of users, and acting as the point of contact between engineering, the C-suite, and regulators including the Bank of Thailand, the SEC, and the AMLO. He holds the CISSP, CISM, CISA, and CDPSE, and an MSc in Information Security from Royal Holloway, University of London.ท่านเคยรับผิดชอบงานด้านความมั่นคงปลอดภัยในบทบาทประธานเจ้าหน้าที่บริหารฝ่ายเทคโนโลยี (CTO) สถาปนิกด้านความมั่นคงปลอดภัยไซเบอร์ และผู้จัดการฝ่ายปฏิบัติการและการกำกับการปฏิบัติตามกฎเกณฑ์ — มีผลงานโดดเด่นในการวางกรอบความมั่นคงปลอดภัยและการเก็บรักษาสินทรัพย์ระดับสถาบัน ดูแลการปฏิบัติการด้านความมั่นคงปลอดภัยให้แพลตฟอร์มที่มีผู้ใช้หลายล้านราย และเป็นผู้ประสานงานระหว่างทีมวิศวกร ผู้บริหารระดับสูง และหน่วยงานกำกับดูแล อาทิ ธนาคารแห่งประเทศไทย สำนักงาน ก.ล.ต. และสำนักงาน ปปง. ท่านถือใบรับรอง CISSP, CISM, CISA และ CDPSE และสำเร็จการศึกษาระดับปริญญาโทสาขา Information Security จาก Royal Holloway, University of London

Whether the work is a security assessment, a controls audit, or a smart-contract review, the person you brief is the person who does it and signs the report.ไม่ว่างานจะเป็นการประเมินความมั่นคงปลอดภัย การตรวจสอบการควบคุม หรือการตรวจสอบสัญญาอัจฉริยะ ผู้ที่คุณติดต่อคือผู้ที่ลงมือทำและลงนามในรายงานด้วยตนเอง

Contactติดต่อ

Tell us what you need to protect, audit, or prove.บอกเราว่าคุณต้องการปกป้อง ตรวจสอบ หรือรับรองสิ่งใด

Send a short note about the work and the timeline. You'll hear back from the person who would actually do it — including an honest view on whether we're the right fit.ส่งข้อความสั้น ๆ เกี่ยวกับงานและกรอบเวลา คุณจะได้รับการตอบกลับจากผู้ที่ลงมือทำงานจริง พร้อมความเห็นตรงไปตรงมาว่าเราเหมาะกับงานของคุณหรือไม่

+66 81 695 0101
5 Soi Suan Siam 3 Yek 3, Ram-Intra Road, Kannayao, Kannayao, Bangkok 10230, Thailand5 ซอยสวนสยาม 3 แยก 3 ถนนรามอินทรา แขวงคันนายาว เขตคันนายาว กรุงเทพมหานคร 10230