Questions we get asked.
Straight answers. No sales language. If your question is not here, contact us directly.
▊How long does an assessment take?+
Small scope engagements run 2–4 days. Standard API assessments run 4–7 days. Larger platform reviews and architecture engagements run 1–2 weeks. Final duration is agreed after a technical discussion.
▊What happens after disclosure?+
We provide reproduction, impact analysis, and mitigation guidance. Remediation happens in your codebase with your engineers; we retest and issue a final validation once the fix is deployed.
▊Can we start with one endpoint?+
Yes. Single-endpoint reviews are common, often as a first engagement before wider scoping.
▊Do you sign NDAs?+
Yes. NDAs are standard for every engagement and are executed before scoping specifics are exchanged.
▊How are reports delivered?+
Reports are delivered as Markdown, PDF, or directly into your issue tracker, whichever your engineering team prefers.
▊Do you retest fixes?+
Retesting and final validation are included in every engagement. Closure is a milestone, not a handoff.
▊Can you work alongside developers?+
Yes. We routinely work in shared channels with engineering teams and review PRs before they ship.
▊Do you take on continuous partnerships?+
Yes. We work with a small number of clients as an ongoing security partner, reviewing architecture, PRs, and pre-launch changes.
Request an audit.
Disclose a finding.
Private handling. No data accessed, modified, or retained beyond what is necessary to demonstrate the issue. Most messages are acknowledged within a few hours on business days.