How can we help?
Tell us which side you’re on and we’ll point you to the right place — with answers to the questions we hear most, and a real person on the end of an email if you need one.
Questions from customers
Getting a fix
How does getting a fix actually work?
You tell us the CVE (or describe the finding) and your environment. A vetted specialist scopes the work and sends back a fixed quote. If you accept, they deliver a reviewed fix for you to deploy in staging first — never straight to production. You deal with our team throughout.
What does it cost, and do I pay upfront?
It’s priced by the work, not a flat fee — engagements start at $750, and you can see how it’s built on the pricing page. Quoting is always free, and you pay nothing until you’ve accepted a scope and quote.
The CVE page quotes a price. Is that what I’ll pay?
No — it’s an estimate scoped from the published advisory, not from your codebase. It exists so you can budget before you talk to anyone. The real quote comes after a specialist has seen your actual setup, and it is fixed before any work starts.
How fast can you turn a fix around?
Standard work is planned over a week or two. If it’s urgent we have expedited (a few days) and emergency (24-hour target) options — useful when a CVE is being actively exploited.
There’s no vendor patch at all. Can you still help?
That’s the case we exist for. Most CVEs in this catalogue have no vendor fix — no patch, no version to upgrade to. We write an original fix for your environment, test it, and hand it over with the reasoning. It is harder work and it is priced accordingly.
I’m not sure which CVE I have. Can you still help?
Yes. On the request form, choose “help assessing a finding” and tell us what your scanner or pentest flagged. We’ll work out what you’re actually dealing with before quoting anything.
Trust & access
Do you need access to my codebase?
Usually not. Most engagements need a version, a configuration, and a clear description of the deployment. If a fix genuinely can’t be built without seeing code, the specialist will say so up front — and you decide, not us.
Who actually does the work?
A specialist from our vetted roster, matched to the shape of your problem. They’re professional contractors who earned their place by proving the work, and a named person owns your fix end to end. Not a queue, not a bot.
What if the fix breaks something?
That’s why it goes to staging first, always. Any known breaking change is stated in the handover before you deploy — not discovered afterwards. If something we shipped is wrong, we fix it.
What do you store about me?
What you send us, and nothing more. We don’t sell data, we don’t run ads, and we don’t need your source to do most of this. If you paste an environment into the checker on a CVE page, don’t include secrets — we say so on the box.
Can you sign an NDA?
Yes. Say so in your first message and we’ll handle it before any technical detail changes hands.
The database
Where does the data come from?
NVD and vendor advisories for the source material, CISA KEV for exploitation status, EPSS for likelihood. Every section on a CVE page states its source on the page, so you always know whether you’re reading the vendor’s words or ours.
Which parts are written by AI?
The technical summary, the remediation steps and the environment checks. We label them — visibly, in the heading, not in a footnote. The official description is the vendor’s own wording, unedited. Where our summary and a primary source disagree, the source wins, and we say that too.
Can I trust the AI summary?
Trust it the way you’d trust a competent colleague’s notes: useful, worth reading, and not a substitute for the advisory. It is written only from published material and never invents facts. The references on every page are the authority.
Is the scanner really free?
Yes — free, open source, and it runs on your machine. It reads your lock files locally and uploads nothing. There is no account, no telemetry and no upsell inside it.
What do you actually charge for, then?
One thing: building a fix that doesn’t exist. The database, the scanner and the community notes are free and stay free. We’d rather you never needed the paid part.
Questions from contractors
Joining
How do I join the roster?
Head to Jobs and apply. You’ll complete a short technical assessment — that’s what carries the most weight, not your résumé.
How does vetting work?
We judge demonstrated remediation skill above everything else. The assessment is the main gate; if the work is strong, you’re on.
Do I need a security job title?
No. We care whether you can close a vulnerability and explain why your fix is correct. Plenty of people who can do that have never had “security” on a business card.
The work
How is work assigned, and how much?
We match engagements to your skills and interests and offer them to you — you take what fits, at your own pace. There’s no obligation to accept any given piece of work.
What kind of work is it?
Real remediation of live vulnerabilities for organisations that need them closed. A lot of it is the hard case: no vendor patch exists and somebody has to write one.
Is it remote?
Yes — remote and project-based. You work when and where suits you, around the scope and timeline agreed for each engagement.
Getting paid
How and when do I get paid?
Every engagement is scoped and paid, with your rate agreed up front — no spec work, no unpaid trials. Payment follows delivery of the reviewed fix.
Who owns the fix I write?
The client gets the fix they paid for. Where it makes sense to upstream a patch to the vendor, we’ll do it with your name on it — your work, your credit.
Send us a message.
If your question isn’t answered above, drop us a line — a human reads every message, and it lands with our team rather than a black-hole inbox.