FAQ

Questions, answered plainly

These are the questions we hear most often from security leads, engineering managers, and procurement teams. The answers below are the same ones we give on a call. If yours is not covered, write to us and a practitioner will reply within one business day.

Engagements

Scoping, models, and timelines

How do we start an engagement?

Write to sales@planckdefense.com or use the form on our contact page. We reply within one business day, execute a mutual NDA, and then hold a short scoping call to understand your targets, objectives, and constraints. Within a few days of that call you receive a fixed proposal covering methodology, team composition, timeline, and price. Once you approve it, we agree on dates and lock the team.

Do you sign an NDA before scoping?

Yes, always. Scoping requires architecture detail, URLs, and sometimes documentation you would not share with an outside party otherwise, so a mutual NDA comes before any of it changes hands. We have a standard template ready, and we are equally comfortable signing yours if it covers mutual obligations.

How are scope and price set?

Scope is defined by what needs testing and to what depth: the number of applications and user roles, API operations, hosts and network segments, cloud accounts, and the objectives you care about. Price follows from the effort a proper assessment of that scope requires, quoted as a fixed fee for the engagement. There is no hourly meter and no surprise overrun.

If testing reveals that the environment is materially larger than described, we tell you and agree on next steps before expanding anything. We would rather resize a scope openly than deliver shallow coverage quietly.

What is the difference between black box, gray box, and white box testing?

The difference is how much knowledge and access we start with. Black box begins from an outside position with no credentials, which models an opportunistic external attacker but spends a share of the schedule on discovery. Gray box adds test accounts and documentation, so more of each day goes into depth rather than reconnaissance; it is the model we recommend for most application and API work. White box adds source code or configuration access and delivers the highest assurance per hour of testing, since we can trace a suspicious behavior straight to its cause. The right choice depends on the question you want answered, and we help you pick during scoping.

How long does an engagement take?

A single web application, API, or external network assessment typically runs one to three weeks of active testing, depending on size and depth. Internal network work, cloud reviews, and multi-asset scopes run longer, and red team operations are measured in weeks rather than days by design. Your proposal states the exact schedule, and the report follows within five business days of the last test day.

Do you test production or staging?

Either, and we decide together during scoping. Production gives the truest picture of what an attacker faces, and we test it carefully: no destructive payloads, agreed testing windows, rate limits respected, and an emergency contact on both sides. Staging is the right place for intrusive test cases and load-sensitive components, provided it mirrors production configuration closely. Many clients split the difference, running intrusive cases against staging and verifying a subset of findings in production.

Deliverables & Support

What you receive and what happens after

What is in the report?

An executive summary written in plain language for leadership, followed by technical findings. Each finding includes a description, the affected assets, step-by-step reproduction instructions, supporting evidence such as request and response data or screenshots, a CVSS v3.1 rating, and remediation guidance aimed at the team that will implement the fix. The report closes with a methodology and coverage appendix, so you know exactly what was tested and what was not. Every report is followed by a live debrief call with the testers.

Do you use CVSS?

Yes. Every finding carries a CVSS v3.1 vector and score. We also add a short written justification for each rating, because a vector string on its own can mislead: a technically severe issue behind three layers of authentication is a different problem from the same issue on an unauthenticated endpoint. The score gives you a common language for tracking; the justification gives you the context to prioritize honestly.

Is a retest included?

It is. Every assessment includes one retest of fixed findings at no additional cost. When your team has remediated, we verify each fix against the original reproduction path, check that the change did not introduce an obvious regression nearby, and issue an updated report marking each finding as resolved or still open. Retests are typically scheduled within an agreed window after report delivery.

Do you help engineering fix the issues?

Yes, within the bounds of an assessment. Remediation guidance in the report is written for implementers, not auditors, and the debrief call is a working session where your engineers can ask the testers anything. During the remediation window the engagement team remains reachable for follow-up questions about specific findings. If you want deeper involvement, such as reviewing a proposed redesign, we can scope advisory time separately.

Who sees the report and how is it delivered?

Only the recipients you designate. Reports are delivered over an encrypted channel agreed at kickoff, typically PGP-encrypted mail or a secure transfer link, never as a plain email attachment. Inside our firm, access is restricted to the engagement team, and engagement material is retained and destroyed on the schedule set in your agreement. Our Trust & Data Handling page describes the full lifecycle.

Threat Intelligence

Monitoring built around your organization

How is this different from a threat feed?

A feed sends you indicators; we send you judgments. Monitoring is configured around your organization specifically: your domains, brands, executives, infrastructure, and suppliers. Human analysts triage everything before it reaches you, so every alert has been verified as relevant, ranked by severity, and paired with recommended actions. You also get a named analyst who knows your environment, not a ticket queue.

What do you need from us to start?

A modest starter set: your domains, brand and product names, the public roles of executives you want covered, external IP ranges, and the third parties whose compromise would hurt you. We hold an onboarding call to tune priorities, deliver a baseline report of your current exposure, and then move into continuous monitoring. Most organizations are fully onboarded within days, not weeks.

How fast will we hear about a leaked credential?

Credential exposures that appear valid for your systems, including those recovered from infostealer logs, are escalated as soon as an analyst validates them, with 24/7 handling for critical alerts. The alert tells you which account, which source, and what to do first. Lower-severity material, such as stale or already-rotated credentials, is grouped into your periodic summary rather than paged out at night.

Can you take down a phishing domain?

Yes, takedown support is part of the service. We collect evidence, file with the registrar, hosting provider, and relevant blocklist operators, and track the case through to removal. Because takedown timelines depend partly on how responsive those parties are, we also give you immediate mitigations while the process runs: indicators to block, mail rules to apply, and wording to warn staff or customers if the campaign is active.

Dedicated IP VPN

Your addresses, your gateways

What makes the IP dedicated?

The addresses are allocated to your organization and to no one else. No other customer's traffic ever egresses from them, so their reputation is entirely under your control and you can allowlist them with confidence in SaaS admin panels, firewalls, and partner systems. The gateways behind them are single-tenant as well: your organization runs on its own instances, not on shared infrastructure with per-customer routing.

Do you log our traffic?

We do not inspect or store the content of your traffic. We do keep the connection metadata needed to operate the service: authentication events, session timestamps, assigned tunnel addresses, and aggregate bandwidth. That is what lets us troubleshoot connectivity, detect abuse of a compromised key, and bill accurately. Exactly what is collected, how long it is retained, and who can access it is scoped and disclosed in your service agreement before you sign, so there is nothing to discover later.

Can it run on-premises?

Yes. Gateways deploy in our managed cloud regions, inside your own cloud accounts, or on hardware in your facilities. An on-premises deployment keeps the data path entirely within infrastructure you control while retaining the same WireGuard and OpenVPN protocols, per-user key model, and private DNS. Mixed topologies are common, for example cloud gateways for the remote workforce and an on-premises gateway in front of internal systems.

How fast is key revocation?

Effectively immediate. Each user holds an individual key, and revoking one propagates to your gateways within seconds. A revoked key cannot establish a new session, and its active sessions are terminated. When an employee leaves or a laptop goes missing, access ends the moment your administrator acts, without touching anyone else's configuration.

Working With Us

People, data, and long-term programs

Who actually does the work?

Senior practitioners who work for us. We never outsource or subcontract delivery, and there is no junior bench learning on your systems. The people on your scoping call are the people who execute the engagement, and you communicate with them directly throughout. That is a structural choice: small teams of experienced testers produce better findings than large teams of interchangeable ones.

How do you handle our data?

On the principle of least data for the shortest time. We collect only what the engagement requires, store evidence encrypted at rest, restrict access to the assigned team, and destroy engagement material on the schedule defined in your agreement. Findings are never reused, anonymized into marketing, or shared across clients. The full policy is documented on our Trust & Data Handling page.

Do you offer continuous testing programs?

We do. Beyond one-time assessments, we run standing programs: recurring assessments aligned to your release cycle, quarterly external testing, or a retainer that lets your team pull us in when a significant change ships. Continuity has a compounding benefit, because the same testers return each cycle carrying real knowledge of your architecture, your history, and where regressions tend to appear.

Get Started

Ask us the question that is not here

Send the specifics of your situation and a senior practitioner will answer within one business day. An NDA is ready before any sensitive detail changes hands.