Engagement, pricing & delivery FAQs
50 questions answered. More on how we work →
How does Bitkosh price a new software project?
Bitkosh offers three engagement models rather than fixed packages: a Fixed-Scope Project with a written quote and milestones, a Dedicated Squad billed monthly for ongoing product work, and Staff Augmentation billed per engineer per month. Every engagement starts with a free consultation and a written scope, so pricing reflects what you actually need rather than a generic tier or hourly guess.
What's the difference between a fixed-scope project and a dedicated squad?
A Fixed-Scope Project suits a clearly defined product or MVP: discovery, a written scope, milestone-based delivery and a fixed quote, ideal when you already know what you need. A Dedicated Squad suits evolving products: a cross-functional team of engineers, QA and design works as an extension of your team on a monthly basis, with sprint-based delivery and the ability to scale up or down.
When does staff augmentation make more sense than a dedicated squad?
Staff Augmentation fits when you have a specific skills gap rather than a whole project to hand off. Vetted engineers, from frontend to security to AI, plug directly into your existing team, tools and workflow at a per-engineer monthly rate, with flexible commitment. A Dedicated Squad instead brings a full cross-functional team of its own, better suited to ongoing delivery capacity.
How long does it take to get a written quote from Bitkosh?
Share your goals through the pricing or contact page and Bitkosh responds with a written scope and estimate within 48 hours, at no cost and with no obligation. This happens before any commercial engagement begins, so you can see the proposed scope and pricing before deciding whether to proceed.
Does Bitkosh charge by the hour or by milestone?
Neither model relies on hourly guesswork. Fixed-Scope Projects are billed against agreed milestones and fixed deliverables, while Dedicated Squad and Staff Augmentation engagements are billed monthly, per squad or per engineer. Across all models you get full visibility into progress and spend at every stage, rather than a running hourly meter.
Do startups get any special pricing terms at Bitkosh?
Yes. Bitkosh is itself a DPIIT-recognised startup, and it offers flexible arrangements for early-stage founders and pilot projects as part of its standard pricing approach. This sits alongside the free written quote and milestone-based billing offered to every client, so startups are not pushed into the same commercial terms as a large enterprise engagement.
What's included in every Bitkosh engagement regardless of model?
Whichever model you choose, Fixed-Scope, Dedicated Squad or Staff Augmentation, a few things are never optional extras: a written scope before work starts, ownership of your code and repository, security and compliance built into delivery, direct access to the engineers doing the work, sprint demos and progress reporting, and a post-launch support window.
Who owns the source code once a project is delivered?
You do. Bitkosh states plainly that your code and your repository belong to you as part of every engagement, whether it is a Fixed-Scope Project, a Dedicated Squad or Staff Augmentation. This is listed as a standard inclusion rather than something negotiated per contract, alongside a written scope, direct engineer access and progress reporting.
Is post-launch support part of the price or billed separately?
A post-launch support window is listed as a standard inclusion in every engagement model, not a separate line item to negotiate. For consultancy engagements specifically, Bitkosh includes a close-out walkthrough plus 30 days of follow-up support once deliverables are handed over, so support after go-live is built into the original scope.
Can we scale the team up or down once a project is underway?
Yes, within the Dedicated Squad model. It is built around sprint-based delivery with the explicit ability to scale the team up or down as your product's needs change, alongside direct communication and reporting. A Fixed-Scope Project instead works against a fixed set of milestones agreed up front rather than a flexing team size.
Can I license a Bitkosh product instead of commissioning custom software?
Yes. Bitkosh's own products, including the ISO ISMS Compliance Platform, Healthcare EHR, School Bus Manager and the AI GST suite among others, are available on subscription or perpetual licence rather than only as custom builds. You send your requirements and Bitkosh puts a number to it, with deployment available in the cloud or on-premise.
What determines the price of a Bitkosh product licence?
Licence pricing depends on the number of users, which modules you need, and whether you deploy in the cloud or on-premise. There is no fixed price list because those variables change the cost; instead you share your requirements and Bitkosh responds with a tailored number, the same way it handles a quote for a custom build.
Can Bitkosh products be deployed on our own servers instead of the cloud?
Yes. Bitkosh's own products are offered on subscription or perpetual licence with deployment in the cloud or on-premise, and pricing adjusts according to which option you choose along with your user count and module selection. Updates and support are included either way, and your data remains yours and exportable regardless of deployment choice.
Do software updates cost extra after buying a Bitkosh licence?
No, updates and support are included as part of a Bitkosh product licence, whether it is subscription or perpetual and whether deployed in the cloud or on-premise. You also only pay for the modules you actually use, and your data stays yours and exportable, rather than locked into the platform.
Is a security consultancy engagement a fixed project or an ongoing retainer?
Both are available. Bitkosh's consultancy work is delivered as project-based engagements, retainers or workshops, priced for Indian businesses with published rate cards rather than global consultancy rate cards. A project such as a gap assessment, penetration test or audit runs to a fixed scope, while a Virtual CISO retainer is ongoing advisory rather than a one-off deliverable.
What happens if the scope of a consultancy project changes partway through?
Every consultancy engagement starts with a written statement of work covering explicit inclusions, exclusions, timeline, pricing and acceptance criteria. If the scope needs to change once work is underway, it goes through a documented change request rather than turning into a surprise invoice, so pricing and timeline stay predictable through delivery.
What happens on the first call with Bitkosh?
An engineer, not a call-centre or generic sales representative, reviews your message and replies within a business day with first thoughts, questions and a suggested next step. From there a 30-minute call covers scope, timeline and a straight answer on feasibility, which is also the fastest route to a firm written quote.
How quickly does Bitkosh respond to a new project enquiry?
Bitkosh typically responds within one business day. An engineer reviews the message directly rather than an auto-responder, and the reply includes initial thoughts, any clarifying questions and a suggested next step, usually followed by an offer to book a 30-minute call to talk through scope and timeline.
What's the fastest way to get a firm number for our project?
A 30-minute call is the fastest route to a number. Alternatively you can send your requirements through the contact or pricing page and Bitkosh will come back with a written estimate, typically within 48 hours, with no cost or commitment attached to receiving it.
Does Bitkosh offer workshop or training engagements instead of full projects?
Yes. Alongside fixed-scope projects and ongoing retainers, Bitkosh offers standalone workshop and training engagements, including secure development training for engineering teams. This suits organisations that want to build in house security skills rather than outsource the work entirely. You can select workshop or training as the engagement type on the enquiry form, and it still gets a written scope before work begins, the same as any other engagement.
What if we're not sure of our project timeline yet?
That's fine, the enquiry form includes a just exploring option alongside ASAP, within one month, one to three months, and three to six months, so you are not forced to commit to a start date before the work has even been scoped. Tell Bitkosh where you are and the first call will focus on understanding your situation rather than pushing you toward a deadline.
What budget range should we have in mind before reaching out?
There is no minimum to enquire. The project form lets you select a range, under ₹1,00,000, ₹1,00,000 to ₹5,00,000, ₹5,00,000 to ₹15,00,000, or ₹15,00,000 and above, or you can choose prefer to discuss if you would rather share requirements first and get a written estimate back. Whichever you pick only shapes how the first conversation is framed, not whether Bitkosh responds.
Can we skip the enquiry form and just book a call directly?
Yes. If you would rather talk than type, you can skip the contact form entirely and book a 30-minute call straight from the website, or message Bitkosh on WhatsApp. It is the fastest route into a real conversation about scope and feasibility, and it runs alongside the form rather than replacing a proper review of your project.
Will contacting Bitkosh lead to repeated sales calls?
No. Bitkosh states plainly that there is no sales spam, and your details are used only to reply to your enquiry, in line with its privacy policy. An engineer reads your message and responds with next steps, rather than handing you off to a recurring outbound sales cadence.
Does an engineer or a salesperson review our project enquiry?
An engineer reviews it, not a call centre and not an auto-responder. Bitkosh routes enquiries to the right engineer rather than a generic sales team, so the first reply you get reflects an understanding of what you are actually building, including first thoughts, questions, and a suggested next step, usually within a business day.
Is Bitkosh reachable outside normal business hours?
Phone and WhatsApp support are staffed Monday to Saturday, 9:00 AM to 6:00 PM IST, so calls outside that window are better handled through the enquiry form or email. Bitkosh typically responds to written enquiries within one business day regardless of when they are sent, and delivery is remote and worldwide even though the team is based in Kataka, Odisha, India.
Can we see a live product demo before committing to anything?
Yes, and there is no obligation attached to it. Bitkosh runs a demo that walks through whichever product is most relevant to you, such as the ISO ISMS compliance platform, Healthcare EHR, the AI GST suite, or School Bus Manager, using your own workflows rather than a fixed script, so you can see how it actually behaves before deciding anything.
Who actually runs the product demo, sales or engineering?
An engineer who actually builds the product runs it, not a generic sales representative. You will be speaking with someone who understands the details of security audits, GST filings, patient records, or fleet operations depending on the product, and who can answer technical questions on the spot instead of escalating them elsewhere.
How long does a Bitkosh product demo usually run?
Most demos run 30 to 45 minutes, with direct access to the product engineers for the whole session rather than a scripted handoff partway through. You can book a slot directly or send the contact form instead, and Bitkosh will work around your schedule, with no obligation to proceed afterward.
Does Bitkosh work with partners who resell to their own clients?
Yes. If you serve your own clients and want to bring Bitkosh into that relationship, the team welcomes the conversation through its partnership inquiries channel. This sits separately from a direct project or product enquiry, so it is worth flagging upfront that you are exploring a partner arrangement rather than a one-off engagement.
Is Bitkosh's security consultancy only for large enterprises?
No. The consultancy practice is built around startups preparing for Series A due diligence, SMEs pursuing ISO 27001 or DPDP Act compliance, HealthTech and FinTech teams facing sector regulation, engineering leaders embedding security into the SDLC, and international SaaS companies needing offshore AppSec depth, so smaller and earlier stage organisations are a core part of who it is designed for, not an afterthought.
What happens on the discovery call before a consultancy scope is written?
Bitkosh runs an intake call to understand what is actually driving the engagement, whether that is a certification deadline, investor due diligence, an enterprise customer questionnaire, or a regulatory mandate, before anyone proposes a scope. That understanding shapes the written statement of work that follows, so scoping starts from your real business driver rather than a generic checklist.
Does Bitkosh give us a written statement of work before consultancy work starts?
Yes. Every consultancy engagement gets a written statement of work covering explicit inclusions and exclusions, timeline, pricing, and acceptance criteria before delivery begins. If anything needs to change later, it goes through a documented change request instead of turning into a surprise invoice partway through the engagement.
How are findings from a Bitkosh security assessment rated?
Findings come back severity rated using either the CVSS v4 scoring system or an ISO 27005 risk matrix, depending on what is being assessed. Each finding feeds into a prioritised remediation roadmap with named owners and timelines, so your team knows not just what is wrong but what to fix first and who is responsible for it.
How much follow-up support comes after a security assessment ends?
Every consultancy engagement includes a close-out walkthrough plus 30 days of follow-up support after delivery, on top of the peer-reviewed deliverables themselves. That window is meant for questions that come up once your team starts actually acting on the findings, rather than just a one-time handover meeting.
Will a Bitkosh security report be something we can actually show our board?
Yes, that is a deliverable by design. Alongside the severity rated findings and the remediation roadmap, every consultancy engagement includes an executive summary written so your board or customers can read it directly, instead of someone having to translate a technical report into business language afterward.
Does Bitkosh offer a fractional or part-time CISO service?
Yes, as a Virtual CISO retainer. It provides fractional security leadership covering board level governance, programme management, and regulatory interaction, aimed at organisations that need senior security direction without hiring a full-time CISO. It is structured as an ongoing retainer, billed monthly, rather than a one-off fixed-scope project.
Do old ISO 27001:2013 certificates need updating now?
Yes. The transition deadline for the 2013 edition of ISO 27001 has passed, so organisations still holding a legacy 2013 certificate now need re-certification against the 2022 edition, not a simple gap assessment. Bitkosh's ISO 27001 implementation service covers scope, risk assessment, the Statement of Applicability, policy suite, internal audit, and certification body liaison for that transition.
Can Bitkosh help us comply with multiple frameworks at once?
Yes, through a multi-framework crosswalk. Bitkosh maps overlapping controls across ISO 27001, SOC 2, HIPAA, GDPR, and the DPDP Act using its crosswalk engine, so your team can satisfy several regulatory or customer requirements from one body of evidence instead of running each framework as a separate project.
Do we own our data if we stop using a Bitkosh product?
Yes. Bitkosh product licences state that your data stays yours and remains exportable at any time, whether you are on a subscription or perpetual licence. This applies across the compliance platform, Healthcare EHR, AI GST suite and other Bitkosh products, so switching away or ending a licence does not lock your data in.
Can we license just one module instead of the whole product?
Yes. Bitkosh's product licensing is modular, so you pay only for the modules you actually use rather than a flat all-in fee for the whole platform. Whether you need one workflow from the Compliance Management Platform or a single module of the AI GST suite, tell us your requirements and the quote reflects that narrower scope.
Does Bitkosh only work with clients based in India?
No. Bitkosh is based in Kataka, Odisha, but delivers remotely to clients worldwide, working in IST (UTC+5:30) alongside whatever hours suit your team. The company is built in India but engages internationally across software development, product licensing and security consultancy, so location is not a barrier to working together.
Will we get to talk directly to the engineers, not just account managers?
Yes. Direct access to the engineers working on your project is included in every Bitkosh engagement, whether it's a fixed-scope build, a dedicated squad or staff augmentation. You are not routed through an account manager for technical questions; you speak with the people actually writing the code or running the assessment.
Is security part of every project or a separate add-on?
Security and compliance are built into every Bitkosh engagement by default, not sold as an optional extra. Whether you commission a fixed-scope build, a dedicated squad or staff augmentation, the written scope includes security and compliance considerations alongside milestone delivery, code ownership and a post-launch support window.
How often will we get updates on project progress?
Every Bitkosh engagement includes sprint demos and progress reporting as a standard part of delivery, not something you have to request. Dedicated squads work on sprint-based delivery with direct communication and reporting built in, so you see working software and status updates at regular intervals rather than only at the final handover.
Can Bitkosh audit our cloud security setup on AWS or Azure?
Yes. Bitkosh's Risk & Vendor Assessment service includes cloud posture audits benchmarked against CIS standards across AWS, Azure and GCP, alongside ISO 27005 or NIST-aligned risk registers. It's delivered as part of the same consultancy practice as ISO 27001, DPDP Act and vendor risk work, with a written scope and fixed price agreed up front.
Does Bitkosh help with DPDP Act 2023 data compliance?
Yes. Bitkosh's DPDP Act 2023 Compliance service covers data mapping, privacy impact assessments, consent management design, Data Protection Officer advisory and Significant Data Fiduciary obligations under India's data protection regime. It runs as a fixed-scope consultancy engagement with a written statement of work, the same delivery model used for our other advisory services.
Can Bitkosh help us prepare for investor due diligence before a funding round?
Yes, that's one of the situations Bitkosh's security consultancy is built for. Startups preparing for Series A due diligence are named alongside SMEs pursuing ISO 27001 or DPDP Act compliance as typical clients for this practice. The engagement still follows the same discovery call, fixed-scope statement of work and evidence-based delivery as any other consultancy project.
Is Bitkosh's consultancy pricing based on standard rate cards?
Yes. Bitkosh publishes rate cards for its cyber security and secure development advisory work and prices them for Indian businesses rather than matching global consultancy rate cards. Combined with a fixed-price statement of work agreed before delivery starts, this is meant to keep costs predictable and avoid scope-creep surprises partway through an engagement.
What should we include when filling out Bitkosh's project enquiry form?
Fill in your work email, a short description of what you need, and select the closest options from the dropdowns: how we can help, engagement type (project, retainer or workshop), budget range and timeline. The more you add in the project details field, the sharper the written scope we send back will be, so include your goals and any constraints you already know.