Questions About Working With Palisade
Answers about our cloud and DevOps support, penetration testing, security consulting, pricing, and engagement process.
Book a free scoping call through the website. We will discuss your goals, current setup, timeline, and the pressure you are facing, then recommend a practical next step.
You do not need to choose perfectly before contacting us. If the issue is reliability, deployments, cloud controls, or infrastructure maturity, it usually starts with Cloud, DevOps & Technical Advisory. If you need independent testing of an application, API, mobile app, cloud environment, or AI system, it usually starts with penetration testing. If you need help answering customer, compliance, or security readiness questions, it usually starts with Security Consulting & Readiness.
No. Many clients are early-stage or lean teams with founder-built infrastructure, a small engineering team, or no dedicated security function. We meet you where you are and focus on improvements that fit your stage and budget.
Most engagements begin within 1-2 weeks of scoping and approval. If you have a time-sensitive customer review, launch, or security concern, we can usually prioritize the first call and confirm what is realistic.
Every engagement starts with a scoping call. We look at the complexity of your environment, the service required, the depth of testing or advisory support, and your timeline. You receive a clear proposal before work begins.
We review the parts of your delivery and cloud setup that affect reliability, security, and buyer confidence: cloud accounts, access, CI/CD, infrastructure-as-code, environments, backups, monitoring, alerting, secrets, cost signals, and operational runbooks.
Yes. We can work alongside your team to turn review findings into concrete improvements across delivery, infrastructure, reliability, access, and cloud operations. The goal is practical implementation, not just a list of findings.
Yes. A lot of useful work starts with systems that were built quickly to get a product to market. We help make that setup easier to operate, safer to change, easier to explain to customers, and more ready for the next stage of growth.
Yes. We can help map your cloud architecture, access model, deployment process, backup approach, logging, monitoring, and change controls into clear evidence for customer security reviews and vendor questionnaires.
A vulnerability assessment identifies and prioritizes potential weaknesses, often with automated scanning and manual review. A penetration test goes further by validating exploitability and real-world impact, which gives your team a clearer view of actual risk.
We test web applications, APIs, mobile applications, cloud infrastructure, and AI & LLM systems. Each assessment is scoped to your environment and follows recognized methodologies such as OWASP, OWASP MASVS, PTES, and NIST guidance where relevant.
We recommend testing at least annually, and after major infrastructure changes, product launches, authentication changes, sensitive feature releases, or significant cloud architecture changes. Regulated or higher-risk environments may need testing more often.
Yes. We test AI and LLM systems for risks such as prompt injection, unsafe tool use, data exposure, insecure integrations, model manipulation, and weak controls around AI-enabled workflows.
We follow recognized frameworks including OWASP Top 10, OWASP MASVS for mobile, PTES, and NIST guidance where relevant. Our approach combines automated coverage, targeted validation, exploitation where appropriate, and practical reporting by experienced security engineers.
We take precautions to avoid disruption. Testing is carefully scoped and scheduled, and we coordinate closely with your team. For production environments, we use non-destructive techniques unless otherwise agreed.
You receive a report with an executive summary, technical findings ranked by severity, proof-of-concept evidence, and clear remediation guidance. We can also run a walkthrough session so your team understands the results and next steps.
We provide remediation guidance, answer developer questions, and can retest fixes where retesting is included in scope. For teams that need deeper help, we can also support practical remediation work through an advisory or implementation engagement.
Yes. If we discover a critical or actively exploitable issue, we notify you promptly instead of waiting for the final report. We then agree on a safe communication path and help your team understand the fix priority.
Yes. A penetration test evaluates specific systems for exploitable weaknesses. Security Consulting & Readiness looks at the broader operating model: customer security reviews, policies, cloud controls, secure development workflows, evidence, and practical remediation priorities.
Yes. We help teams answer vendor and customer security questionnaires with clearer evidence, realistic commitments, and remediation plans for gaps that need attention before the review is returned.
Yes. We can help prepare for these frameworks by reviewing current controls, identifying gaps, organizing evidence, and building a practical remediation plan. We do not turn readiness work into paperwork for its own sake. The goal is controls your team can actually operate.
Yes. All Palisade services are covered by our independently certified ISO/IEC 27001:2022 information security management system, including penetration testing, technical consultancy, and SaaS application services.
Yes. Training can be focused on the systems your team actually builds, such as secure API design, authentication, authorization, secrets handling, dependency hygiene, cloud security basics, AI security risks, and secure review habits.
Both. Some clients need a focused review or test. Others use a retainer for periodic testing, cloud and DevOps advisory, customer review support, remediation guidance, and secure development enablement. The scope is tailored to the work you actually need.
Pricing depends on scope, complexity, and the type of assessment. As a rough guide, a small, well-scoped REST API penetration test often ranges from SGD 5,000 to 10,000. Broader web, mobile, cloud, or AI assessments vary based on scope. We provide fixed-price quotes after scoping, and retesting is included where agreed in the proposal.
We accept bank transfers and major credit cards. For retainer engagements, we can discuss monthly or quarterly billing cycles.