Hoxy
ServicesOfferingsProjectsToolsAbout
faConsultation
Hoxy

Hoxy Platform — precise cybersecurity for growing organizations.

Unit 1204, 12th Floor, Aseman Tower, Valiasr St., above Saei Park, Tehran, Iran

Product

ServicesOfferingsToolsDownloads

Company

AboutProjectsFAQContact

Legal

PrivacyTermsConfidentialitySLA

Phone: 021-9109-4580

Email: info@hoxy.ir

© 2026 Hoxy. All rights reserved by Hoxy.

hoxy.ir

FAQ

How long does a penetration test take?

Depending on scope, typically 5–15 business days plus reporting time.

Do you test production environments?

Yes, with agreed rules of engagement and a defined window; otherwise staging is preferred.

What are the deliverables?

Executive report, technical report, remediation priorities, and optional readout/retest.

What should we do for critical incidents?

Use the incident form or emergency channel. Isolate suspicious systems until the team arrives.

Do you sign NDAs?

Yes. Confidentiality agreements are completed before receiving sensitive data and starting assessment.

Are services delivered remotely?

Most services are delivered over secure remote access; on-site engagement is available for OT or sensitive cases.

What is the initial response time for consultation requests?

Typically under one business day during working hours; critical incidents have 24/7 coverage.

Do you offer retesting after remediation?

Yes. Retesting agreed findings is part of our standard packages.

How is project scope defined?

In a discovery call we document assets, constraints, objectives, and success criteria.

Do you offer lighter packages for startups?

Yes. Focused product and cloud risk assessments are available with phased budgets.

How does your pricing model work?

Based on asset scope, assessment depth, and duration—typically fixed-project pricing or monthly packages for SOC/advisory. After discovery we send a clear proposal with assumptions.

In what language are reports delivered?

By default Persian and English; executive summaries for leadership and technical detail for engineering can be provided in both languages.

Do you test OT/industrial environments?

Yes—under strict safety constraints, maintenance windows, and a preference for non-disruptive assessment unless explicitly agreed otherwise.

What does a typical cloud scope include?

Accounts/subscriptions/projects, IAM, networking, storage, logging, and agreed workloads across AWS, Azure, or GCP.

How long is the retest window?

In standard packages typically 30–45 days after report delivery for agreed findings; extensions are available by separate agreement.

How do you handle customer data?

We collect the minimum necessary data, transfer it over secure channels, retain it for a defined period, and delete or return it after the engagement per agreement.

Do team members have clearances or internal access controls?

Need-to-know access, project isolation, and access logging apply; for sensitive projects named individuals are introduced in advance.

What are SLAs for ongoing services?

Contract-dependent: critical-incident initial response typically under one hour, high-priority items within agreed business-hour tables, and monthly metrics reporting.

Do you issue certificates or attestation letters for completed tests?

On request we issue a brief scope-and-date attestation for partners or risk committees; it is not a substitute for a formal audit.

What happens if disruption occurs during a penetration test?

Per the RoE, testing is paused or limited, your point of contact is notified immediately, and work resumes only after approval.