FD.Solutions

FAQ

Questions we get before the first call.

Our bank asked for a penetration test showing no high or medium severity vulnerabilities. Can you provide that?

Yes — that's core to what we do. We test, you remediate with our support, we retest, and you receive a report explicitly confirming no outstanding high or medium severity findings, in the format your bank expects.

How long does an assessment take?

Testing typically runs 5–10 working days depending on scope, with the report following within ⟨5⟩ business days. Remediation time depends on your team. Plan 3–4 weeks end to end, and start earlier than you think you need to.

Will testing disrupt our live site?

We test production carefully, within agreed windows, avoiding intentionally destructive techniques unless you specifically authorize them.

What's the difference between a vulnerability scan and a penetration test?

A scan is automated and looks for known issues. A penetration test is manual and looks for what an actual attacker would exploit — including flaws no scanner can recognize. Many compliance frameworks require both as separate controls.

Can you analyze an Android app we didn't build?

Yes, provided you own it or hold written authorization from the owner. We commonly analyze third-party applications before clients deploy them internally.

Can you both build our platform and provide the compliance report?

We can build it, but the compliance report has to come from an independent party. That's not our preference — it's what makes the report acceptable to your bank.

How often do we need to retest?

Annually at minimum, and after any significant change. Most compliance frameworks require both.

Find out what's exposed — before someone else does.

Tell us what you need tested and who's asking for the report. A short scoping call is usually enough to give you a clear scope, timeline, and fixed price.

Request a Scoping Call