Help centre
How can we help?
Search our answers first. Most questions are solved here in seconds, and our team is one ticket away when they are not.
- 51 answers
- 3 languages
- 4-hour incident response
Browse by topic
- Getting started Who we are, how to start and what to expect. 6 answers
- Penetration testing and security Methodology, scope, reports, re-tests and incidents. 11 answers
- Quotes and billing Proposals, pricing, invoices, VAT and agreements. 7 answers
- Client portal and tickets Accounts, tickets, priorities, response times and files. 9 answers
- Cloud, hosting and software Managed hosting, migrations, backups and code ownership. 7 answers
- EU projects and partnership VET, CERV, Horizon Europe, Erasmus+ and REFEND. 6 answers
- Privacy and data GDPR, data processing agreements, data location and cookies. 5 answers
- Still need help? The fastest way to reach our team. Every ticket is tracked, has a response target and reaches the right department. Open a ticket
Answers matching your search:
We could not find an answer for that.
Try a shorter or different word. If the question is specific to your project, our team will answer it in a ticket.
Getting started
Who we are, how to start and what to expect.
Kodvalley is a European technology group based in Vilnius, Lithuania. We work in four areas:
- Cybersecurity: manual penetration testing, red teaming and security reviews
- Software engineering: web platforms, e-commerce, mobile apps and reverse engineering
- Cloud and AI: cloud integration, DevOps, managed hosting and machine learning
- EU projects: VET, CERV, Horizon Europe and Erasmus+ partnerships
Our product brands Improj, Visalley and Jairno grow out of the same engineering team.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
The fastest route is the quote form. Tell us what you need, the size of the environment and any deadline. A specialist reviews it, may ask a few scoping questions and sends a fixed-scope proposal.
If you are not sure which service fits, describe the goal in plain words. Scoping is part of our job and costs you nothing.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
We work with companies of every size, public bodies, foundations, schools and universities across the EU and beyond. Engagements range from a single web application test for a start-up to multi-year platform development and EU-funded consortia.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Our team works in English, Turkish and Lithuanian. Reports, proposals and support are available in any of the three. Technical deliverables are written in English by default unless you ask otherwise.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Our registered office is at Laisvės pr. 60-1107, Vilnius, Lithuania. Most work is delivered remotely across Europe.
On-site work such as internal network testing, workshops or project meetings is available on request and scheduled in the proposal.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Our legal name is MB Kodvalley, company code 306329532, registered in Lithuania. The full details, including address and contacts, are in the footer of every page. Our team can also send a supplier information sheet on request through the quote or contact form.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Penetration testing and security
Methodology, scope, reports, re-tests and incidents.
A scanner looks for known patterns and reports possible issues. A penetration test is performed by a person who thinks like an attacker: they confirm each finding, chain weaknesses together and exploit business logic that no tool understands.
Every finding in our reports comes with a working proof of concept, a risk rating and clear remediation steps.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Our testing is aligned with OWASP (Web Security Testing Guide, API Security Top 10, MASVS), PTES and NIST SP 800-115. Findings are scored with CVSS.
If you need mapping to a specific framework such as ISO 27001, SOC 2, PCI DSS, DORA or NIS2, tell us during scoping and we include it in the report.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
- Web applications and APIs (REST, GraphQL, SOAP)
- Mobile apps on iOS and Android
- External and internal networks, Active Directory and Wi-Fi
- Cloud environments on AWS, Azure, Google Cloud and OVHcloud
- Red team exercises and social engineering, including phishing simulations
- Source code reviews and architecture reviews
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
A typical web application test takes three to ten working days depending on the number of roles, features and integrations. Network and red team engagements take longer. The exact number of days is fixed in your proposal before any work begins.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
We plan every engagement to avoid disruption. Rules of engagement agree the scope, time windows, test accounts and an emergency contact on both sides. Destructive tests and denial of service are excluded unless you explicitly ask for them.
If you prefer, we can test a staging environment that mirrors production.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
- A signed authorisation and agreed scope (URLs, IP ranges or apps)
- Test accounts for each user role
- Testing windows and any systems that must not be touched
- A technical contact reachable during testing
We send a short checklist with the proposal so nothing is missed.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
You receive two layers in one document:
- An executive summary written for management, with overall risk and priorities
- A technical section with every finding, its CVSS score, evidence, proof of concept and remediation guidance
A debrief call is included to walk your team through the results.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Yes. Once your team has fixed the findings, we re-test them free of charge within the agreed period and issue an updated report with the new status of each issue. Many clients use this updated report as evidence for auditors and customers.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
An NDA can be signed before scoping. Findings and evidence are stored encrypted, shared only through the client portal or encrypted channels, and deleted after the retention period agreed in the contract. Testers access only what is in scope.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Open a ticket in the client portal and choose the Security Incident department. These tickets carry a 4-hour response target and reach our security team immediately.
If you cannot sign in, use the contact page and mark the message as urgent. Do not switch off affected systems before talking to us, since this can destroy evidence.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Thank you for helping. Please report it through the contact page with clear steps to reproduce, and do not access data beyond what is needed to show the issue. We confirm receipt, keep you updated and credit you if you wish once it is fixed.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Quotes and billing
Proposals, pricing, invoices, VAT and agreements.
Every environment is different, so we price each engagement on its scope rather than a fixed list. You receive a written proposal with a fixed price, the number of days, deliverables and timeline. There are no hidden costs and no online payments on this site.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Most proposals are sent within two business days of receiving the scope. Complex programmes such as multi-site red teaming or platform development may need a short scoping call first.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Sign in to the client portal and open Quotes. Every request has a reference number and a status: received, under review, proposal sent, accepted or declined. You can reply with questions from the same place.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
After you accept a proposal we send an invoice by e-mail according to the agreed payment schedule. Payment is by bank transfer. Long projects are usually billed by milestone and subscriptions monthly or yearly.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Prices in proposals are shown without VAT. VAT is applied according to EU rules: for business clients in other EU countries with a valid VAT number the reverse charge mechanism usually applies.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Yes. Many clients book a yearly testing programme or a monthly engineering retainer with reserved capacity and better rates. Ask for it in the quote form and we will propose options.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
You can reschedule free of charge with reasonable notice, as defined in your proposal. Late cancellations may be billed for reserved days. Talk to us as early as possible and we will always try to find a new slot.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Client portal and tickets
Accounts, tickets, priorities, response times and files.
The client portal is your private workspace with Kodvalley. From one place you can:
- Open and follow support tickets
- Track quotes and proposals
- Download reports and attachments shared in tickets
- Leave a review after a project
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Choose Client portal in the top bar and then Create account. Use your work e-mail so we can link your account to your organisation. If we already work together, your account may be created for you and you only need to set a password.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
On the sign-in page choose Forgot password and enter your e-mail. You will receive a reset link that is valid for 60 minutes. If the e-mail does not arrive, check your spam folder or ask your IT team to allow mail from kodvalley.com.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Sign in, choose New ticket, pick the department, set a priority and describe the issue. Good tickets include:
- The URL, system or service affected
- Steps to reproduce and what you expected to happen
- Error messages, logs or screenshots
You will receive a reference number and an e-mail when we reply.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Each department has a response target during working hours:
- Security Incident: 4 hours
- Technical Support: 8 hours
- Sales & Quotes and Billing: 24 hours
- EU Projects: 48 hours
Contracts with a dedicated SLA override these targets. The deadline is shown on every ticket.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
- Urgent: a production service is down or a security incident is ongoing
- High: a key feature is broken with no workaround
- Normal: a problem with a workaround, or a question
- Low: a suggestion or cosmetic issue
Choosing the right priority helps us reach the most critical issues first.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Yes. You can attach up to 5 files of up to 10 MB each to every message. Supported types are images, PDF, TXT, LOG, CSV, JSON, XML, HAR and ZIP. Never send passwords in plain text; we will arrange a secure channel when credentials are needed.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
- Open: we have received the ticket and are working on it
- Answered: we replied and are waiting for you
- Customer reply: you replied and the ball is with us
- On hold: waiting on a third party or a planned window
- Closed: the issue is resolved. Replying reopens it
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Yes. Each colleague creates an account with their work e-mail. Ask us in a ticket to link the accounts to your organisation so tickets and quotes can be shared within your team.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Cloud, hosting and software
Managed hosting, migrations, backups and code ownership.
We set up and run your infrastructure: provisioning, security hardening, monitoring, backups, updates and incident response. You get one team that knows your application and your servers, with clear response times and monthly reporting.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
We work with OVHcloud, AWS, Microsoft Azure and Google Cloud, as well as private and on-premise environments. For EU data residency we usually recommend European data centres.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
In most cases yes. We plan migrations in stages, sync data in advance and switch traffic in an agreed window with a tested rollback plan. Any expected downtime is stated in the plan before we start.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Backups are automated, encrypted and stored in a separate location from the production systems. Retention follows your needs and restore tests are performed regularly so a backup is never assumed to work.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Unless agreed otherwise in the contract, you own the custom code we write for you once the related invoices are paid. Third-party and open-source components keep their own licences, which we document.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Yes. We offer maintenance plans that cover security updates, monitoring, bug fixes and a monthly budget for improvements. You can also call on us ticket by ticket without a plan.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
No. Client data is never used to train models for other clients. When we build AI features we agree with you which models are used, where they run and how data is protected, including private or EU-hosted options.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
EU projects and partnership
VET, CERV, Horizon Europe, Erasmus+ and REFEND.
We focus on Vocational Education and Training (VET), CERV (Citizens, Equality, Rights and Values), Horizon Europe and Erasmus+. Within consortia we usually lead digital work packages: platforms, cybersecurity, data and dissemination tools.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Use the application form on the Partner page. Tell us about your organisation, the call you are targeting and the role you imagine. Our partnerships team replies within a few working days, and earlier is always better than close to a deadline.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
REFEND is a European network of organisations working on education, inclusion and digital skills. Kodvalley is a member, which helps us form strong consortia and share results across countries. Our membership page is linked on the Partner page.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Yes. We contribute to proposal writing, especially the technical and digital parts, impact and dissemination. When we join a consortium as a partner, our contribution to the proposal is part of the partnership.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Typical deliverables include learning platforms, mobile apps, project websites, data dashboards, cybersecurity training and secure hosting for the whole project lifetime. Everything is designed to meet EU accessibility and data protection requirements.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Partners in our running Erasmus+ projects use a dedicated partner workspace, linked under Partner in the main menu. If you are a partner and do not have access yet, ask your project coordinator or open a ticket in the EU Projects department.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Privacy and data
GDPR, data processing agreements, data location and cookies.
Yes. Kodvalley is an EU company and processes personal data under the GDPR. We collect only what is needed, keep it secure and delete it when it is no longer required. Details are in our privacy policy.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Yes. When we process personal data on your behalf, for example in hosting or testing, we sign a data processing agreement (DPA). Ask for it during scoping and we will send our standard version or review yours.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
By default, client data is stored in data centres inside the European Union. If a project needs another location, it is agreed with you in writing beforehand.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
You can view and update your profile in the client portal at any time. To request a copy of your data, its correction or its deletion, write to support@kodvalley.com. We answer within the deadlines set by the GDPR.
Thank you for the feedback.
Sorry about that. Open a ticket and we will answer it personally. Open a ticket
Still need help?
Three steps to the right answer
Following these steps gets your question to the right specialist with everything they need, so you get a faster and better answer.
-
Step 01
Search the help centre
Most questions about services, quotes and the portal are answered above.
Back to search -
Recommended
Step 02
Open a support ticket
The fastest way to reach our team. Every ticket is tracked, has a response target and reaches the right department.
- Security Incident 4h
- Technical Support 8h
- Sales & Quotes 24h
-
Step 03
Check system status
If a service seems down, check for a known incident or planned maintenance first.
System status
Active security incident?
Open a Security Incident ticket for a 4-hour response target. Do not switch off affected systems before talking to us.
Last resort
Contact us directly
Could not sign in, or the question does not fit a ticket? Write or call us. Direct messages are answered within one business day.