Frequently Asked Questions
Everything you need to know about engaging Kryvasis.
Every engagement begins with a scoping call under NDA. We map your requirements, define the statement of work, agree on timeline and commercial terms, and begin with threat modelling specific to your environment. All findings are delivered with a prioritised remediation roadmap.
Yes. All consultations, audits, and communications are covered by a mutual Non-Disclosure Agreement before any work begins. We never disclose client identities or engagement details without explicit written permission.
Kryvasis serves financial institutions, telecommunication providers, critical infrastructure operators, legal and advisory firms, and technology companies. We operate exclusively by private mandate.
A standard security audit engagement runs 2–6 weeks depending on scope. Threat modelling and surface mapping typically take 1 week, exploitation and testing 1–3 weeks, and reporting with remediation roadmap 1 week.
For retainer clients, we offer defined SLAs for incident response, patch development, and advisory turnaround. Ad-hoc engagements are delivered per the statement of work agreed during scoping. Contact us for specific SLA terms.
We assess against ISO 27001, SOC 2, PCI DSS, NIST CSF, NIS2, EU CRA, and OWASP ASVS. Assessments are tailored to your regulatory environment and industry.
Yes. We regularly engineer custom patches for legacy systems where vendors have ceased support. Our team has experience with proprietary firmware, embedded systems, and mainframe environments.
Pricing is project-based or retainer-based, depending on the engagement type. We do not publish rate cards. Contact us via the booking form for a scoping call and we will provide a tailored proposal.