Frequently asked questions
The questions we're asked most frequently about engagements, security, and onboarding. Don't see your question — reach out directly.
Engagements
How does an engagement with AftPak typically start?
Most engagements begin with our guided Requirement Intake wizard, where you define scope, select modules, and specify deployment and compliance needs. Our solutions engineering team reviews your submission and follows up with a custom technical proposal within a few business days.
Do you work with organizations outside government and intelligence sectors?
Yes. While a significant share of our work is with governments and intelligence agencies, we also build for large global enterprises that need the same level of custom-engineered security and compliance infrastructure — particularly in financial services, telecommunications, and critical infrastructure.
How are proposals reviewed and approved?
Every proposal is delivered through your Client Portal, where you can review the full scope, request revisions with specific notes, or approve it digitally. Once approved, it moves into the project tracker with milestone-level visibility.
Security
How does AftPak protect data submitted through this website?
Submissions are encrypted in transit, rate-limited against automated abuse, and stored behind role-based access controls. See our Trust Center and Privacy Policy for full detail on our infrastructure controls and data handling practices.
Is two-factor authentication available for Client Portal accounts?
Yes. TOTP-based two-factor authentication is available for both Client Portal and Admin Panel accounts, and can be enabled from your account's Security page using any standard authenticator app.
Can we deploy on-premise or in an air-gapped environment?
Yes. Many of our engagements — particularly for government and intelligence clients — are deployed on-premise, in sovereign GovCloud environments, or fully air-gapped. Deployment environment is one of the requirements captured during intake.
Onboarding
How long does onboarding take?
Timeline depends on scope and deployment environment, but most engagements move from signed proposal to an active project tracker within one to two weeks. Air-gapped and highly regulated deployments typically take longer due to additional due-diligence and clearance requirements.
Who do we work with day-to-day once onboarded?
Each engagement is assigned a dedicated engagement lead who coordinates with our solutions engineering team on your behalf. You'll have full visibility into progress through your Client Portal, plus direct access to your engagement lead for anything that needs a faster response.
Procurement
Can AftPak support formal RFP, tender, or government procurement processes?
Yes. We regularly respond to formal solicitations for government and intelligence agency buyers, including scoped technical responses, pricing structured to your procurement format, and reference material for evaluation committees. Start the conversation through Requirement Intake or Contact and note that a formal process is underway.
What documentation can you provide for a vendor security or risk assessment?
We provide a summary of our infrastructure controls, access management practices, and compliance framework alignment — the same detail published on our Trust Center — along with policy documents covering data handling, vulnerability disclosure, and export control. Engagement-specific attestations are scoped per Statement of Work.
What are your data residency and export control commitments?
Data residency requirements are captured during Requirement Intake and reflected in the deployment architecture — including on-premise, sovereign GovCloud, and fully air-gapped options. Export control posture for each engagement is documented per our Compliance & Export Control policy and confirmed in writing before work begins.
Do you provide reference points of contact for due diligence?
Given the sensitivity of our government and intelligence engagements, client identities are withheld by default, matching the standard our clients themselves require. Where a specific procurement process requires reference validation, we can arrange it directly with prior client consent on a case-by-case basis.
Still have questions?
Our corporate liaison team responds within one business day for verified organizations.
Contact Us