cyberagent.id · docs FAQ

Frequently Asked Questions

Short answers to the things we are asked most often before an engagement begins.

What services are available?

Two service lines: security assessment (web, API, source code, external infrastructure, cloud configuration, and AI systems) and custom AI engineering for day-to-day operations. Details are on the Security Assessment and Custom AI Engineering pages.

How do we get started?

Send a short brief to founder@cyberagent.id. We reply within 45 minutes during WIB business hours and arrange a 30-minute scoping call at no cost.

How long does one engagement run?

A focused assessment generally takes 2–4 business days, a standard assessment 5–10 business days, and an in-depth assessment 2–4 weeks. The final duration is set during scoping, based on the number of assets and the depth of the review. For AI projects, the phases follow the agreed discovery and prototype.

Which frameworks do you use as a reference?

OWASP Top 10, OWASP API Security Top 10, OWASP LLM Top 10, OWASP ASVS/WSTG, MITRE ATT&CK, NIST CSF 2.0, ISO/IEC 27001, PTES, and CVSS for severity scoring. Details are on the Methodology & Standards page.

Can you sign an NDA?

Yes. A mutual NDA and a testing authorization letter are signed before any work begins. Client names and engagement details are not published without written consent.

How is our data handled?

Data accessed during an engagement is used only for that engagement, is not copied outside the agreed environment, and is deleted after the report has been accepted. For AI projects, customer data is never used to train third-party models.

Is there a reward for vulnerability reports?

No. Our disclosure program is recognition-only — no payment or bounty. What we offer is fast confirmation, fixes that are actually shipped, and public acknowledgement if you want it. Details are on the Vulnerability Disclosure page.

Are the dashboard and API available yet?

Not yet. The public dashboard and API are marked coming soon and will be opened once testing is complete. During this period, every service is handled directly by email.

What happens if a critical vulnerability is found during the work?

We report it early through the agreed communication channel — we do not wait for the final report. For findings that require a fast decision, we include the impact and interim mitigation options.

How do payment and ownership of deliverables work?

Billing is handled through a B2B invoice with the payment terms agreed in the proposal. For development work, the code and configuration we build belong to you.

Still have other questions?

Email founder@cyberagent.id for service questions, or founder@cyberagent.id (subject: Vulnerability report) specifically for vulnerability reports.

© 2026 CyberAgent.id Getting Started · Disclosure · cyberagent.id