Full scope, contracted through our US entity. Federal, ITAR and PHI work we decline.
Full scope on the mainland, through our own UAE entity. Health and government data we decline.
Full scope for private-sector clients, under English law if you want it. Public sector and CNI we decline.
Cyber Resilience Act readiness, and build work in English. Managed services and DORA we decline.
United States
Full scope, contracted through our US entity. Federal, ITAR and PHI work we decline.
Our commercial HQ is in Scottsdale, we hold a US EOR entity, and we invoice in USD on Net-15. Every compliance, security, build and talent service is deliverable here. The exclusions are narrow, legal, and listed below.
US entity (Scottsdale, Arizona). Direct EOR entity. USD invoicing, Net-15.
No US privacy regime imposes data localisation. Our MSA carries CCPA/CPRA service-provider clauses and an addendum covering the twenty state comprehensive privacy regimes now in force.
US federal, defense, ITAR/EAR-controlled and CUI-touching work
US-person restrictions are structural rather than procedural. Serving this properly would require a separate US-cleared subsidiary, which we do not have and are not building.
CMMC readiness
Phase II was suspended with immediate effect on 13 July 2026 pending review, with no announced restart date. Building against it now would be speculative.
Engagements requiring access to protected health information
HIPAA itself does not prohibit offshore processing under a business associate agreement, but many payer and provider contracts ban it outright, and HIPAA's enforcement reach over an Indian entity is untested. We scope healthcare engagements as no-PHI-in-scope, which usually removes most of the value — so we will normally tell you to use someone onshore.
UAE & GCC
Full scope on the mainland, through our own UAE entity. Health and government data we decline.
The National Cyber Security Strategy made resilience mandatory rather than advisory. NESA, DESC ISR v3 and PDPL now bite on architecture, not policy. Our Dubai office runs delivery and account management; engineering is delivered from Mumbai, and that is in the MSA because your regulator will ask.
UAE presence (Dubai) with a direct EOR entity. Mainland commercial work is contracted from the UAE; free-zone entities are handled case by case.
Federal PDPL has published no adequacy list and its Executive Regulations remain unissued, so we treat the federal transfer regime as under-specified rather than permissive. DIFC and ADGM are materially stricter: neither lists India as an adequate jurisdiction, so Article 42 safeguards and a documented recipient-jurisdiction assessment apply where a free-zone entity is in scope.
Anything touching health data
UAE law prohibits health data being stored, processed, generated or transferred outside the country. Our engineering is delivered from Mumbai, so there is no scoping arrangement that fixes this.
Dubai government data and DESC-regulated pipelines requiring in-country processing
DESC ISR v3 requires in-country processing for these. We will not propose a workaround for a residency requirement.
Financial-services customer data required to be stored in-country
Same reason: a hard localisation requirement that offshore delivery cannot satisfy.
Saudi Arabia as a primary market
NCA ECC-2's tiered model, in-Kingdom presence expectations and localisation make it a Riyadh-entity market. We take KSA only as pull-through from a UAE client with a Saudi subsidiary, delivered under the UAE contract.
United Kingdom
Full scope for private-sector clients, under English law if you want it. Public sector and CNI we decline.
53,699 Cyber Essentials certificates were issued in twelve months, and every ISO 27001:2013 certificate expired on 31 October 2025. Private-sector work we take at full scope. Public sector and critical national infrastructure we decline, because SC clearance requires roughly five years of UK residency and our engineers are in Mumbai.
No UK entity, deliberately. B2B services from a non-UK supplier are handled by the customer under the VAT reverse charge, so no UK VAT registration is required. We can contract under English law with English courts on request.
India is not on the UK adequacy list, so transfers run on the UK IDTA — or the Addendum to the EU SCCs — with a documented Transfer Risk Assessment. The ICO's updated international transfer guidance took effect 5 February 2026.
All UK public-sector and CNI work
Public contracts require contractual UK data residency covering support escalation, not merely UK hosting. G-Cloud 15 makes Cyber Essentials Plus mandatory for cloud suppliers. We hold neither, and our India-based engineers cannot obtain SC clearance, which requires roughly five years of UK residency.
CHECK IT Health Checks and anything touching a PSN-connected body
Every tester must hold SC clearance and the company must be NCSC-approved. This is structurally impossible from Mumbai, so we refer it rather than imply we can.
Issuing Cyber Essentials or Cyber Essentials Plus certificates
Certificates come only from an IASME-licensed certification body. We are not one — checkable in IASME's public directory — so we prepare you and introduce you to one.
Penetration testing under our own name
We hold no CREST or CHECK accreditation. PPN 014 makes CREST a requirement for government testing. We refer a named accredited partner and disclose the subcontract in writing.
Managed services framed as ongoing administration
The Cyber Security and Resilience Bill defines a relevant managed service provider to include firms providing ongoing support, maintenance, monitoring or active administration of a customer's systems accessed remotely. We contract UK delivery as fixed-scope, change-controlled projects, which sits outside that definition.
European Union
Cyber Resilience Act readiness, and build work in English. Managed services and DORA we decline.
We take one thing in the EU and decline the rest. Any engagement touching EU personal data needs SCCs, a Transfer Impact Assessment and supplementary measures, because India has no adequacy decision. Cyber Resilience Act readiness touches no personal data, so none of that applies — which is why it is the EU engagement we recommend.
No EU establishment, deliberately. Article 196 reverse charge means the B2B customer self-accounts for VAT, so no registration is required. EU work is delivered as a fixed-scope engineering project from our US entity.
India has no EU adequacy decision, and the published timeline puts a possible decision no earlier than 2028–29. Any engagement touching EU personal data therefore needs an Article 28 processor agreement, SCC Module 2 or 3, a documented Transfer Impact Assessment and supplementary measures. We work from pseudonymised or synthetic data in development environments, which is correct practice anyway and collapses most of the question.
Anything framed as a managed security service
NIS2 Article 26(3) requires a non-EU entity offering in-scope services in the Union — explicitly including managed security services — to designate a representative in a Member State, whose authority then becomes our lead supervisor for incident notification and compliance assessment. Designation does not shield us from direct liability. No single engagement is worth acquiring a supervisory regime, so anything with ongoing security administration is declined and offered as a fixed-scope Remediation Pod instead.
EU AI Act high-risk readiness
Only Article 50 transparency and Article 4 AI literacy are live; the high-risk obligations were deferred to December 2027 and August 2028. Nobody needs a programme for a disclosure label. Ask us again in 2027.
Managed EOR through our own entities
We hold direct EOR entities in India, the UAE and the USA only. EU employment runs through partners, which means it is not a one-contract-one-invoice engagement and we will say so.
Work requiring delivery in German, French, Italian, Dutch or Spanish
We have no non-English sales or delivery capability, and our AEO/SEO/GEO practice does not operate in those languages. NIS2 and CRA buying frequently happens in them.
DORA engagements
Threat-led penetration testing under DORA requires TIBER-EU-accredited red teams, which we are not. Where you are an ICT third party to a DORA entity rather than in scope yourself, that is a SOC 2 or ISO 27001 conversation and we can help with it.
True in every market
We never audit, attest or certify
Only a licensed CPA firm can attest SOC 2. Only a UKAS- or ANAB-accredited body can certify ISO 27001 or ISO 42001. Only an IASME-licensed body issues Cyber Essentials. And under ISO/IEC 17021 the body that certifies you is barred from having consulted you — which is precisely why the implementation work is available to us. We hold no accreditations. On this side of the wall that is the qualification, not the gap.
We take no fee from any auditor
withRemote receives no fee, commission, rebate or other consideration from any auditor or certification body to which it refers a client, and confirms this in writing to both the client and the auditor.
No detection, no response, no SLA
We sell no monitoring, no managed detection, no security operations centre and no incident response retainer, and we carry no availability or response duty. Turnaround targets on each service page are targets, not guarantees.
Your approver merges every change
On any engagement touching your systems, we write the change and your named approver merges it, inside your change window, with a documented rollback. Our liability for business interruption arising from changes you approved is excluded — because the dominant risk on remediation work is an outage, not a breach.
No testing without written authorisation
No production testing proceeds without signed Rules of Engagement and a countersigned authorisation letter from a verified asset owner, plus third-party authorisation where the systems sit with a cloud provider. Without that paperwork, testing is a criminal offence in every jurisdiction we operate in, regardless of intent.
We disclose our own jurisdiction
Engineering is delivered from Mumbai. India's CERT-In directions impose a six-hour incident reporting duty and in-country log retention on Indian entities, which is why client findings, logs and evidence live in a client-controlled tenant that we access rather than on our systems. We disclose this in the MSA rather than let you discover it.
One price list, priced in USD
We publish one set of prices and do not run a per-market rate card. Invoicing is in USD with no FX surcharge and the rate is fixed for the contract term. GCC engagements commonly settle on longer terms than our standard Net-15 and we will agree that up front rather than pretend otherwise.
What procurement usually asks next.
A security buyer’s procurement team will ask every one of these questions. We would rather answer them on a page you can read before the call than in a questionnaire after it.
If your situation is not covered here — a jurisdiction we have not listed, a residency clause we have not addressed, a regime we have read wrong — tell us and we will say plainly whether we can take the work.