FAQ
English version coming soon — showing the French content.
- Do you keep my data and the engagement's content confidential?
- Yes. Every engagement is covered by a signed non-disclosure agreement (NDA) before it starts. Data you share and the engagement's results (reports, technical evidence, correspondence) are handled in strict confidence, with access limited to the people directly involved.
- What's the difference between a penetration test and an audit?
- A penetration test (pentest) simulates a real attack on a defined scope — through manual exploitation aligned with the OWASP Top 10 — to verify what an attacker could actually compromise. A security audit is a broader assessment of your security and compliance posture against reference frameworks (OWASP, industry best practices), based on documentation review and interviews, resulting in a prioritized remediation roadmap. The two are complementary: the audit gives you the overall picture, the pentest validates real-world resistance on a targeted scope.
- How does an engagement unfold?
- Every engagement broadly follows the same flow: an initial scoping phase to define the scope and rules of engagement, an analysis phase (reconnaissance and mapping for a pentest, documentation review and interviews for an audit), the engagement itself, then a debrief — a detailed technical report, a non-technical executive summary, and a live session to prioritize next steps.
- What geographic area do you work in?
- France only for now. Expansion into Europe and West Africa is planned — feel free to reach out even outside this area to discuss it.
- What languages do you work in?
- French and English, both written and spoken — deliverables, correspondence, and debriefs are available in either language.