Alphasall

FAQ

English version coming soon — showing the French content.

Do you keep my data and the engagement's content confidential?
Yes. Every engagement is covered by a signed non-disclosure agreement (NDA) before it starts. Data you share and the engagement's results (reports, technical evidence, correspondence) are handled in strict confidence, with access limited to the people directly involved.
What's the difference between a penetration test and an audit?
A penetration test (pentest) simulates a real attack on a defined scope — through manual exploitation aligned with the OWASP Top 10 — to verify what an attacker could actually compromise. A security audit is a broader assessment of your security and compliance posture against reference frameworks (OWASP, industry best practices), based on documentation review and interviews, resulting in a prioritized remediation roadmap. The two are complementary: the audit gives you the overall picture, the pentest validates real-world resistance on a targeted scope.
How does an engagement unfold?
Every engagement broadly follows the same flow: an initial scoping phase to define the scope and rules of engagement, an analysis phase (reconnaissance and mapping for a pentest, documentation review and interviews for an audit), the engagement itself, then a debrief — a detailed technical report, a non-technical executive summary, and a live session to prioritize next steps.
What geographic area do you work in?
France only for now. Expansion into Europe and West Africa is planned — feel free to reach out even outside this area to discuss it.
What languages do you work in?
French and English, both written and spoken — deliverables, correspondence, and debriefs are available in either language.