Home / FAQ

Frequently asked questions

Everything clients ask us about scoping, testing, reporting and payment. If your question isn't here, contact us and a real engineer will answer it.

What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment identifies and catalogues weaknesses across your systems, usually with heavy use of automated tooling. A penetration test goes further: our testers actively exploit those weaknesses by hand to prove what an attacker could really achieve. Most clients start with an assessment for breadth, then a penetration test for depth on critical systems.
How long does a typical engagement take?
Scoping takes one to two days. A focused external network or web application test usually runs three to five working days, with the report delivered within a week of testing finishing. Larger environments take longer — we give you a firm timeline before any work begins.
Will testing disrupt our live systems?
We agree rules of engagement with you before starting, including testing windows, out-of-scope systems and escalation contacts. Destructive techniques are never used without explicit written approval, and we can test against staging environments where production risk is a concern.
What do we actually receive at the end?
A prioritised findings report: every issue with a reproducible proof of concept, a CVSS score, the business impact in plain language, and a specific remediation step. You also get an executive summary suitable for your board or clients.
Is the retest really free?
Yes. Once your team has shipped the patches, we retest the original findings at no extra cost and issue an updated report confirming what has been closed. This is included in every engagement.
Do you sign NDAs?
Always. We sign your NDA before scoping begins, and all findings, data and evidence are handled under strict confidentiality and deleted according to an agreed retention schedule.
We think we have already been breached. What now?
Contact us immediately through the contact page and mark it as an emergency. Our response team is available 24/7 to contain the attacker, close the entry point and restore your services.
Which countries do you operate in?
We have entities and teams across India, the United States and the United Kingdom, and we work with clients remotely worldwide.
Do you work with small businesses, or only enterprises?
Both. Engagements are scoped to the size of your environment, so a small SaaS product with a handful of endpoints costs considerably less than a multi-region enterprise network.
Still unsure?

Talk to an engineer, not a salesperson

Send us your question and someone who actually runs the tests will reply — usually within one business day.

Contact us