Skip to content

Questions we are asked most

The questions we are asked most

90 questions, grouped by topic. Not answered here? Send us a message.

90 questions

General

What is Neuraltan?

Neuraltan works across four areas: AI agents and automation, custom software, Web3 and blockchain, and cybersecurity. What is rare is not any one of them but having them in a single team — the systems we build are penetration-tested by the people who know how they were built, and the agents we deploy ship with limits of authority and are tested against instructions slipped in by outsiders.

How do we get started?

It starts with a one-hour technical session at no cost to map the problem. Where the scope is already clear, we lock a number straight away. Where it is not, we propose a two-week paid diagnosis whose output stands on its own — the specification is yours to take to any vendor, and the fee is credited in full if you continue with us.

How long does an engagement usually take?

Of the 54 engagements we have on record, 31 finished within two to four weeks. That is the most typical shape of our work, which is why our fixed-price packages sit in that range. Platform builds run two to six months, and ongoing support runs monthly with no fixed end.

How does payment work?

Payment follows the milestones set out in the proposal, beginning with a deposit before work starts. Invoices fall due within 14 days. We accept bank transfer and digital asset payments in USDT or USDC. All prices exclude tax.

What happens after the work is delivered?

Defects that depart from the specification are corrected at no charge for 90 days after handover. All source code, documentation, and control are handed over in full — we lock nothing away. If you want us to keep maintaining it, monthly support with a written response time is available; if your team wants to take it over, that was the intention all along.

Automated Customer Response

How is this different from most automated responders?

Ours answers from your own documents rather than inventing. When it is unsure it hands over to a person instead of guessing — and where that line sits is agreed with you, not decided for you. Every conversation is stored and reviewable.

How long until it is live?

Three weeks, at a fixed USD 5,500. The first week absorbs your documents and the questions that actually come in, the second connects it to your channels, the third tests it against real questions before customers see it.

Does it handle Indonesian well?

Yes, including the informal register and abbreviations customers actually use on WhatsApp. If a customer switches language mid-conversation, it follows without being told.

Where can it be deployed?

WhatsApp, your website, and email at once, drawing on one shared source of answers — so a customer never gets two different replies from two channels. If you run a ticketing system or CRM, conversations land there rather than in a silo.

What does it cost to run each month?

USD 460 per month, covering infrastructure, answer-quality monitoring, and a fallback provider that engages by itself if the primary one fails. The cost of each conversation is logged, so you can see for yourself what is actually being used.

Workflow Automation

What kind of work is worth handing to a machine?

Work that is repetitive, high in volume, and governed by rules you can write down: tiered approvals, reconciliation, scheduling, invoicing, and copying data between applications. Work that needs case-by-case judgement is better left with people — and we say so when that is the answer.

What happens with cases that fall outside the normal flow?

Exceptions are not guessed at. They are pulled out of the flow, flagged, and routed to whoever is authorised to decide, along with the reason they were pulled. A flow that quietly guesses produces errors that only surface months later.

How do we work out whether it pays off?

We first count the hours the process genuinely consumes each month, then set that against the cost of building and running the automation. If the numbers do not add up we say so plainly — an automation opportunity map is bought precisely to get that answer, not to justify a build.

How long does implementation take?

Approval automation is a fixed USD 3,900 and takes two weeks. Flows that span several systems run six to twelve weeks and start with a diagnosis, because the scope cannot be pinned down until we know which systems are involved.

Is our team trained to use it?

Yes, and the training is for the people who will actually run it day to day, not only the IT team. It covers how to read a failure and handle it yourselves, so you do not need to call us for the simple things.

Custom Software

When is building better than buying off the shelf?

When off-the-shelf software forces your team to change how it works and the part that matters most simply is not there. If what you need already exists on the market, buying is almost always cheaper — and we will say so, even when that means there is no work in it for us.

How does the build run?

Small releases every two weeks, not one large handover at the end. You see what works from early on and can change direction while it is still cheap. Scope changes are written down with their cost and time attached — we do not quietly do extra work and invoice for it later.

How many rounds of changes do we get?

Corrections to anything that departs from what was agreed are unlimited and unbilled — that is our responsibility. What is bounded is added scope, and that is costed openly by the day. Promising "unlimited revisions" without drawing that line is a promise that always ends badly for one side.

How long until we can use it?

A custom web application runs six to sixteen weeks, a subscription platform ten to twenty, and a back-office system eight to twenty. The exact figure is locked after a two-week diagnosis rather than guessed at the outset.

Do we own the source code?

Yes, entirely, on full payment — including the right to modify it and pass it to another party. Third-party open-source components remain under their own licences, and we hand over that list alongside the work.

Web3 & Blockchain

When is blockchain actually the right tool?

When several parties who do not trust one another must agree on the same record, and the rules have to be readable in the open so nobody can quietly change them. If everyone already trusts a single operator, an ordinary database is cheaper and faster — and that is what we will recommend.

Which networks do you work on?

Ethereum-compatible networks, including Polygon and Base where low network fees matter. The choice is driven by cost, liquidity, and where your investors already are — not by our preference.

What does publishing a contract cost?

The network fee itself is small; what drives cost is the design and the audit. A contract audit up to 500 lines is a fixed USD 5,000 including one retest, and 500 to 1,500 lines is USD 9,500. For a full platform, the figure is locked once the token design is final.

Is the contract reviewed before launch?

Always, and it is not an optional extra. We review dimension by dimension — arithmetic, access control, external calls, price references, economic resilience — then test with randomised input rather than only the happy path. Once published, a mistake cannot be recalled.

Who holds the keys and the authority?

You do. We set up multi-signature wallets, approval thresholds, and key rotation procedures, then hand over control at completion. We do not hold client keys — one person holding every key is the most common way funds are lost permanently.

Security Engineering

What is the difference between a penetration test and a vulnerability assessment?

A vulnerability assessment catalogues and ranks weaknesses broadly. A penetration test tries to actually break through them to see how far an attacker could get. The first answers "what is weak"; the second answers "how bad it is when someone uses it".

How long does a security audit take?

Two weeks per target, counted from the moment scope and testing authorisation are agreed in writing. The report arrives at the end, and one retest after your fixes is included — not billed as new work.

Can we share the report with other parties?

Yes, and it is often used that way — our reports are written to be handed to prospects, auditors, or investors. They come in two layers: a summary a board can read, and a technical annex for your team. We never disclose findings to anyone without your written permission.

What happens once a gap is found?

Every finding arrives with a reproduction and a remediation step your own team can carry out. Findings are ranked by real danger rather than by count — a long unprioritised list is how the most dangerous item ends up waiting its turn.

Do you also support us through to certification?

Yes, for ISO 27001, SOC 2, and PCI-DSS. Evidence is assembled along the way rather than crammed together before the auditor arrives, and policies are written to be followed rather than filed.

Vulnerability Assessment

When is a recurring assessment better than a one-off?

When your systems change every month. Testing once a year leaves eleven months in which nobody knows the state of things. A recurring assessment compares each period with the last, and carries forward findings that are still open.

How long does one round take?

About two working days a month for a settled scope, with results in the same week. Nothing needs to be taken offline; the assessment runs without disturbing live services.

Do we receive a certificate?

What we issue is a dated report with the testing evidence behind it, and that is what auditors and prospects actually ask for. A formal certificate can only be issued by an accredited certification body — we support you through to that point but do not issue one ourselves, and anyone claiming otherwise is worth doubting.

What does it cost?

Recurring vulnerability assessment is a subscription at USD 1,100 per month, six-month minimum. For a one-off, a penetration test is usually the better instrument — USD 4,500 per target, including the report and one retest.

Is there support after the report?

Yes. Your team can ask about any finding until it is clear, and a retest after remediation is included. A report handed over and then abandoned closes no gaps at all.

Penetration Testing

Is it safe to test a system that is serving customers?

It is, under rules of engagement agreed in writing beforehand: what may be tested, when, and which actions are off limits. Anything potentially disruptive runs outside peak hours or against a replica, and we keep a route to halt testing within minutes if something goes wrong.

How long does it take?

Two weeks for a single web or API target, counted from the moment scope and authorisation are agreed. The report arrives at the end of the second week, and one retest after fixes is included.

Does it cover all our systems?

It covers the agreed targets, and that boundary is stated plainly in the report. We do not blur scope, because a report that appears to cover everything is the dangerous kind: whatever was not tested gets treated as safe despite never having been looked at.

What does it cost?

USD 4,500 for a single web or API target — a full price with a written scope, not a "starting from". It includes a report you can hand to prospects or auditors, and one retest after fixes.

Do you help close the gaps you find?

Every finding comes with a remediation step your own team can carry out, and we stay available while they do it. If you want us to carry out the fixes, that is a separate engagement — so that whoever tests is not marking their own homework.

Cloud Security

Why does a cloud environment need its own review?

Because most cloud exposures come not from software flaws but from settings left as they came: over-broad permissions, storage accidentally left public, and old accounts never disabled. An application penetration test does not touch that layer.

How long does the review take?

Two weeks for one AWS, Azure, or GCP environment. Monitoring is installed as part of the work, not merely recommended on the last page of a report.

Can the checks run automatically and continuously?

Yes. The checks are wired into the release pipeline so they run on every change, and drift is reported as soon as it appears. That is what keeps an environment tidy after we leave, rather than tidy only on assessment day.

What does it cost?

USD 3,800 for one environment — a full price with a written scope. Where the review surfaces cloud cost savings, we put a number on them; not infrequently that offsets part of the fee.

Does this help with compliance requirements?

Yes. The configuration evidence and monitoring records it produces feed directly into ISO 27001, SOC 2, and PCI-DSS — the three things auditors ask for most often and that are most often missing when they arrive.

Corporate Account Security

Why does the corporate account directory need reviewing?

Because it holds the keys to nearly everything. What we find most often: accounts of staff who left a year ago still active, some with administrator-level rights. One such account is enough to open the whole network.

How long does the review take?

Two weeks for a single directory. The first week maps permissions and accounts; the second tests escalation paths to administrator rights. You receive findings ranked by danger, not a long unprioritised list.

How do we stop people escalating to administrator rights?

By narrowing rights to what is genuinely used, separating everyday accounts from privileged ones, and closing the intermediate paths that usually go unnoticed — old service accounts whose rights accumulated over years, for instance. We test the paths first, then show you which ones demonstrably work.

What does it cost?

USD 3,800 for a single directory. It covers mapping excess permissions, dormant-but-active accounts, testing escalation paths to administrator rights, and drawing up a leaver account-disabling procedure.

Can attacks be detected as they happen?

They can, with monitoring built for it — and we install that as part of the work. But monitoring only helps if someone acts on the alerts, so we also set out who gets called and what the first step is.

Mobile App Security Testing

Why do mobile apps need testing of their own?

Because a mobile app stores data on a device its user fully controls — and which anyone holding it can prise open. Keys, tokens, and customer data kept there are regularly found with no protection at all, and server-side testing never sees that layer.

How long does testing take?

Two weeks for one application, covering both Android and iPhone. It includes prising open data stored on the device and testing traffic to the server — the two places most often overlooked.

How does testing iPhone differ from Android?

The approach is the same and follows OWASP guidance, but the tooling and the techniques for prising them open differ because the two systems are built differently. We test both rather than testing one and assuming the other matches.

What does it cost?

USD 3,800 for one application, covering both Android and iPhone — not counted twice. The third-party libraries bundled inside the app are examined too, because that is where flaws often enter unnoticed.

Does our development team get guidance?

Yes. Alongside the findings, your team receives safe patterns for the things most commonly got wrong — on-device storage, token handling, and server communication — so the same mistake does not reappear in the next release.

Audit & Certification

What is the difference between a security audit and compliance?

A security audit judges whether your systems are genuinely hard to break into. Compliance judges whether you meet a standard’s list of requirements. The two do not automatically move together: a system can pass certification and still be easy to breach, and the reverse.

How long until the certificate is issued?

Three to nine months for ISO 27001, depending on how far you are from it now. Measuring that distance is itself a fixed USD 4,000 and takes one to two weeks — only then can a schedule and cost be stated with any basis.

Is evidence collection automated?

Largely, yes — configuration evidence and monitoring records collect themselves throughout the year. What cannot be automated is policy and training, because both require people to actually follow them rather than merely be recorded.

What does it cost?

Audit readiness is a fixed USD 4,000: we measure the distance between where you are and ISO 27001 or SOC 2, then hand over a prioritised work list with time and cost estimates. Support through to the certificate itself carries no upfront figure — its scope depends on that measurement.

What is the business case?

The clearest benefit: deals stop stalling. Large prospects routinely withhold signature until a test report or certification exists, and their security questionnaires can then be answered in days rather than weeks. The rest — insurance premiums, investor due diligence — follows from that.

AI Agents

How does an agent differ from an assistant that only answers?

An assistant answers questions. An agent works step by step to completion: reading context, deciding within written limits of authority, calling the systems it needs, then handing over to a person the moment it steps outside those limits. What makes one usable is not its cleverness but its boundaries.

Does the agent learn from our data?

It reads your documents and data in order to answer, but that data is not used to train anyone else’s model. Where your policy requires that data never leaves at all, we run it on your own servers.

How often does an agent get things wrong?

A single number here is always misleading, because it depends on the task. What we do instead: build the means of measuring right and wrong from the outset, measure against your own real cases, and show you the figure before the agent goes anywhere near users. Without that instrument, "high accuracy" is just a claim.

How is sensitive data protected?

The agent’s access is confined to what it genuinely needs, and every retrieval is logged. We also test whether it can be coaxed into leaking data through instructions hidden in an incoming document or message — a test almost never run by vendors who merely deploy agents.

Is there monitoring once the agent is live?

Yes, and it is part of monthly operations: the cost of each run is logged per user, answer quality is checked periodically, usage limits keep the bill from running away, and a fallback provider engages by itself if the primary one goes down.

System Integration

Which systems can be connected?

Almost anything with an open interface: accounting systems, ERPs, CRMs, payment gateways, shipping providers, and online stores. For legacy systems that offer none, we build a connecting layer of our own — which is in fact the work we are asked for most.

How long does one connection take?

One to two weeks per connection, at a fixed USD 2,100. What drives the timeline is not the number of systems but how well documented the system on the other side happens to be.

Do we receive documentation?

Yes: what is exchanged, when it runs, what happens on failure, and how to inspect it yourselves. Without that, an integration becomes a black box only we can repair — and that is not the working relationship we want.

What happens when a transfer fails?

Failures are reported, not swallowed. Failed transfers retry themselves with increasing delays, and whatever still fails goes into a queue for a person to handle. An integration that fails silently is the most common way data discrepancies appear with nobody noticing.

Is there support if a connection breaks?

Yes, through monthly support with a written response time. The system on the other side can change without telling anyone — that is the most common cause of breakage, and not something our side can prevent outright.

Data into Decisions

What kind of data can you work with?

Sales, website behaviour, operational records, and financial data from multiple sources — including whatever currently lives in spreadsheets. What matters is not the format but whether the figures are consistent; that is where most of the work turns out to be.

How long until the dashboard exists?

Three weeks for a management dashboard at a fixed USD 5,200, unifying three data sources. What takes the time is not drawing the charts but agreeing one definition of each figure that every division accepts.

Are the figures updated in real time?

They can be, but it is rarely worth it. For management decisions, hourly updates are usually enough and far cheaper to run. We build real-time updates where decisions genuinely are made in seconds — operations monitoring or fraud detection, for instance.

How is personal data within it protected?

Personal data is separated and masked where a report does not genuinely need it — and most management reports do not. Access is set per role, so not everyone opening the dashboard sees the same rows.

Is our team taught to read it?

Yes, and the important part is not which button to click but how to tell when a figure deserves doubt. A dashboard trusted blindly is more dangerous than no dashboard at all.

Company Websites

Is the design made specifically for us?

Yes, built around your brand rather than lifted from a reused template. But we do not chase unusual layouts for the sake of looking different: a company site is judged by how quickly a visitor finds what they came for.

How long does it take?

Two to three weeks for a company site with a content panel, at a fixed USD 3,200. Your own copy is usually what sets the pace, not the build.

Is the site ready to be found by search engines?

Yes, from day one: correct page structure, loading speed, structured data, and a proper showing on phones. What we cannot promise is a particular ranking — that depends on your content and your competition, and anyone promising rankings is worth doubting.

Can we change the content ourselves?

All of it. Text, images, pages, navigation links, and search engine descriptions can be changed from a panel without calling a developer. A site where every small change goes through the vendor stops being updated within months.

Can it connect to online sales?

It can — catalogue, basket, payment, and shipping, or a connection to the store you already run so stock and orders do not live apart. If your sales already run elsewhere, connecting is almost always cheaper than migrating.

Technology Advisory

What does an advisory engagement cover?

A review of the systems you have, choosing a technical direction, architecture, and vendor assessment — including judging other vendors’ proposals honestly. The output is a decision you can act on, not a stack of documents.

How long does it usually run?

One to two weeks for a clearly framed question, and a two-week diagnosis where the systems need dissecting. Where the advice runs on, it takes a monthly shape rather than a project with an artificial end date.

Do you stay on through implementation?

We can, but it is not required — deliberately so. The output is written so your own team or any vendor can act on it. Advice that only its author can execute is not advice; it is a sales pitch.

What form does the output take?

A short document setting out the findings, the available options with their numbers, our recommendation and the reasoning behind it, and the order of work. It closes with a working session involving the people who will carry it out.

Is there any follow-up afterwards?

Yes. Your team can ask questions while the work proceeds, and where circumstances change we revisit the recommendation. A recommendation never looked at again a year later is usually wrong by then.

Trading Automation

Is trading automation guaranteed to be profitable?

No, and anyone promising otherwise is best avoided. What the machine does is execute your strategy with discipline — never late, never hesitant, never asleep. If the strategy itself loses money, running it more faithfully only makes the losses more consistent.

How long until it can run?

Six to twelve weeks, most of it spent testing against historical data rather than writing code. We do not switch it on against real funds until its behaviour is proven across a period that includes bad markets.

What happens when markets move violently?

Loss limits are enforced by the machine rather than left to human discipline. If losses breach the threshold you set, it halts itself and reports — waiting for nobody’s decision. That moment is precisely when people most often make the decision they later regret.

How is risk controlled?

Position size limits, daily loss limits, and capital separation are set in advance and cannot be exceeded. Every decision is logged, so any trade can be traced back to the rule that triggered it.

Is it monitored around the clock?

Yes, and the monitoring does more than record: if it stops, loses its connection, or behaves outside its norm, an alert goes out immediately. A bot that dies quietly with a position open is far more dangerous than one that stops and says so.

Still something unclear?

Just ask. We answer plainly, including when the answer is that it is not worth building yet.