- Can you intervene if we have already received a vulnerability report or notification?
- Yes. We start by taking controlled ownership of the infrastructure and making an initial backup, so the data is preserved before anything changes. We then assess the critical vulnerabilities, isolate the affected components and set out a remediation plan. We commit to rapid mobilization and assessment — not to a fixed resolution deadline decided before the analysis.
- How long until we receive an offer?
- We reply within the same business day with a preliminary assessment, the recommended service and the steps required for procurement. The technical and financial offer follows once we understand the access available and the actual state of the application.
- What if the original supplier no longer responds, or the source code is incomplete?
- This is one of the most common situations. We start from what actually exists: the running application, the database, the server configuration. We rebuild the technical inventory, document the dependencies and establish what can be recovered, what has to be rebuilt and what can be retired.
- Can the application be moved directly into government infrastructure?
- Rarely directly. An application with outdated components, dependencies that cannot be updated, or no automated deployment can be rejected on entry into the new infrastructure. The migration readiness audit establishes exactly what has to be modernized before the move.
- Do we need Kubernetes?
- Not for every application. For simple sites and portals we recommend an architecture proportional to the requirement. Kubernetes is justified when availability, scaling and operational complexity genuinely call for it.
- We have backups. Is that enough?
- An untested backup is not a recovery strategy. We test the actual restore, measure how long it takes and document the procedure, so the institution knows the real recovery time before an incident rather than during one.
- Can these services be contracted through direct acquisition?
- The services are defined with an object, deliverables, a timeframe and terms of provision, so they can be acquired directly under Law no. 98/2016. The decision on the procedure belongs to the contracting authority, based on the estimated value of the entire requirement.
- Can you publish the service in the SEAP electronic catalogue?
- Yes. On request we send the technical datasheet, the matching CPV code and the item in the SEAP electronic catalogue, together with the technical and financial offer.
- Can the content and history of the current website be preserved?
- Yes. Taking over and structuring the content, together with migrating the public archive, are part of the modernization package. Preserving the public archive is usually a requirement, not an option.
- What happens after the migration?
- We can take over operations as a monthly subscription or annual contract: monitoring, updates, backup, restore testing, certificate management, security reviews, reporting and incident management.