faq
Questions, answered straight.
If something you need to know is missing, ask. A direct answer costs nothing and saves us both a wasted call.
What does a test cost?
Web application and API testing starts at £2,950, medical-device and SaMD web application testing at £5,950, and a cloud configuration review at £1,950. The final figure depends on scope: how many roles, how much of the application is distinct functionality, and whether testing is authenticated, unauthenticated or both. You get a fixed price before anything starts.
How do you scope it?
A 20-minute call is usually enough. I ask what the application does, how many user roles there are, how big the authenticated surface is, whether there are APIs or integrations, and what would hurt most if it broke. If a smaller scope would answer your real question, I will tell you.
How long does it take?
Scope drives duration, and you get specific dates in the proposal rather than a vague window. Fixed-price quote within 2 working days of the scoping call, and report delivered within 5 working days of testing ending.
Staging or production?
Staging, where it genuinely mirrors production, is usually best: testing is unconstrained and there is no risk to live users or data. Production testing is possible when it is necessary, with agreed timing, rate limits, and a named contact who can stop the test at any moment.
What access do you need?
A URL, one account per user role (two per role is better for access-control testing), a short description of what matters most, and any documentation you already have. For cloud reviews, a read-only role over the subscriptions in scope. Nothing starts before authorisation is signed.
Will testing break anything?
The intent is never to cause an outage. Testing avoids destructive actions, there is no denial-of-service testing, and anything with a plausible impact on availability is agreed with you first. On production systems we also agree rate limits and a stop contact.
What happens if you find something critical?
You hear about it the day it is confirmed, with enough detail to act, rather than finding out when the report lands. If it is serious enough to warrant pausing the test, we will pause and talk.
Do you retest after we fix things?
One retest of fixed findings included, within 60 days. The retest confirms what has actually been resolved, and you get a retest letter you can show customers or auditors.
Can we show the report to customers or auditors?
Yes, that is part of what you are buying. The management summary is written for exactly that, and the retest letter is designed to be forwarded. ISO 27001 auditors and enterprise security reviewers are common readers.
Is this enough for an FDA submission or a technical file?
The medical-device package is written for that purpose: a test plan and specification produced before testing, traceable test cases, and findings mapped to your security risk management. No test report on its own makes a submission successful, but this gives you the independent evidence the documentation needs.
Who actually does the testing?
Alex Adamovici, personally, on every engagement. You deal with the same person from scoping through to retest.
Who do we contract with?
MD QMS Ltd., a UK company (number 14499573). The service is delivered under that contract, and invoiced by that company.
What do you do with our data?
Findings, evidence and reports stay confidential and are shared with nobody but you. An NDA can be signed before scoping. Evidence is kept only as long as needed for the report and retest, then removed.
request a scope
Find out what a test would cost
A 20-minute scoping call, then a fixed-price proposal. No obligation, and no pressure to buy a bigger scope than you need.
Fixed-price quote within 2 working days of the scoping call · Report delivered within 5 working days of testing ending · One retest of fixed findings included, within 60 days