FAQ
Questions we get before every engagement.
If your question isn't answered here, email us — we reply to every legitimate inquiry within one business day.
- Do you perform unauthorised testing?
- No. Every engagement begins with a signed Rules of Engagement document that names the assets, windows, and contacts. We do not touch anything you do not own or explicitly authorise.
- How is a VIROXEN audit different from a scanner report?
- Automated tooling is a starting point, not the deliverable. Every finding in a VIROXEN report is manually verified with reproduction steps, evidence, and a CVSS score adjusted for your environment.
- What standards do you align with?
- OWASP Top 10, OWASP ASVS Level 2, and CVSS 3.1 for scoring. Where relevant we also reference NIST SP 800-115 for testing methodology.
- Will testing affect our production systems?
- By default we test against staging environments that mirror production. When production testing is required we agree on windows, rate limits, and a rollback contact before any traffic is generated.
- How are findings delivered?
- You receive an executive summary and a full technical report in PDF, plus a walkthrough call on request. Findings can also be delivered as ticket-ready entries mapped to owners.
- Do you offer retests?
- Yes. Professional and higher plans include one free retest of remediated findings. Additional retests can be added at any time.
- Can you sign an NDA?
- Yes — mutual NDAs are standard. We also support customer paperwork on request.
- Which payment methods do you accept?
- We invoice in INR or USD. Bank transfer, UPI, and card payment via invoice link are all supported.
Still have a question?
Email contact@mespark.in or head to the contact page.