Frequently asked questions
Straight answers about how we work, what our engagements cover, and how we handle your data. If your question isn’t here, ask us directly — we’ll give you an honest read.
What does verrou actually do?
We’re a boutique security consultancy focused on three things we do well: Post-Quantum Cryptography (PQC) Readiness, AI Security, and Product Penetration Testing. Rather than sell a broad menu staffed by a junior bench, we keep the scope narrow and the seniority high — every engagement is scoped, executed, and reported by an experienced practitioner. If a request falls outside where we can genuinely add value, we’ll tell you and, where we can, point you somewhere better.
Who do you typically work with?
Growing companies that need serious security outcomes without the overhead of a large consultancy: software and product teams, platform and infrastructure companies, and organizations shipping AI-powered features. We work well with teams that have real engineering depth but limited in-house security capacity, and with leaders who want direct access to the person doing the work rather than an account manager. We’re comfortable in regulated and security-sensitive contexts, and we adapt scope to your stage rather than forcing an enterprise template onto a smaller team.
How are engagements scoped?
Every engagement starts with a scoping conversation, not a quote. We map what you’re trying to protect, your threat model, and your business priorities, then define a scope that targets what actually matters — the systems, data, and risks that would hurt if they failed. From there you get a written statement of work with clear objectives, boundaries, deliverables, and timeline before anything begins. No surprise change orders, and no padding the scope with work that doesn’t move your risk needle.
How long does an engagement take?
It depends on scope and complexity, but the shape is consistent: a scoping call, a written statement of work, a kickoff, an active assessment window, and reporting with a walkthrough. We give you a realistic timeline in the statement of work and flag anything that would move it as soon as we know.
Will you sign an NDA?
Yes. We’re happy to sign a mutual NDA before we discuss anything sensitive, and we can work under yours or provide a standard one. Confidentiality is fundamental to security work — the whole point is that we see things you don’t want widely known. If you’d like the specifics of the arrangement (governing terms, retention, and the legal entity you’re contracting with) in writing, that’s covered in the engagement paperwork.
What does a PQC readiness assessment cover?
A post-quantum cryptography readiness assessment inventories the cryptography across your environment — algorithms, key sizes, protocols, certificates, and where they live — then grades that estate against current NIST post-quantum standards and guidance such as CNSA 2.0. Our discovery starts with our own in-house scanner, so you get a concrete picture of your cryptographic estate rather than a checklist. The deliverable is a risk-graded inventory plus a prioritized migration roadmap: what’s exposed, what to fix first, and how to move to quantum-resistant algorithms without breaking what works. See the PQC Readiness page for detail.
What is the "harvest now, decrypt later" threat?
It’s the reason post-quantum migration is urgent even though large-scale quantum computers don’t exist yet. An adversary can capture encrypted data today — traffic, backups, archives — and simply store it, waiting until a future quantum computer can break the encryption protecting it. Anything with a long confidentiality lifetime (health records, financial data, trade secrets, government material) is effectively at risk now, because the data being intercepted today may still be sensitive when it can be decrypted. That’s why the practical question isn’t "when will quantum arrive?" but "how long does my data need to stay secret?" — and why migrating to quantum-resistant cryptography is a present-day priority.
What does AI security testing cover?
We assess AI-powered products and the pipelines behind them for the ways they actually fail: prompt injection and jailbreaks, sensitive data leakage, insecure handling of model inputs and outputs, and weaknesses in the model supply chain. For agentic systems — assistants that call tools, take actions, or operate autonomously — we red-team the workflows and, critically, the permissions and integrations behind them, because that’s where an AI feature turns into a real-world exposure. You get findings tied to concrete impact plus practical guidance for deploying AI features safely. More on the AI Security page.
What’s the difference between a penetration test and a vulnerability scan?
A vulnerability scan is automated: a tool checks your systems against a database of known issues and produces a list, usually ranked by generic severity scores. It’s useful for coverage and hygiene, but it doesn’t understand your business, chain weaknesses together, or tell you what an attacker could actually achieve. A penetration test is hands-on: an experienced practitioner probes your systems the way a real attacker would, combining findings, testing your specific logic, and validating what’s genuinely exploitable. We rank results by real business impact rather than raw scanner noise, so you fix what matters instead of chasing a long list of low-signal alerts. See Penetration Testing.
Do you help with remediation and retesting?
Yes. A report full of findings isn’t the finish line. Our findings come with concrete, prioritized remediation guidance written for the engineers who have to implement it, and we’re available to answer questions as your team works through fixes. Retesting of remediated issues is included in our testing engagements, so you get confirmation that a fix actually resolved the problem — not just an assumption that it did. The goal is that improvements stick rather than quietly regress.
How are reports delivered, and how do you handle our data?
You get a written report structured for two audiences: a plain-language executive summary that stands on its own, and detailed technical findings with reproduction steps and remediation guidance your engineers can act on. Critical issues are flagged the moment we find them, not held until report day, and we walk you through the results rather than emailing a PDF and disappearing. On data handling: we collect only what the engagement requires, treat it as confidential under NDA, and transfer and store it securely. If you have specific requirements around data residency, retention periods, or destruction after the engagement, tell us up front and we’ll document exactly how it’s handled.