FAQ
Questions, answered
How engagements work, what you get, and how we handle your data.
How does an engagement start?
You tell us what you need — through the contact form today, or the intake assistant once it launches. We review the request, ask any clarifying questions, and come back with a scoped proposal and quote. Work starts only after you approve the scope.
What does a penetration test include?
A scoped, rules-of-engagement-bound assessment of the systems you authorize, following OWASP-aligned methodology. You receive a report with severity-rated findings, reproduction steps, an executive summary, and concrete remediation guidance — followed by a debrief call.
Do you sign NDAs?
Yes. Confidentiality is standard in this line of work. We're happy to sign your NDA before any technical details change hands, or provide our mutual NDA if you prefer.
Do you retest after we fix the findings?
Yes — retesting of remediated findings is included in vulnerability analysis and pentest engagements, so you get confirmation that fixes actually close the gap.
Can you help with compliance (ISO 27001, SOC 2, GDPR)?
We align our assessments and reports with the frameworks you care about, so the output is directly usable as audit evidence. We are a technical partner, not a certification body — we prepare you for audits rather than issue certificates.
Do you work with startups, or only larger companies?
Both. Engagements are scoped to fit — a focused assessment for an early-stage product is just as valid a project as a broad audit for an established platform.
How will I follow progress during a project?
Every client gets access to our portal (launching soon), where you can track project phase, milestones, findings, and deliverables in real time. Until then, you'll get regular updates directly from your engagement lead.
Something we didn't cover?