Frequently asked questions
IT and cybersecurity questions, answered plainly.
Pricing, timelines, compliance frameworks and how we actually work — the things Canadian businesses ask us before starting an engagement.
General
- What does Gpenda Technologies do?
- Gpenda Technologies Inc. is a Toronto-based IT and cybersecurity firm. We cover penetration testing and VAPT, incident response, security compliance, security awareness training, IT consulting and infrastructure, automation, custom software and SaaS development, and website development with SEO.
- Where are you located and which areas do you serve?
- Our office is at 561 Sherbourne Street, Toronto, ON M4X 0A1, Canada. We work on-site across the Greater Toronto Area and remotely with clients throughout Canada.
- What are your business hours?
- Mon–Sat · 8:00 AM – 7:00 PM ET. Reach us at +1 437-320-4284 or inquiry@gpendatechnologies.ca. Incident response retainers include agreed response times outside these hours.
- Is the first consultation free?
- Yes. Discovery calls and scoping cost nothing and carry no obligation. You receive a written scope with deliverables, timeline and cost before any work begins.
- Do you work with small businesses, or only enterprises?
- Most of our clients are small and mid-sized Canadian businesses and startups. Engagements are scoped to your size and budget rather than sold as fixed packages.
- Can you help if we already have an IT provider?
- Yes. We frequently work alongside an existing MSP or internal IT team, usually on security, compliance or development work they don't cover.
- How do we report a suspected breach or urgent security issue?
- Call +1 437-320-4284 immediately and email inquiry@gpendatechnologies.ca. Do not wipe or reboot affected machines before speaking with us — that destroys the evidence needed to understand the incident.
Scripting & Automation
View the scripting & automation service →- What kinds of tasks are worth automating?
- Anything repeated, rule-based and error-prone — onboarding, reporting, backups, data cleanup, provisioning, alerting. If a person does it weekly from a checklist, it's a candidate.
- Which languages and platforms do you use?
- PowerShell, Python and Bash most often, plus cloud-native tooling and API integrations across Windows, macOS, Linux and major cloud providers.
- Who owns the scripts?
- You do. Everything is delivered as documented source you keep, with no lock-in.
Windows Custom Image Creation
View the windows custom image creation service →- How much time does a custom image save?
- Teams typically go from hours of per-machine setup to a fully configured device in well under an hour, with identical configuration every time.
- Does it work with Intune or SCCM?
- Yes. We build for whichever deployment stack you use, including Autopilot-based provisioning.
- Is the image hardened for security?
- Yes — baseline hardening, disabled legacy protocols, patched components and your policy baseline are part of the build.
Security Awareness Training
View the security awareness training service →- How often should staff be trained?
- An annual session plus quarterly phishing simulations is the practical baseline, and it satisfies most compliance frameworks.
- Is the training remote or on-site?
- Both. We deliver live remote sessions across Canada and on-site in the Greater Toronto Area.
- Do you provide certificates for compliance evidence?
- Yes — attendance records, per-user completion and campaign metrics suitable as audit evidence.
Incident Response
View the incident response service →- We think we're being attacked right now — what do we do?
- Call +1 437-320-4284 immediately. Do not wipe or reboot affected machines: that destroys the evidence needed to understand the breach. We'll walk you through containment on the call.
- Can you help us recover from ransomware without paying?
- Often, yes — through backup validation, shadow copies, known decryptors and rebuilding from clean images. We assess recovery options before anyone discusses payment.
- Do you handle breach notification obligations?
- We support them. Our forensic findings document what data was affected, which is the basis for PIPEDA, GDPR and contractual notification decisions made with your legal counsel.
- Can we retain you before an incident?
- Yes. A retainer buys guaranteed response times and means we already know your environment when the call comes in.
Vulnerability Assessment & Penetration Testing (VAPT)
View the vulnerability assessment & penetration testing (vapt) service →- How much does a penetration test cost in Canada?
- Cost depends on scope — the number of applications, IP ranges and user roles in play. Most small-business web app tests land in the low four figures; a scoping call gives you a fixed quote before any work starts.
- What's the difference between a vulnerability assessment and a penetration test?
- A vulnerability assessment enumerates known weaknesses, largely with tooling. A penetration test goes further: our testers manually exploit those weaknesses and chain them together to show real business impact.
- Will testing take my systems down?
- No. We agree safety rules and testing windows upfront, avoid destructive payloads on production, and stay reachable throughout the engagement.
- Do you provide a report we can share with clients or auditors?
- Yes. You get a full technical report plus a clean executive summary and attestation letter suitable for customers, auditors and insurers.
- How often should we test?
- At least annually, and after any significant release or infrastructure change. Frameworks like PCI DSS and SOC 2 expect a documented annual cadence.
Operating Systems: Installation, Maintenance & Custom OS
View the operating systems: installation, maintenance & custom os service →- Will we lose data during a migration?
- No. Profiles and data are backed up and verified before anything is reinstalled, and restoration is checked before we close the job.
- Can you support Linux servers as well as desktops?
- Yes — server provisioning, hardening and ongoing maintenance across major distributions.
- Do you handle licensing?
- We review your licensing position as part of the assessment and flag anything non-compliant before deployment.
Equipment Setup — Software & Hardware
View the equipment setup — software & hardware service →- Do you supply the hardware or do we buy it?
- Either. We can spec and procure, or configure equipment you've already purchased.
- Can you set up secure guest Wi-Fi and segmentation?
- Yes. Network segmentation, guest isolation and firewall rules are part of a proper install, not an add-on.
- Do you cover locations outside Toronto?
- On-site work is focused on the Greater Toronto Area; remote configuration and shipped, pre-imaged devices work anywhere in Canada.
IT Consultation
View the it consultation service →- Do you offer ongoing managed IT support?
- Yes — retainer-based support alongside project work, scoped to your headcount and hours.
- Can you reduce our IT spend?
- Usually. Duplicate licensing, oversized cloud instances and unused SaaS seats are the most common savings we find in an audit.
- Do you work on-site in Toronto?
- Yes, on-site across the Greater Toronto Area, and remote everywhere else in Canada.
Cybersecurity Consultation
View the cybersecurity consultation service →- What does a virtual CISO do?
- Provides the security leadership a full-time CISO would — strategy, risk decisions, policy, vendor reviews and board reporting — on a fraction of the cost and hours.
- We're a 15-person company. Is this overkill?
- No. Smaller teams are targeted precisely because they lack coverage. The engagement scales down to what genuinely reduces your risk.
- Do you sell security products?
- We're vendor-neutral. Recommendations are based on what fits your environment and budget, not on reseller margin.
Development — Databases, SaaS, Web & Native Apps
View the development — databases, saas, web & native apps service →- How much does it cost to build a SaaS product?
- A focused MVP is typically a fixed-scope project in the five-figure range; full multi-tenant platforms scale from there. Scoping is free and gives you a written estimate.
- Do you build native mobile apps?
- Yes — iOS, Android and desktop, either natively or cross-platform depending on what your product actually needs.
- Who owns the code?
- You own all source code and infrastructure. We hand over repositories and documentation at launch.
- Can you take over an existing codebase?
- Yes. We start with a technical and security review, then give you an honest assessment of whether to extend or rebuild.
Business & Enterprise Software
View the business & enterprise software service →- Should we buy software or build it?
- Buy whenever a mature product covers 80% of the need. We recommend building only where the process is genuinely specific to your business and worth the ownership cost.
- Can you integrate systems that have no public API?
- Often yes, via database-level integration, file exchange, or automation layers — we assess feasibility before quoting.
- Do you provide staff training?
- Yes. Rollout includes training sessions and written documentation for each affected team.
Website Development & SEO
View the website development & seo service →- How much does a business website cost?
- A standard business site is CAD $2,000 upfront plus $100/month for maintenance; e-commerce builds start at CAD $3,000 upfront. Custom scopes are quoted after a short call.
- How long until SEO shows results?
- Technical fixes can move rankings within weeks. Competitive terms usually take three to six months of consistent publishing and link acquisition — anyone promising page one in days is selling you something.
- Do you handle e-commerce payments and tax setup?
- Yes — secure payment integration, product catalogue, shipping and tax configuration are part of the storefront build.
- What is the automated SEO content engine?
- A system built into your site that researches, drafts and publishes routine blog content on schedule, so the site keeps gaining topical coverage without a full-time writer.
Security Compliance
View the security compliance service →- How long does SOC 2 readiness take?
- Most small teams reach readiness in 8–16 weeks depending on how much tooling and documentation already exists. The gap assessment gives you a dated plan in week one.
- Which framework does my business actually need?
- It depends on your customers and data. Enterprise SaaS buyers usually ask for SOC 2; ISO 27001 travels better internationally; card data means PCI DSS; Canadian personal data means PIPEDA. We map it in the first session.
- Can you fix the gaps, or only report them?
- We do both. Remediation — hardening, logging, access control, policy writing, secure redesign of software — is the core of the engagement.
- Do you work with vibe-coded or AI-built SaaS products?
- Yes, frequently. We review the generated stack, close the security holes and redesign the parts that can't pass an audit as built.
Custom IT & Cybersecurity Requests
View the custom it & cybersecurity requests service →- What kinds of projects do you take on?
- Anything in business technology, IT or cybersecurity — legacy migrations, one-off integrations, security reviews, technical due diligence, interim technical leadership.
- Do you work on retainer?
- Yes — fixed-scope projects, monthly retainers and staff augmentation are all available.
- Is scoping free?
- Yes. The discovery call and written scope cost nothing and carry no obligation.
Business Analysis & Digital Growth
View the business analysis & digital growth service →- What's included in the digital presence audit?
- A structured review of your website, technical and on-page SEO, social channels, brand consistency and conversion path, delivered as a prioritised fix list.
- Do you rebuild the website or just advise?
- Both are available. Where the audit shows the current site is the constraint, we rebuild it; where it isn't, we fix what's actually limiting growth.
- How do you measure success?
- Against agreed baselines for qualified traffic, conversion rate and revenue — set at the start of the engagement.
