FAQ
How engagements work
Short answer
Engagements are scoped in a short call, fixed in price before work starts, and delivered by one named consultant. You provide test accounts, environment details and a signed authorisation. You receive findings as they are confirmed, a report, a remediation call and a free retest within 30 days.
Frequently asked questions
Who am I actually hiring?
One named consultant, not a bench. Abin Antony performs the testing, writes the report and runs the remediation call. Nothing is subcontracted, and you always know who did the work.
How quickly can an engagement start?
Scoping usually happens within two working days of first contact, and testing typically starts within one to three weeks depending on the queue. Urgent pre-launch work can sometimes be accommodated sooner — ask.
What do you need from us to begin?
A signed authorisation letter, test accounts for every user role, environment details, and a technical contact reachable during the test window. For mobile work, a signed build. For cloud work, a read-only role you create and revoke.
Do you sign NDAs?
Yes, before any technical detail is exchanged. Your NDA is preferred; a standard mutual one is available if you would rather not draft it.
How is pricing structured?
Fixed price per engagement, agreed after scoping, with the number of testing days stated in the proposal. No hourly billing surprises, and the retest is included rather than quoted separately.
Is the retest really free?
Yes — every finding is retested once, within 30 days of the report, at no additional cost. The reissued report showing closed findings is the version you hand to customers and auditors.
Can you work with our compliance framework?
Findings can be mapped to SOC 2, ISO 27001, PCI DSS or an enterprise customer's questionnaire. Say which one at scoping and the mapping ships with the report. Certification itself requires an accredited auditor — this is the engineering half.
Do you test production systems?
Where necessary, under written rules of engagement: no denial-of-service testing, no bulk data extraction, agreed request rates and a monitored contact channel. Staging that mirrors production is always preferred.
What happens if you find something critical mid-test?
You hear about it the same day, through the channel agreed at kickoff, with enough detail to start mitigating immediately. Critical findings are never held back for the report.
Do you work with clients outside India?
Yes. Remote engagements run across the Gulf, Europe, Singapore and Australia. Indian Standard Time overlaps comfortably with Gulf, European and South-East Asian working hours.
How do you handle our data?
Evidence is minimised, stored encrypted, and destroyed 90 days after the engagement closes unless you ask otherwise. No production data is exported beyond the minimum needed to prove a finding.
What if we disagree with a finding?
Say so, with reasoning. Severity ratings are a judgement call about your business context, and context you hold can change them. Disputed findings stay in the report with both positions documented — that is more honest than quiet deletion.
Want this tested properly?
Scope and a fixed quote within two working days. First consultation is free.