Skip to content
Kodvalley

Help centre

How can we help?

Search our answers first. Most questions are solved here in seconds, and our team is one ticket away when they are not.

Popular:
  • 51 answers
  • 3 languages
  • 4-hour incident response

Answers matching your search:

We could not find an answer for that.

Try a shorter or different word. If the question is specific to your project, our team will answer it in a ticket.

Open a ticket

Getting started

Who we are, how to start and what to expect.

Kodvalley is a European technology group based in Vilnius, Lithuania. We work in four areas:

  • Cybersecurity: manual penetration testing, red teaming and security reviews
  • Software engineering: web platforms, e-commerce, mobile apps and reverse engineering
  • Cloud and AI: cloud integration, DevOps, managed hosting and machine learning
  • EU projects: VET, CERV, Horizon Europe and Erasmus+ partnerships

Our product brands Improj, Visalley and Jairno grow out of the same engineering team.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

The fastest route is the quote form. Tell us what you need, the size of the environment and any deadline. A specialist reviews it, may ask a few scoping questions and sends a fixed-scope proposal.

If you are not sure which service fits, describe the goal in plain words. Scoping is part of our job and costs you nothing.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

We work with companies of every size, public bodies, foundations, schools and universities across the EU and beyond. Engagements range from a single web application test for a start-up to multi-year platform development and EU-funded consortia.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Our team works in English, Turkish and Lithuanian. Reports, proposals and support are available in any of the three. Technical deliverables are written in English by default unless you ask otherwise.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Our registered office is at Laisvės pr. 60-1107, Vilnius, Lithuania. Most work is delivered remotely across Europe.

On-site work such as internal network testing, workshops or project meetings is available on request and scheduled in the proposal.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Our legal name is MB Kodvalley, company code 306329532, registered in Lithuania. The full details, including address and contacts, are in the footer of every page. Our team can also send a supplier information sheet on request through the quote or contact form.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Penetration testing and security

Methodology, scope, reports, re-tests and incidents.

A scanner looks for known patterns and reports possible issues. A penetration test is performed by a person who thinks like an attacker: they confirm each finding, chain weaknesses together and exploit business logic that no tool understands.

Every finding in our reports comes with a working proof of concept, a risk rating and clear remediation steps.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Our testing is aligned with OWASP (Web Security Testing Guide, API Security Top 10, MASVS), PTES and NIST SP 800-115. Findings are scored with CVSS.

If you need mapping to a specific framework such as ISO 27001, SOC 2, PCI DSS, DORA or NIS2, tell us during scoping and we include it in the report.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

  • Web applications and APIs (REST, GraphQL, SOAP)
  • Mobile apps on iOS and Android
  • External and internal networks, Active Directory and Wi-Fi
  • Cloud environments on AWS, Azure, Google Cloud and OVHcloud
  • Red team exercises and social engineering, including phishing simulations
  • Source code reviews and architecture reviews
Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

A typical web application test takes three to ten working days depending on the number of roles, features and integrations. Network and red team engagements take longer. The exact number of days is fixed in your proposal before any work begins.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

We plan every engagement to avoid disruption. Rules of engagement agree the scope, time windows, test accounts and an emergency contact on both sides. Destructive tests and denial of service are excluded unless you explicitly ask for them.

If you prefer, we can test a staging environment that mirrors production.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

  • A signed authorisation and agreed scope (URLs, IP ranges or apps)
  • Test accounts for each user role
  • Testing windows and any systems that must not be touched
  • A technical contact reachable during testing

We send a short checklist with the proposal so nothing is missed.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

You receive two layers in one document:

  • An executive summary written for management, with overall risk and priorities
  • A technical section with every finding, its CVSS score, evidence, proof of concept and remediation guidance

A debrief call is included to walk your team through the results.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Yes. Once your team has fixed the findings, we re-test them free of charge within the agreed period and issue an updated report with the new status of each issue. Many clients use this updated report as evidence for auditors and customers.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

An NDA can be signed before scoping. Findings and evidence are stored encrypted, shared only through the client portal or encrypted channels, and deleted after the retention period agreed in the contract. Testers access only what is in scope.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Open a ticket in the client portal and choose the Security Incident department. These tickets carry a 4-hour response target and reach our security team immediately.

If you cannot sign in, use the contact page and mark the message as urgent. Do not switch off affected systems before talking to us, since this can destroy evidence.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Thank you for helping. Please report it through the contact page with clear steps to reproduce, and do not access data beyond what is needed to show the issue. We confirm receipt, keep you updated and credit you if you wish once it is fixed.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Quotes and billing

Proposals, pricing, invoices, VAT and agreements.

Every environment is different, so we price each engagement on its scope rather than a fixed list. You receive a written proposal with a fixed price, the number of days, deliverables and timeline. There are no hidden costs and no online payments on this site.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Most proposals are sent within two business days of receiving the scope. Complex programmes such as multi-site red teaming or platform development may need a short scoping call first.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Sign in to the client portal and open Quotes. Every request has a reference number and a status: received, under review, proposal sent, accepted or declined. You can reply with questions from the same place.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

After you accept a proposal we send an invoice by e-mail according to the agreed payment schedule. Payment is by bank transfer. Long projects are usually billed by milestone and subscriptions monthly or yearly.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Prices in proposals are shown without VAT. VAT is applied according to EU rules: for business clients in other EU countries with a valid VAT number the reverse charge mechanism usually applies.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Yes. Many clients book a yearly testing programme or a monthly engineering retainer with reserved capacity and better rates. Ask for it in the quote form and we will propose options.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

You can reschedule free of charge with reasonable notice, as defined in your proposal. Late cancellations may be billed for reserved days. Talk to us as early as possible and we will always try to find a new slot.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Client portal and tickets

Accounts, tickets, priorities, response times and files.

The client portal is your private workspace with Kodvalley. From one place you can:

  • Open and follow support tickets
  • Track quotes and proposals
  • Download reports and attachments shared in tickets
  • Leave a review after a project
Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Choose Client portal in the top bar and then Create account. Use your work e-mail so we can link your account to your organisation. If we already work together, your account may be created for you and you only need to set a password.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

On the sign-in page choose Forgot password and enter your e-mail. You will receive a reset link that is valid for 60 minutes. If the e-mail does not arrive, check your spam folder or ask your IT team to allow mail from kodvalley.com.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Sign in, choose New ticket, pick the department, set a priority and describe the issue. Good tickets include:

  • The URL, system or service affected
  • Steps to reproduce and what you expected to happen
  • Error messages, logs or screenshots

You will receive a reference number and an e-mail when we reply.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Each department has a response target during working hours:

  • Security Incident: 4 hours
  • Technical Support: 8 hours
  • Sales & Quotes and Billing: 24 hours
  • EU Projects: 48 hours

Contracts with a dedicated SLA override these targets. The deadline is shown on every ticket.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

  • Urgent: a production service is down or a security incident is ongoing
  • High: a key feature is broken with no workaround
  • Normal: a problem with a workaround, or a question
  • Low: a suggestion or cosmetic issue

Choosing the right priority helps us reach the most critical issues first.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Yes. You can attach up to 5 files of up to 10 MB each to every message. Supported types are images, PDF, TXT, LOG, CSV, JSON, XML, HAR and ZIP. Never send passwords in plain text; we will arrange a secure channel when credentials are needed.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

  • Open: we have received the ticket and are working on it
  • Answered: we replied and are waiting for you
  • Customer reply: you replied and the ball is with us
  • On hold: waiting on a third party or a planned window
  • Closed: the issue is resolved. Replying reopens it
Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Yes. Each colleague creates an account with their work e-mail. Ask us in a ticket to link the accounts to your organisation so tickets and quotes can be shared within your team.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Cloud, hosting and software

Managed hosting, migrations, backups and code ownership.

We set up and run your infrastructure: provisioning, security hardening, monitoring, backups, updates and incident response. You get one team that knows your application and your servers, with clear response times and monthly reporting.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

We work with OVHcloud, AWS, Microsoft Azure and Google Cloud, as well as private and on-premise environments. For EU data residency we usually recommend European data centres.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

In most cases yes. We plan migrations in stages, sync data in advance and switch traffic in an agreed window with a tested rollback plan. Any expected downtime is stated in the plan before we start.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Backups are automated, encrypted and stored in a separate location from the production systems. Retention follows your needs and restore tests are performed regularly so a backup is never assumed to work.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Unless agreed otherwise in the contract, you own the custom code we write for you once the related invoices are paid. Third-party and open-source components keep their own licences, which we document.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Yes. We offer maintenance plans that cover security updates, monitoring, bug fixes and a monthly budget for improvements. You can also call on us ticket by ticket without a plan.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

No. Client data is never used to train models for other clients. When we build AI features we agree with you which models are used, where they run and how data is protected, including private or EU-hosted options.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

EU projects and partnership

VET, CERV, Horizon Europe, Erasmus+ and REFEND.

We focus on Vocational Education and Training (VET), CERV (Citizens, Equality, Rights and Values), Horizon Europe and Erasmus+. Within consortia we usually lead digital work packages: platforms, cybersecurity, data and dissemination tools.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Use the application form on the Partner page. Tell us about your organisation, the call you are targeting and the role you imagine. Our partnerships team replies within a few working days, and earlier is always better than close to a deadline.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

REFEND is a European network of organisations working on education, inclusion and digital skills. Kodvalley is a member, which helps us form strong consortia and share results across countries. Our membership page is linked on the Partner page.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Yes. We contribute to proposal writing, especially the technical and digital parts, impact and dissemination. When we join a consortium as a partner, our contribution to the proposal is part of the partnership.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Typical deliverables include learning platforms, mobile apps, project websites, data dashboards, cybersecurity training and secure hosting for the whole project lifetime. Everything is designed to meet EU accessibility and data protection requirements.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Partners in our running Erasmus+ projects use a dedicated partner workspace, linked under Partner in the main menu. If you are a partner and do not have access yet, ask your project coordinator or open a ticket in the EU Projects department.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Privacy and data

GDPR, data processing agreements, data location and cookies.

Yes. Kodvalley is an EU company and processes personal data under the GDPR. We collect only what is needed, keep it secure and delete it when it is no longer required. Details are in our privacy policy.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Yes. When we process personal data on your behalf, for example in hosting or testing, we sign a data processing agreement (DPA). Ask for it during scoping and we will send our standard version or review yours.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

By default, client data is stored in data centres inside the European Union. If a project needs another location, it is agreed with you in writing beforehand.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

You can view and update your profile in the client portal at any time. To request a copy of your data, its correction or its deletion, write to support@kodvalley.com. We answer within the deadlines set by the GDPR.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

We use only essential cookies that keep the site secure and remember your preferences, such as your language and your session when signed in. We do not use advertising or tracking cookies.

Was this helpful?

Thank you for the feedback.

Sorry about that. Open a ticket and we will answer it personally. Open a ticket

Still need help?

Three steps to the right answer

Following these steps gets your question to the right specialist with everything they need, so you get a faster and better answer.

  1. Step 01

    Search the help centre

    Most questions about services, quotes and the portal are answered above.

    Back to search
  2. Recommended
    Step 02

    Open a support ticket

    The fastest way to reach our team. Every ticket is tracked, has a response target and reaches the right department.

    • Security Incident 4h
    • Technical Support 8h
    • Sales & Quotes 24h
    Open a ticket
  3. Step 03

    Check system status

    If a service seems down, check for a known incident or planned maintenance first.

    System status

Active security incident?

Open a Security Incident ticket for a 4-hour response target. Do not switch off affected systems before talking to us.

Report an incident

Last resort

Contact us directly

Could not sign in, or the question does not fit a ticket? Write or call us. Direct messages are answered within one business day.