FAQ

Every question, answered in writing.

What buyers, security teams and legal ask before they commit — the hunt, the price, code access, and where your data lives. Every answer ends with the next step.

The hunt

Who actually does the test?

You get a human-verified PoC on every finding and a signed report. The researcher is named in the contract and reachable during the test and at the readout. Right now that is Samir Abis.

Trust
How is this different from a bug bounty?

Fixed scope, fixed price, report guaranteed. A bounty gives you no coverage and no timeline, and you only pay when someone finds something. You need that report for SOC 2 anyway.

See the pricing
Does this replace a scanner?

It complements one. A scanner lists what might be there, and you verify every flag yourself. We prove what an attacker can actually do — working PoC, named researcher, signed NIS2 / ISO report a scanner cannot produce. The scanner keeps its job.

Start the free check
What happens if you find a critical?

We pause the affected path. You hear about it within 4 hours on the agreed channel. Nothing destructive happens without written sign-off.

Sample report

Pricing

What does it cost?

From €9,900/year for one surface, every release, billed annually — monthly also available. Both in writing before we start. No per-scan billing, ever.

Start the free check
What if I only need a one-off report?

The deep audit runs once, from €3,500, with one retest included — for NIS2, SOC 2, or the board.

Sample report
What moves the price?

Additional app or API surface, mobile or cloud scope, and code-assisted scope (+€1,500 audit / +€5,000/year). Every increment is flat, and every number comes in writing.

Contact
What is included?

Onboarding, scoping, the report, and NIS2 / ISO 27001 evidence mapping — all included. No metered hours, no surprise line items.

Trust
What does "No High, no pay" mean exactly?

You pay the flat fee upfront. No validated High or Critical in the signed report for the agreed scope: you get the money back — 100 %, within 14 days of delivery. The full terms are in the contract.

The guarantee

Code access

Can you also look at our source code?

Yes. Give us repo access; the agent reads every release's diff for data-flow issues, missing auth checks, and framework-specific misconfigs. Findings come with file:line references and a working PoC. You ship, the code is read, the logic is retested. Flat add-on, in writing.

Contact

Data & trust

Where does our data live?

In the EU only. Sub-processors: Google Cloud (EU region) and PostHog Cloud EU (Frankfurt), used only after your consent. Encrypted in transit and at rest, least-privilege access, append-only logging.

Privacy
How does GDPR work here?

You are the controller, we are the processor — under a DPA (Art. 28 GDPR). A data-protection incident is reported to you within 24 hours.

DPA (Art. 28)
What happens to the findings and the report?

The report is signed — advanced electronic signature (eIDAS, PAdES-B-T) plus a qualified timestamp — and kept for 10 years. It is yours.

Sample report
Who is accountable, and what if something goes wrong?

The named researcher signs every report. Insurance: €50M per claim, without deductible (AGB §14). Before anything runs, your written authorization with rules of engagement is in force for 90 days.

Trust

Something not answered here?

Ask it directly — a named person answers, in writing, the same day.