Skip to main content

Talk to an expert

Thirty minutes with a senior engineer.

Not a sales call. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like. You leave with a written scope.

Talk to an expert

Book a 30-minute consultation.

No sales script. A senior engineer walks through your current posture, the frameworks that bind you, and what a realistic programme looks like: scope, timeline and cost.

  • 30 minutes, not 15Enough time to actually scope the work, not just qualify you.
  • Speak to an engineerThe person who would run your assessment, not an SDR.
  • Leave with a written scopeA summary of recommended services and indicative effort.

Office hours 10:30 am to 7:30 pm IST, Monday to Saturday

1Your details
2Your requirement

We only use this to schedule your call.

Optional, speeds up scheduling.

We record the page you arrived on, your referrer and campaign parameters alongside this enquiry so we can route it to the right team. See our privacy policy.

Regional presence

Our cybersecurity footprint across the globe.

10 locations and delivery coverage across 15+ countries, anchored by our Bhubaneswar headquarters. Every key on the map is a place our engineers work from.

Bhubaneswar, IndiaIndiaCorporate Office India

Headquarters of global security operations

3rd Floor, F3, Ryan Tower, Technology Corridor, near Trident Academy, Chandaka Industrial Estate, Infocity, Chandrasekharpur, Bhubaneswar, Odisha 751024

If you are dealing with something live right now

Stop reading and call. The number on this page is answered outside business hours, because an incident line that only works between nine and six is not an incident line.

Three things worth doing before we speak, and none of them take long. Preserve rather than clean: do not rebuild the affected host, do not delete the suspicious account, do not wipe and reimage, because the evidence that tells us how far this went lives in exactly the places instinct says to tidy. Write down the timeline you have, even roughly, with times and who noticed what. And identify who in your organisation can authorise containment actions, because the first useful decision usually needs somebody with that authority awake.

If you are subject to the CERT-In Directions, your six hour reporting clock started when somebody noticed, not when the intrusion began, and not when we arrive. Raising that early is part of what the first call covers.

What happens after you send the form

An engineer reads it, not a queue. For anything that is not an active incident, you will hear back within one working day, and the reply comes from a person who can answer a technical question rather than one who has to go and ask.

The first substantive conversation is thirty minutes and is not a sales call. Its purpose is to work out what you actually need, which occasionally turns out to be less than what you asked for. We would rather establish that on a call than three weeks into an engagement.

If a scope follows, it arrives in writing with the effort broken out by activity rather than as a single number, a named lead, a start date, and the list of what we need from you. You are not asked to commit to anything before you can see what you would be committing to.

What to include so the first reply is useful

  • What the system does and roughly who uses it, in one or two sentences
  • Which regulator or framework is driving this, if any: CERT-In, RBI, SEBI, IRDAI, DPDP, ISO 27001, PCI DSS, SOC 2
  • Whether there is a date you are working towards, and what happens on that date
  • Whether the environment is production, staging, or not built yet
  • Whether this is a first assessment or a repeat, and who did the last one
  • Anything you are specifically worried about, however unformed

Which route to use

For an active incident, the phone. For everything commercial or exploratory, the form or the sales address, both of which reach the same place.

For a security issue in one of our own systems or in something we built, use the responsible disclosure route rather than the general form. It is monitored, it is answered, and we do not pursue researchers who follow it in good faith.

For a request about data we hold about you, or for our Data Processing Addendum, sub-processor list, insurance certificates or attestation reports, the trust centre sets out how to ask. Documents are usually turned around within two working days under NDA.

For a job, the careers page rather than here. We answer applications, including the ones we decline.

Things people ask before they get in touch

Do you work with organisations our size. Yes, and the honest caveat is that if what you need is genuinely a compliance tick at the lowest possible price, we will tell you on the first call that we are the wrong firm rather than quote for it.

Will you sign our NDA. Yes, before any technical detail is discussed if you would prefer. We will also sign yours rather than insisting on ours.

Can you work outside India. Yes, across the Gulf, Africa and Australia. The testing method travels unchanged; what we adjust is the reporting, because findings are framed against the obligations you actually answer to rather than against Indian regulation.

How quickly can you start. It depends on the practice and the time of year, and we will give you a real date rather than an optimistic one. If we cannot serve your timeline properly, we would rather say so than compress the work to fit it.

What if you find nothing serious. You get a report that says so plainly, with what was covered and how. A firm that cannot produce a clean report is a firm whose findings you cannot trust when they are severe.