Thirty Minutes With a Founder

A scoping call, not a pitch. We work out what needs testing, what it would cost, and whether a penetration test is even the right thing for where you are. Our pricing is published, so there is no number being held back.

Nothing on the calendar works for your timezone? Say so through the contact form or write to contact@cybersecify.com and we will open a slot that does.

What We Cover

Three things, in this order. Most calls finish inside the half hour.

01

What you are shipping

Your product, your stack, and which parts are exposed. Web app, APIs, cloud, mobile, or an AI feature. This is what decides scope, and scope is what decides price.

02

Why now

A customer questionnaire, an investor asking, a SOC 2 or ISO audit with a date on it, or you want to know how you would hold up. The trigger changes what the engagement needs to produce.

03

What it would cost

Our pricing is published, so this is usually confirming which tier fits rather than revealing a number. If your scope does not fit a published tier, we say so on the call.

A Founder, Both Times

The call is with Ashok Kamat, co-founder. Where it turns deeply technical, Rathnakara GN, co-founder and Chief Hacking Officer, joins or takes it separately. Rathnakara holds OSCP and an M.Sc in Cyber Security, and he leads every penetration testing engagement we run.

Every boutique firm says it is founder-led, and at most of them the work quietly moves to someone junior after the sale. The version of that claim worth anything is the one you can check before you pay. Your lead tester is named in the statement of work at signature, not announced at kickoff, and Rathnakara signs the final report and the Letter of Attestation.

We work with AI-first and API-first SaaS startups, Seed to Series B. See who you would be working with.

Useful, Not Required

You can turn up with none of this. Having it makes thirty minutes go further.

Rough scope

How many applications or APIs, roughly how many user roles, and whether cloud infrastructure or a mobile app is in scope. Approximate is fine. We are not going to hold you to it.

Your deadline

If an audit, a customer, or a funding round has a date attached, say so early. It changes sequencing more than anything else in the conversation.

Your questions

Especially the awkward ones. How we handle findings we cannot exploit, what happens if we find nothing, who actually does the testing. Those are the useful ones.

Before You Book

How long is the call and who runs it?

Thirty minutes over Zoom, with Ashok Kamat, co-founder. There is a waiting room, so nobody else can drop into your call. If the conversation turns deeply technical, Rathnakara GN, co-founder and Chief Hacking Officer, joins or picks it up separately. You are speaking to a founder either way, not to a sales representative or an account manager.

Is this a sales call?

It is a scoping call. Our pricing is already published at cybersecify.com/pricing/, so there is no number to reveal and nothing to negotiate on a call. The purpose is working out what your scope actually is, whether a pentest is even the right thing for your situation, and what the engagement would produce. If a pentest is not what you need, we will tell you that.

Do I need to prepare anything?

No, but the call goes faster if you know roughly how many applications or APIs are in scope, how many user roles exist, and whether cloud infrastructure or a mobile app is included. Approximate numbers are fine. If there is a deadline from an audit, a customer, or a funding round, mention it early because it affects sequencing more than anything else.

Will I get a quote on the call?

Usually yes, because pricing is published and most scopes map directly onto a published tier. Where scope is unusual or spans several systems, we follow up with a written quote rather than guessing on the call. Anything binding arrives as a written quote and statement of work, never as something said in conversation.

Who actually does the testing?

Rathnakara GN, co-founder and Chief Hacking Officer, leads every penetration testing engagement. He holds OSCP and an M.Sc in Cyber Security. There are no account managers and no junior analysts running your pentest. The lead tester is named in your statement of work at signature rather than announced at kickoff, and Rathnakara signs the final report and the Letter of Attestation.

What if I am not ready to buy yet?

That is a normal reason to book. Plenty of these calls end with a scope, a rough timeline, and a decision to come back in a quarter. If you would rather read first, the redacted sample report at cybersecify.com/sample-report/ shows exactly what we deliver, and cybersecify.com/methodology/ covers how we work. Booking a call is not a commitment to anything.

What times can I book, and what if my timezone does not fit?

Slots run Monday to Saturday, 11:00 to 20:00 India Standard Time. The later slots are there deliberately so buyers outside India can reach us inside their own working day. 20:00 IST is roughly 10:30am US Eastern, 15:30 in the UK, 22:30 in Singapore and midnight in Sydney, so most timezones have something workable. If nothing on the calendar fits yours, send a note through the contact form at cybersecify.com/contact/ saying which hours suit you and we will open one. We work with clients across the US, EU, UK, Singapore, Australia and Hong Kong, so this is a normal request rather than a favour.

Can we sign an NDA before talking?

Yes. Send yours over or ask us for ours before the call and we will get it signed first. Nothing you describe on a scoping call needs to include credentials, live data, or anything sensitive, but if your process requires an NDA before any conversation, that is straightforward to arrange.

Pick a Time

Thirty minutes over Zoom, with a waiting room, so nobody drops into your call. Slots run Monday to Saturday, 11:00 to 20:00 India time, with the later ones there so buyers outside India can reach us inside their own working day. If none of them work for your timezone, send a note through the contact form and we will find one that does. First reply is a few hours most days, up to 2 business days under heavy load.

Open the calendar