Depending on scope, typically 5–15 business days plus reporting time.
Yes, with agreed rules of engagement and a defined window; otherwise staging is preferred.
Executive report, technical report, remediation priorities, and optional readout/retest.
Use the incident form or emergency channel. Isolate suspicious systems until the team arrives.
Yes. Confidentiality agreements are completed before receiving sensitive data and starting assessment.
Most services are delivered over secure remote access; on-site engagement is available for OT or sensitive cases.
Typically under one business day during working hours; critical incidents have 24/7 coverage.
Yes. Retesting agreed findings is part of our standard packages.
In a discovery call we document assets, constraints, objectives, and success criteria.
Yes. Focused product and cloud risk assessments are available with phased budgets.
Based on asset scope, assessment depth, and duration—typically fixed-project pricing or monthly packages for SOC/advisory. After discovery we send a clear proposal with assumptions.
By default Persian and English; executive summaries for leadership and technical detail for engineering can be provided in both languages.
Yes—under strict safety constraints, maintenance windows, and a preference for non-disruptive assessment unless explicitly agreed otherwise.
Accounts/subscriptions/projects, IAM, networking, storage, logging, and agreed workloads across AWS, Azure, or GCP.
In standard packages typically 30–45 days after report delivery for agreed findings; extensions are available by separate agreement.
We collect the minimum necessary data, transfer it over secure channels, retain it for a defined period, and delete or return it after the engagement per agreement.
Need-to-know access, project isolation, and access logging apply; for sensitive projects named individuals are introduced in advance.
Contract-dependent: critical-incident initial response typically under one hour, high-priority items within agreed business-hour tables, and monthly metrics reporting.
On request we issue a brief scope-and-date attestation for partners or risk committees; it is not a substitute for a formal audit.
Per the RoE, testing is paused or limited, your point of contact is notified immediately, and work resumes only after approval.