The system audit runs at a fixed price over five working days. For the remaining positions the effort depends on the system, which is why we name the price only after scoping. It is then fixed and not renegotiated.
Yes. For suitable projects we work fully or partly for equity instead of the full price. Whether that fits, we clarify upfront in the mandate review.
Yes. We explicitly take on operations, maintenance and further development for third-party systems. A system audit usually comes first, because we do not take responsibility for something we have not seen.
The system audit is a one-off engagement with no follow-on obligation. Implementation runs over twelve weeks with exit points after week four and week eight. Operations runs monthly, a mandate over six to twelve months.
On infrastructure in Germany, set up in line with the GDPR from the outset. If you have your own requirements regarding the operating location or the certification of the data centre, we build accordingly.
Yes. We carry out penetration testing and red teaming, strictly on assignment and with written authorisation. In scope are the external perimeter, web applications, the firewall, social engineering and semi-automated attack chains. The result is a traceable report with proven weaknesses, severity and concrete countermeasures.
No. We handle the technical and organisational preparation: assessing whether you are in scope, finding gaps, planning measures and documenting evidence. The legally binding assessment belongs with your lawyers, with whom we work on this.
No. Every enquiry goes through a mandate review. We decline if we cannot see a project through into operations, or if another firm is better placed for it.
In most mandates providers are already in place. We take technical leadership and continue working with them wherever that holds. Replacing a provider is never an end in itself and is only proposed when it pays off.
Yes. We build to public procurement standards and know the requirements for documentation, evidence and handover readiness that apply in the public sector.
We work for companies and institutions, including public and non-profit bodies. For this area we build tender-ready, GDPR-native software and know the requirements for documentation and evidence.
As a rule we reply within 24 hours with a concrete proposal for the next steps. It starts with a short first call in which we place your project.
A reply within two working days, with a concrete scoping proposal.