FAQ
Straight answers, no sales theatre.
The questions people actually ask before they hire us — including the awkward ones about price, capacity and what we cannot do. 23 answers across 5 topics.
FAQ
Working with us
How do we start an engagement with SemperWise?
Send an enquiry or call, and we will book a 30-minute scoping call — usually within a day or two. On that call we establish what you actually need, which is not always what was asked for. You then receive a written scope and a fixed price, and nothing begins until you have signed it. There is no obligation attached to the scoping call and we do not charge for it.
Where are you based and do you work outside India?
We are based in Coimbatore, Tamil Nadu, and we work with clients across India and internationally. Security testing is largely remote work, so location rarely constrains delivery. On-site presence for workshops, internal network testing and training is straightforward across Tamil Nadu and available elsewhere in India by arrangement.
How big is your team and who actually does the work?
We are a small, senior team, and that is deliberate. The people who scope your engagement are the people who deliver it — there is no model here where a senior consultant sells the work and a junior performs it. The founding team brings over 20 years of combined experience across cybersecurity, cloud, compliance, healthcare and enterprise technology. If our capacity is genuinely the wrong fit for the size of your programme, we will say so rather than take the work.
What does an engagement cost?
It depends on scope, and we quote fixed prices rather than day rates that expand. A single web application penetration test is typically the smallest engagement we run; a multi-application programme with internal network and cloud testing is several times that. We publish no price list because any number we printed would be wrong for most readers — but we will give you a firm figure in writing after one call, and we will tell you if a smaller piece of work would answer your question just as well.
Do you sign NDAs?
Yes, as a matter of course, and usually before the scoping call if you would prefer. Client identities, findings and reports are confidential by default. We do not name clients publicly or use their logos without explicit written permission, which is why this site does not display any — security testing engagements are covered by NDA and we would rather have a thin case-study page than break one.
Can you work under our customer’s security requirements?
Yes. We routinely work under enterprise client requirements covering background checks, secure handling of data, restricted-environment working, and non-removal of code or findings. Tell us the constraints during scoping and we will confirm in writing what we can meet.
FAQ
Testing and reports
What makes your reports different?
They are short, every finding in them has been verified by a person, and each one tells you what to do about it. We do not deliver tool exports. Automation gives us coverage across 10,046 detection rules and current vulnerability intelligence; a human then discards the noise, confirms exploitability and establishes business impact. A typical report has a two-page executive summary a director can read and a technical section a developer can act on directly, with control mappings so the same work serves your audit.
Do you provide evidence we can give to auditors and customers?
Yes. Every finding is mapped to ISO 27001 Annex A, PCI DSS, HIPAA, NIST CSF and OWASP ASVS clauses, so remediation and audit evidence are the same piece of work. After the retest we issue a summary letter confirming scope, dates and closure status, written to be shared with customers and procurement teams without exposing technical detail that should stay private.
Is a retest included?
Yes, one retest cycle is included in every testing engagement at no additional cost. You fix, we verify, and the report records the state change per finding rather than becoming a fresh document with no history. Further retests, if you need them, are quoted separately and are inexpensive.
How quickly will we hear about a critical finding?
The same day we confirm it. Critical and high-severity findings are escalated to your named contact immediately, with enough detail to act, rather than being held back for the final report. Waiting two weeks to tell a client their customer database is reachable would be indefensible.
What if you find nothing serious?
That happens, and we will tell you plainly rather than manufacturing severity to justify the invoice. A clean report against a properly scoped test is a genuine result and is exactly what you hand to a customer who asked. Where we think the scope was too narrow to support a confident conclusion, we say that in the report as well.
Do you use automated tools or manual testing?
Both, and the split is the point. Automation provides coverage that no human could match — our engine carries 10,046 detection rules, matches against 356,454 CVEs scored by exploit probability, and tracks the 1,662 vulnerabilities known to be actively exploited. Manual testing provides judgement: business logic, authorisation boundaries, and chaining several minor issues into one serious one. A test that is only automated misses most of what matters; a test that is only manual misses the obvious.
FAQ
The platform
What is SemperWise One™?
SemperWise One™ is our cloud-native SaaS platform, architected on AWS, that unifies security, compliance, risk and AI governance in a single dashboard across 28 modules in four groups — Protect, Comply, Govern and Intelligence. It is one product rather than a suite, so there is one data model and nothing to integrate between modules. The platform section of this site marks each module as live or in development, because it is released progressively and we would rather be accurate than impressive.
Do we have to buy the platform to use your services?
No. The services practice stands entirely on its own and many clients only ever use it. The platform is what makes continuous work — attack surface monitoring, continuous controls monitoring, managed vulnerability management — practical to deliver, so clients on those services get access as part of the engagement.
Can the platform run in our own environment?
Yes. The same codebase deploys to our managed AWS cloud, into a customer-controlled private cloud account where data residency requires it, or on-premises for regulated environments that cannot use shared infrastructure. This is a deliberate design decision rather than an enterprise upsell — a meaningful share of Indian healthcare, financial services and government work simply cannot use multi-tenant SaaS.
How current is your vulnerability intelligence?
Vulnerability intelligence is refreshed daily. That includes exploit-probability scores across 356,454 CVEs, the CISA Known Exploited Vulnerabilities catalogue at 1,662 entries, and a 226,392-row index mapping product versions to the vulnerabilities that affect them. Our own detection library — 10,046 rules across 50 technology packs — is versioned per pack with a review date on each. Current figures and what they mean are published on our detection coverage page.
FAQ
Compliance
Which compliance frameworks do you work with?
ISO 27001, SOC 2, the DPDP Act 2023, GDPR, HIPAA, PCI DSS, NIST CSF and ISO 42001 for AI management systems. Most clients need one certification and two or three others satisfied contractually. Because the underlying controls overlap heavily, we implement once and map to everything, which is considerably cheaper than running separate programmes.
Does the DPDP Act apply to our business?
Almost certainly, if you process the digital personal data of people in India. The Digital Personal Data Protection Act 2023 applies to processing within India, and to processing outside India where goods or services are offered to people in India. In practice that covers nearly every business with Indian customers or Indian employees. The obligations centre on consent and notice, data-principal rights, security safeguards and breach notification, with additional duties for organisations designated as Significant Data Fiduciaries.
Can you certify us?
No, and no legitimate consultancy can. Certification must be issued by an accredited certification body that is independent of whoever implemented the management system. We implement the ISMS, run your internal audit and support you through Stage 1 and Stage 2 — but the certificate comes from an independent body. Any firm offering to both implement and certify is offering something worthless.
Does being compliant mean we are secure?
No. It means you are consistent, which is a precondition for security rather than a substitute for it. A compliant organisation has decided what its controls are and can demonstrate that they operate. Whether those controls would stop a competent attacker is a different question, and it is answered by testing. This is why we run both, and why findings from our testing feed the same risk register the compliance programme runs on.
FAQ
AI and security
Do you use AI in your testing?
Yes, for analysis, correlation and drafting — and every finding that reaches a client has been reviewed and confirmed by a person. AI is genuinely good at reading large volumes of output, spotting patterns across findings and producing a first draft of a narrative. It is not reliable enough to be trusted with a severity rating or an exploitability judgement, and we have seen enough confidently wrong AI output in our own tooling to be firm about that. The structured findings are the source of truth; the AI is a productivity layer over them.
Can you test our AI features?
Yes. We assess LLM and RAG applications against the OWASP Top 10 for LLM Applications, covering direct and indirect prompt injection, agent and tool permissions, retrieval-layer access control and output handling. This is a distinct assessment from a conventional application test — we have repeatedly found serious AI-layer issues in applications that passed a thorough penetration test weeks earlier, because the test correctly examined the application and had no reason to treat the document corpus as an attack surface.
Is our data used to train AI models?
No. Client data, findings and reports are never used to train models, ours or anybody else’s. Where AI analysis is applied during an engagement, it runs within our controlled environment under the same confidentiality terms as the rest of the work, and clients with strict requirements can have AI analysis disabled entirely for their engagement.
More Detail
Service-specific questions.
Every service page carries its own FAQ covering the questions that only apply to that piece of work — how long it takes, what access we need, and what could go wrong.
VAPT Services
Assessment and penetration testing, end to end.
Read the FAQ → 6 questionsWeb Application Testing
OWASP Top 10, ASVS and business logic.
Read the FAQ → 5 questionsAPI Security Testing
REST, GraphQL and service-to-service.
Read the FAQ → 6 questionsNetwork Penetration Testing
External perimeter, internal and Active Directory.
Read the FAQ → 5 questionsCloud Security Assessment
AWS, Azure and GCP configuration and identity.
Read the FAQ → 7 questionsCompliance & Audit
ISO 27001, SOC 2, DPDP, HIPAA, GDPR.
Read the FAQ → 5 questionsAI Security & Governance
LLM testing, AI governance and private deployment.
Read the FAQ → 6 questionsManaged Security & vCISO
Security leadership and operations, as a subscription.
Read the FAQ → 6 questionsSecure Code Review
Manual review and static analysis across 27 languages.
Read the FAQ →Still unanswered
Ask the question directly.
If it is not here, it is probably specific to your situation — which makes it a better conversation than a web page. Thirty minutes, no charge, no obligation.