How We Work

What to expect when working with us.

Every engagement follows a clear sequence. You always know where you stand, what comes next, and what you'll receive. No black boxes, no vague phases, no consulting theater.

Initial Call

You describe what you're building or operating with AI, what worries you, and what outcome you need. We ask the questions that matter: architecture, data flow, team structure, regulatory exposure.

This is a working session, not a sales pitch. We'll tell you on the spot if we can help — and if we're not the right fit, we'll say so and point you in a better direction.

  • No slide deck, no "vision" presentation
  • You talk; we listen and structure
  • Typically 45–60 minutes
You receive

A one-page summary of what we understood, the likely scope, and confirmation of whether we can take it on.

Scope & Proposal

We translate the initial call into a written proposal. That means a concrete scope, a fixed timeline, and a price — not a range, not an estimate, not "depending on findings."

If the scope is too uncertain for a fixed price, we'll propose a paid scoping phase first. Either way, you know the commitment before you decide.

  • Fixed scope, fixed timeline, fixed price
  • Clear deliverables listed one by one
  • No bait-and-switch, no change-order games
You receive

A proposal document you can compare against other offers — structured so the differences are visible, not buried in prose.

Kickoff & Access

Once the proposal is signed, we set up the working environment. You grant the access we need — repositories, APIs, documentation, key contacts — and we confirm everything is reachable.

This phase is deliberately short. We want to be in the work, not in the setup. Most kickoffs are completed within two business days.

  • Dedicated Slack channel or your preferred channel
  • Access matrix agreed upfront, no surprise permission requests mid-project
  • Single point of contact on each side
You receive

A confirmed start date, a channel where you can reach us directly, and a checklist of everything we need from your side — completed or in progress.

Execution

The bulk of the work happens here. We operate in focused cycles with regular checkpoints — you see progress as it happens, not at the end when it's too late to adjust.

Depending on the engagement type, this may be an analysis sprint, a build phase, or a hardening cycle. What stays the same: you get a status update every Friday, and you can reach the team directly between checkpoints. Communication runs through a shared Slack channel, or your preferred channel.

  • Weekly written status: what was done, what's next, what's blocked
  • Mid-cycle demos for build engagements
  • Findings logged as they're discovered, not collected for a final report
You receive

Continuous visibility into the work. No "trust us, it's going well" — you see the output as it's produced.

Review & Verification

Before anything is marked as done, it goes through structured review. What that review looks like depends on the engagement — but it's never "the lead dev glanced at it."

Analysis

Every finding is cross-checked by a second analyst. Risk ratings are calibrated against CVSS and the framework relevant to your industry. Vague statements are sent back.

Build

Code review by someone who didn't write it. Tests run against the acceptance criteria from the proposal — not against what was convenient to build.

Security Assessment

Every identified vulnerability is reproduced on a clean environment to rule out false positives. Severity ratings are documented with the exact method that triggered the finding.

Security Fixes

Every fix is validated against the original finding. A fix that merely changes the behavior without addressing root cause is rejected. Retests confirm closure before handover.

Monitoring

Detection rules are tested against historical data and synthetic edge cases before going live. Alert thresholds are tuned to your actual baseline, not a generic template.

Handover

Everything we produce is yours. At the end of the engagement, you receive a complete package: all deliverables as defined in the proposal, plus the raw working materials — notes, logs, test cases, scripts — not just the polished report.

We walk you through every result in a live session. You ask questions, we explain the reasoning behind each decision, and you sign off when you're confident you have what you need.

  • Live walkthrough of all deliverables
  • Raw working materials included, not just final output
  • 30 days of follow-up clarification at no extra cost
You receive

A complete package you can act on immediately — and a direct line back to us if anything is unclear.

Standards & Frameworks

Frameworks by service.

The frameworks we use depend on the service, system and scope of the engagement. The table below shows where each framework is applied.

Which frameworks inform which Autorea service. A filled marker means the framework informs that service.
Framework Analyze Build Secure Operate & Improve

Methodology alignment is not the same as formal certification.

Where Autorea holds an actual certification or registration, it will be stated separately and specifically.