FAQ

Questions we get before every engagement.

If your question isn't answered here, email us — we reply to every legitimate inquiry within one business day.

Do you perform unauthorised testing?
No. Every engagement begins with a signed Rules of Engagement document that names the assets, windows, and contacts. We do not touch anything you do not own or explicitly authorise.
How is a VIROXEN audit different from a scanner report?
Automated tooling is a starting point, not the deliverable. Every finding in a VIROXEN report is manually verified with reproduction steps, evidence, and a CVSS score adjusted for your environment.
What standards do you align with?
OWASP Top 10, OWASP ASVS Level 2, and CVSS 3.1 for scoring. Where relevant we also reference NIST SP 800-115 for testing methodology.
Will testing affect our production systems?
By default we test against staging environments that mirror production. When production testing is required we agree on windows, rate limits, and a rollback contact before any traffic is generated.
How are findings delivered?
You receive an executive summary and a full technical report in PDF, plus a walkthrough call on request. Findings can also be delivered as ticket-ready entries mapped to owners.
Do you offer retests?
Yes. Professional and higher plans include one free retest of remediated findings. Additional retests can be added at any time.
Can you sign an NDA?
Yes — mutual NDAs are standard. We also support customer paperwork on request.
Which payment methods do you accept?
We invoice in INR or USD. Bank transfer, UPI, and card payment via invoice link are all supported.

Still have a question?

Email contact@mespark.in or head to the contact page.