What do you need from our team?
A short product description, proposed assets and workflows, relevant account roles, available test environment and target timeline. We then agree on access and authorization. Do not send credentials in an initial inquiry.
Can you assess production?
Only where explicitly authorized and appropriate for the agreed checks. Environment, permitted actions, operational limits and escalation arrangements are discussed before testing.
How is sensitive data handled?
We define permitted test data, access boundaries and evidence-handling requirements before the engagement. If you need specific retention, deletion, residency or contractual commitments, share those requirements so we can confirm whether we can meet them.
What determines price and timing?
Asset and workflow scope, available roles and access, environment complexity, reporting needs and follow-up requirements. We confirm a proposal after scoping; this page does not promise a fixed turnaround or price.
How do we stay in touch during testing?
We agree on technical contacts, communication channels and escalation arrangements at kickoff. Tell us about time-sensitive concerns so the engagement can be scoped appropriately.
Will you verify our fixes?
Retesting can be agreed as part of the engagement. The scope, timing and terms should be explicit; a retest result applies to the tested fix and conditions, not to the entire application.
Is this a compliance certification?
No. An assessment is bounded by scope, access and time; it does not certify compliance or guarantee an absence of vulnerabilities. Share any buyer-specific assessor or report requirements before engaging us.