Skip to content

We answer your customer’s security questionnaire, then fix what’s missing

Send us the questionnaire or the portal link. We answer it with evidence, fix the gaps and give you a one-page summary for your customer.

The first call is free. Services start from $1,500, and we agree a fixed price before any work starts.

An example of the one-page summary you forward, from our fictional sample report.Read the whole sample report

When you need it

Usually one of these, often with a date attached.

  • A customer sends a security questionnaire or a vendor-risk portal link.
  • Your customer’s contract asks you to meet DORA, NIS2 or similar rules.
  • An investor’s due diligence list includes security.
  • You’re about to sell to bigger companies and know the questionnaire is coming.

What you get

We agree a fixed price after the free call, once we know what’s in scope. Services start from $1,500.

Request a free call
  • A check of your product against what your customer actually asked.
  • The questionnaire answered, with evidence where it exists.
  • A plan to close the gaps, most important first, with how long each takes.
  • A one-page security summary you can forward.

Not included: changes to your app’s code (your developers make them, with our help), the audit, certificate or pentest itself, software licences, insurer or broker fees, and incident response.

Before we touch anything

Nothing starts without your written OK
You name the systems, the accounts and the dates first.
We work from a named account you create
It has only the rights the work needs, and you can see everything it does.
You take the access back when we’re done
We delete or return our working data, and you remove the account.

All six ground rules

How it works

Three steps. You agree the price before each one starts. Services start from $1,500.

  1. A free call

    Tell us who’s asking and when they need an answer. We’ll say what we’d check, then send you a fixed price.

    30 minutesFree

  2. We check what they asked about

    We check your product and setup against their questions, and test where it matters. You get the answers with evidence, a plan and a one-page summary to send them.

    About two weeksPriced after the call

  3. We fix what’s missing

    We fix your cloud and account setup ourselves. Your developers make the code changes, with our help. Then we check every fix, at no extra cost.

    Usually sign-in security, cloud alerts, tested backups and web firewall. What each fix does.

    1 to 8 weeks a fixPriced after the assessment

Before you enquire

What people ask us most. Anything else, ask on the call.

Do you fill in the portal for us?

We draft every answer and gather the evidence. Then you paste them in, or we do it with you on a call. Some portals only accept the vendor’s own login.

What if the honest answer is no?

Then the answer says no, with the date it becomes yes from the plan. Most customers accept a dated plan. A yes that doesn’t hold up costs you the deal later.

Does this work for investor due diligence?

Yes. It’s the same assessment, with a summary for the data room in place of a questionnaire.

Our customer is a bank or another regulated business. Is that different?

A little. We also map your answers to the DORA and NIS2 clauses they’re likely to ask about.

What do you need from us?

The form, questionnaire or report, and a call with whoever runs your cloud and your workspace. For a fix, a named admin account for the systems it changes, set up the way we describe on the call.

How do you handle our admin access?

You create a named account for us with only the rights the fix needs, and you can see everything it does. We never use shared logins. Each fix lists its changes, when they happen and how to roll them back, and you remove the account when the fix is done.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Tell us about the questionnaire

Who sent it, when they need it back, and roughly how many questions. On the call we’ll say what we can answer from day one.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team

Request a free call

We only use it to follow up on your enquiry.

When does whoever’s asking need an answer?

Please leave out passwords and customer data.

We only use your details to reply to your enquiry. How we handle enquiry information.

Or email contact@unmesha.io directly.