FAQ
Frequently asked questions.
The questions we get most often from procurement, engineering, and security teams. Not finding what you need? Ask directly.
How long does a typical engagement take?
A fixed-scope web application or API pentest is usually 1–3 weeks. A smart contract audit runs 2–4 weeks depending on complexity. Continuous retainers start at 3 months. We scope every engagement individually so the timeline reflects your actual surface.
How is pricing determined?
$6k–$35k for web / API assessments (API starts at $7k). $12k–$75k for smart contract audits, scaled by logic density and complexity. $9k–$40k for source code review. Fixed against your scope, not a day rate — you see the ceiling before you sign. Continuous retainer from $18k/month. Custom scope is priced after a 30-minute call.
Why publish prices when most firms do not?
Most top-tier firms (Trail of Bits, Halborn, Doyensec, Cure53, OpenZeppelin) keep pricing behind a “Get a quote” form. We publish ours because a fixed range up front filters for the engagements that actually fit our model — and saves both sides a week of back-and-forth. If the final scope needs a custom number, we quote it after a 30-minute call. Either way, you see the ceiling before you sign.
Do you sign NDAs?
Yes — every engagement starts with a mutual NDA. We are comfortable signing your paper or providing ours. Rules of engagement are also signed before any testing begins.
What platforms and languages do you cover?
Web apps, REST / GraphQL / WebSocket APIs, Solidity (EVM), Move (Sui / Aptos), Rust / Anchor (Solana), and general source review in Node.js, Python, Go, and Rust. If your stack is outside this, tell us — we will say so if it is not a fit.
Is a retest included?
Yes. One retest is included in every fixed-scope engagement, within 30 days of report delivery. The retest produces an artifact attached to the original report confirming which findings are closed.
Do you deliver remote or on-site?
Remote by default, which keeps costs down and lets us move fast. On-site kickoff or debrief sessions available on request.
What does the report look like?
Executive summary for leadership (business impact, severity distribution, overall risk posture) plus technical section per finding: description, root cause, reproducible PoC, CVSS 3.1 score, and concrete remediation. A sample report is available on request.
Can you work under SOC 2 / ISO 27001 / PCI DSS requirements?
Yes. We have delivered engagements that became evidence for SOC 2 Type II vulnerability management and ISO 27001 Annex A.12 controls. Happy to structure the report to match your auditor’s requirements.
Do you handle responsible disclosure for us?
Yes. Findings go through coordinated disclosure with you first. Public disclosure — if any — only happens after fixes land and with your explicit approval. We never disclose unilaterally.
How do you handle data and credentials?
Credentials provisioned just-in-time, stored in password managers with limited access, and destroyed at engagement close. Reports delivered encrypted (PGP or through your secure channel). Any collected evidence is wiped within 30 days of close unless you request retention.
Can you start immediately?
Lead time is usually 1–3 weeks for a new engagement — depending on current capacity. For true emergencies (active exploitation, pre-funding audit) we try to accommodate; reach out and we will tell you honestly.
What if you don't find anything critical?
Then we write that down and you get defensible evidence for your next audit. We will not pad severity to justify the invoice.
Do you offer bug bounty triage?
Yes, as part of a continuous retainer. We help you triage incoming submissions, deduplicate, validate PoCs, and write responses.
Can I see a sample report?
Yes — a redacted sample is available to qualified prospects under NDA. Request it via the contact form.
Question not answered?
Ask directly — we reply within one business day.