Frequently asked questions

Short answers for people evaluating an audit, post-incident response, or a build engagement. If something is missing, write.

General and pricing

What is the estimated price?

It depends on scope. A security audit is not priced like a product build. Work can be billed hourly or as a fixed project once the scope is clear. Currency is US dollars (USD).

How do payments work?

In USD. Hourly or fixed project, as agreed. Deposit and payment milestones are set when scope is locked; there is no public fixed rate without a brief.

What is the delivery timeline?

It depends on complexity, the access you provide, and the kind of work (audit, incident response, or build). Small scopes close faster; larger ones ship in milestones.

What if scope changes mid-project?

We re-quote. Extra hours or a project addendum; scope creep is not absorbed silently. Better to say it early than stretch the same price.

How do we start?

A serious message with the problem, the stack, and the outcome you want. We agree scope, billing (hourly or project), and a work window. I reply after Shabbat.

When do you reply? What about Shabbat?

While observing Shabbat, the craft rests. Profiles can be read; mail is not opened until Motzaei Shabbat. After that, I reply in earnest.

Which languages and time zone?

Spanish and English. Based in Santa Cruz de la Sierra, Bolivia; when I give Shabbat or other cutoffs, I use Argentina time (as on the site note).

Is there confidentiality or an NDA?

Yes. Work is under agreement. Reports and findings go only to the authorized client. I do not publish real client cases or client data on the portfolio.

Do you work remotely?

Yes. Based in Santa Cruz de la Sierra; the craft is remote unless the work requires presence.

How does this relate to Mercav.lat?

Mercav.lat is the role and the product. Audit, incident-response, or build engagements are agreed separately: they are not Mercav customer support or a marketplace help channel.

Is there maintenance after delivery?

Delivery closes the agreed scope; it does not include open-ended support. Ongoing maintenance or iterations can be hired hourly or as a separate package.

Who is this for — and who is it not for?

For teams and products that want a service that closes cleanly, a serious audit, or post-incident response with an actionable report. Not for offensive catalogs, cheats, or “break X for me” without a defensive mandate and clear authorization.

Security audit

What does an audit include?

Surface review (APIs, authn/authz, flows), findings prioritized by risk, and a remediation-oriented report. I document the failure and the fix — not an exploitation playbook.

What do you need from the client?

Agreed access (staging or scoped prod), a map of relevant endpoints or repos, and a technical contact. Without that, scope and timeline inflate.

What is out of scope?

I do not deliver offensive catalogs or recipes to break third-party systems. Grey-hat here means studying offense to design defense.

Incident response

What do you deliver after an incident?

Timeline and entry vector, observed methods (patterns, not payloads), endpoints involved, data at risk, severity range, and a containment-and-close plan.

How urgent is the work?

Containment and evidence first; reconstruction and report second. The window depends on severity and how much access the team gets.

Does it help if the attack already happened?

Yes. Post-incident work reconstructs what happened, what was exposed, and what to harden so the same path stops being usable.

Full-stack development

What does a full-stack engagement cover?

Backend and web logic (HTTP contracts, domain, auth, data) plus the UI needed for the product to close. One profile that designs the service and understands how it breaks.

How is it priced?

Fixed project when scope is closed, or hourly when scope is evolving. Timeline follows complexity and client dependencies. Currency is USD.

Frontend only

Do you take frontend-only work?

Yes, when the scope is UI, accessibility, and consuming defined APIs. If the backend is weak, I say so early: UI does not hide broken authz.

What stack do you prefer?

TypeScript and React / Next when it fits. I adapt to the product stack when API contracts are clear.

Backend only

Do you take backend-only work?

Yes: APIs, authn/authz, domain, persistence, jobs, and clear layer boundaries. Also low-level C++20 when the problem calls for it.

What do you deliver?

Code and contracts that hold under load and abuse, with explicit auth and data limits. Endpoint and design notes when the project needs them.

Connect