Questions · Answered plainly

The questions we are asked before anyone commits.

These are the questions that come up in almost every first conversation. Where the answer is uncomfortable, it is still the answer.

Engaging with us

What does it cost?

There is no rate card. Every engagement starts with a due diligence review, and the scope that review establishes decides the price. We quote in writing once we know what is actually in scope. The pricing page sets out the three tracks and what each includes.

Do I have to start with an assessment?

No, but most organisations do, because it is the cheapest way to replace an assumption with a documented position. If you already know your scope, the strategic advisory track can begin with the due diligence review instead.

How quickly can we start?

Portal access follows the approval of your request, which is a human decision rather than an automated one. An assessment can be completed as soon as access is granted. An advisory engagement begins on an agreed date after the proposal is accepted.

Who is behind SecureEdge Advisory?

The advisory practice is led personally, which is the point of it: you engage a named accountable person carrying CIO and CISO responsibility, not an account manager routing you to a delivery pool. The About page sets out the position in full.

The products

Are the products generally available?

Not all of them. Each product carries a stage marker on the Products page: simulation, MVP in development, or preview and hardening. We publish the stage rather than a version number, because a version number implies a shipped release. Products are provisioned to an organisation individually when they are ready for that organisation's use.

Which frameworks do you cover?

The control library carries fifteen frameworks spanning international standards and the GCC regulatory set, including ISO 27001, SOC 2, NIST 800-53, GDPR, UAE PDPL, NESA, ADHICS, Dubai ISR, CBUAE, SAMA CSF, NCA ECC and the regional privacy laws. Cross-framework mapping is mature for a subset of these; the Frameworks page states the position for each one rather than implying uniform depth.

Can evidence collected for one framework be reused for another?

Where the mapping supports it, yes, and that is much of the value of a shared control library. It is not universal. Two frameworks may ask a similar question and still require different evidence, and we do not present a mapping as satisfied coverage. The mapping shows the relationship; an auditor decides whether the evidence answers it.

Do you certify us?

No, and no platform can. We prepare you for certification and we facilitate the audit. The affirmation comes from an external auditor or certification body. Any platform that tells you it has certified you has misunderstood what certification is.

Your data

Where is our data hosted?

The application and its database are hosted in Frankfurt, in the European Union. Our sub-processor register names every third party with access to customer data and the purpose of each.

We are in the UAE. Does European hosting create a problem?

It requires the transfer to be handled properly rather than ignored. UAE PDPL permits cross-border transfer where appropriate safeguards are in place, and the Data Processing Agreement sets out those safeguards. If your regulator requires domestic residency for a specific dataset, tell us during scoping, because that changes the design rather than the paperwork.

Can we export our data and leave?

Yes. Assessment results, control mappings, evidence records and reports are exportable in open formats. Leaving should cost you effort, not your history.

Can we ask you to delete everything?

Yes. You may request deletion of your organisation's data, and the Data Processing Agreement sets out the process and the retention periods that apply where a record must be kept for legal reasons.

Who can see our evidence?

Your organisation's users, according to the role you assign them, and our staff only where support requires it and the access is recorded. Audit trails are written as work happens rather than reconstructed afterwards, which means access is visible to you as well as to us.

Assessments and reports

What do I actually receive?

A structured report: a maturity position by domain, what is in place, what is missing, and a prioritised order of remediation. The priority order is the part that matters. An undifferentiated list of gaps tells you nothing about what to do on Monday.

Is the assessment self-certified?

Yes. You answer for your own organisation, and the report reflects what you reported. It is a structured statement of position, not an audit finding, and it is presented as such throughout.

Can we re-run an assessment later?

Yes, and that is the intended use. Results are retained in your portal so a later run can be compared against an earlier one, which is how you evidence direction of travel to a board.

Does a good score mean we are compliant?

No. It means your reported position against that instrument is strong. Compliance is affirmed by a regulator or an auditor, against evidence, at a point in time. We are careful about this distinction because the alternative is selling false comfort.

A question that is not here?

Ask it directly. A question that is difficult to answer publicly is usually the one worth asking.

Ask us directly →