Skip to content

FAQ

Frequently asked questions

The questions we get asked most often. If yours is not here, ask us directly - we answer technical questions whether or not there is a project attached.

How do engagements usually start?

With a free 30-minute call with a senior engineer - not a salesperson. We look at your current delivery path, ask about what breaks and how often, and tell you what we would prioritise. If it turns into a project, we follow up with a scoped proposal. If it does not, you still leave with a view of where your risk sits.

Do you work with clients outside India?

Yes. Most of our work is with teams in North America and Europe, including Bonnier Media, SimplerMedia Group and Eazybot. We overlap with US and European business hours and run engagements entirely remotely, with regular written updates rather than status meetings.

Which cloud providers do you work with?

Primarily AWS, Azure and Google Cloud, including hybrid and multi-cloud architectures spanning several of them. We have delivered production workloads on EKS and AKS under unified tooling. For smaller or self-managed setups we also work with DigitalOcean and Linode, and we handle on-premise to cloud migrations where the starting point is a data centre.

Do we have to take the whole set of services?

No, and most clients do not. Engagements usually start with one thing - a migration, a cost review, a pipeline rebuild - and expand only if it makes sense. We scope to the problem in front of you rather than selling a bundle you grow into.

Can you work with our existing DevOps team?

That is the most common arrangement. We embed alongside your engineers rather than replacing them, and a deliberate part of every engagement is transferring what we build - documentation, runbooks, and pairing - so your team owns it once we step back.

Why do you need read-only access to our AWS account, and how do we revoke it?

Because an audit that cannot read your configuration is a questionnaire. You deploy a CloudFormation stack that creates a cross-account IAM role carrying two AWS-managed policies, SecurityAudit and ViewOnlyAccess, guarded by an external ID unique to you. No credential ever changes hands. Every call we make appears in your own CloudTrail, attributed to the role you created, so you can audit what we read without taking our word for it. Deleting the stack ends our access that second - there is nothing to offboard and nobody to email. The full breakdown is on our trust page.

Is granting a third party access to our cloud account normal?

It is the standard mechanism. Vanta, Drata and Comp AI all connect to AWS the same way, with a cross-account role and an external ID, because AWS designed it as the alternative to sharing keys. If your team has onboarded any compliance platform, this is a decision they have already made. Where we differ is duration: those tools monitor continuously and keep their access indefinitely, whereas ours runs when you ask it to. Most people delete the stack once the audit is done, which is a supported way to use it rather than a workaround.

How do you handle compliance requirements like HIPAA or SOC 2?

We design for the framework from the start rather than retrofitting. That means encryption at rest and in transit, centralised audit logging, access governance, and evidence generated automatically by the pipeline. We delivered a fully certified, audit-ready HIPAA telemedicine platform in three months.

What does a penetration test include?

Adversary-emulation testing scoped against MITRE ATT&CK across web applications, APIs, networks and cloud environments. Every finding ships with a working proof of concept and CWE or CVE mapping - nothing is reported as merely "potentially vulnerable". A retest after you remediate is included.

How long does a typical engagement take?

A cost optimisation review or penetration test is usually two to four weeks. A CI/CD or infrastructure-as-code project runs six to twelve weeks. Full cloud migrations depend heavily on what you are moving, but we work in waves so value lands well before the final cutover.

Do you offer ongoing support after a project ends?

Yes. Many clients continue with a retainer covering monitoring, incident response, periodic reassessment and advisory time. Others take full ownership after handover. Both are fine - we build so that either is possible.

Still have a question?

Send it over. A senior engineer will reply within one business day.