FAQ

Questions we get asked.

Straight answers. No sales language. If your question is not here, contact us directly.

How long does an assessment take?+

Small scope engagements run 2–4 days. Standard API assessments run 4–7 days. Larger platform reviews and architecture engagements run 1–2 weeks. Final duration is agreed after a technical discussion.

What happens after disclosure?+

We provide reproduction, impact analysis, and mitigation guidance. Remediation happens in your codebase with your engineers; we retest and issue a final validation once the fix is deployed.

Can we start with one endpoint?+

Yes. Single-endpoint reviews are common, often as a first engagement before wider scoping.

Do you sign NDAs?+

Yes. NDAs are standard for every engagement and are executed before scoping specifics are exchanged.

How are reports delivered?+

Reports are delivered as Markdown, PDF, or directly into your issue tracker, whichever your engineering team prefers.

Do you retest fixes?+

Retesting and final validation are included in every engagement. Closure is a milestone, not a handoff.

Can you work alongside developers?+

Yes. We routinely work in shared channels with engineering teams and review PRs before they ship.

Do you take on continuous partnerships?+

Yes. We work with a small number of clients as an ongoing security partner, reviewing architecture, PRs, and pre-launch changes.

Establish Secure Comms

Request an audit.
Disclose a finding.

Private handling. No data accessed, modified, or retained beyond what is necessary to demonstrate the issue. Most messages are acknowledged within a few hours on business days.

Cookies

We use a minimal set of cookies to keep this site functional. Analytics cookies only with your consent. Cookie Policy.