Frequently Asked Questions
Answers to common questions about our services, engagement models, pricing, security standards, and how we work with clients - grouped by topic.
Engagement & Pricing
We start with a discovery conversation to understand your specific challenge - whether that's a platform to build, a security vulnerability, a need for automation, or a digital investigation. From there we propose a written scope of work with deliverables, timeline, and pricing, so you know exactly what you are buying before any commitment.
We work with organizations and individuals of all sizes. Our engagement models are flexible - from building standalone products and tools for small businesses to conducting security assessments and multi-month platform builds for larger organizations and institutions.
Three main models: project-based engagements for specific builds or audits with a defined scope and price; retainer models for ongoing development, security monitoring, or bot maintenance; and rapid-response contracts for urgent investigations or incident response where time matters most.
Pricing depends on the service. Development projects and security audits are typically fixed-scope and project-priced. Investigations can be hourly or retainer-based depending on complexity. We prioritize transparency: you receive a written quote before work begins, and scope changes are agreed before they are billed.
Engagements vary widely with scope. A focused security assessment or a small tool sits at the lower end; a complete web or mobile platform with payments, roles, and reporting is a larger multi-month investment. Because we are based in Bamenda, Cameroon, our rates are competitive with regional and international alternatives - tell us your budget range and we will tell you honestly what it can achieve.
Our headquarters is on Commercial Avenue in Bamenda, Cameroon. We work with clients across Cameroon - including Douala and Yaoundé - and across Central Africa, and we deliver remote engagements for clients further afield. Meetings happen in person, by phone, or by video call, whatever suits your team.
Process & Delivery
We operate across seven core capabilities: Secure Software Development, Cybersecurity Engineering, Web Application Development, Mobile Application Development, Security Tool Development, Digital Investigation, and Bot Development & Automation. Most real projects combine several - a mobile app with a secure backend and payment automation, for example.
We have deep, product-proven expertise in fintech and microfinance (escrow, payment aggregation, core banking), education and healthcare administration, public safety, agriculture marketplaces, and retail/commerce. Our security and software engineering capabilities transfer effectively to almost any sector.
Three habits: we agree on scope in writing before building; we deliver working software in short cycles so you see progress early and can redirect cheaply; and we test - functionally and for security - before launch, not after. Investigations and audits follow rigorous documented procedures with regular reporting.
Our core stack is Rust (Axum), TypeScript/Node.js, React and Next.js, Flutter, and Python, over PostgreSQL, SQLite, and Firebase. For security and forensics work we use industry-standard tooling such as Burp Suite, Maltego, Wireshark, and blockchain analysis platforms, alongside custom tools we build ourselves.
Yes. Mobile money integration is standard in our products: we integrate MTN Mobile Money and Orange Money through aggregators such as Campay, with signature-verified, idempotent webhooks and automated reconciliation, so payments cannot be double-counted or spoofed.
Two different cases. If your funds were stolen, our Digital Investigation unit traces the movement of funds on-chain and supports freeze requests and legal action - with an honest upfront assessment of recovery odds. If you lost access to your own wallet because of a partially lost seed phrase, our Crypto Hunter tooling can often restore wallets with one or two missing or misspelled BIP39 words, after ownership verification, with all processing done locally.
Our core team includes cybersecurity engineers, full-stack developers, and security researchers, led by our founder - a veteran developer and certified cybersecurity professional. For complex projects we bring in specialized professionals from our vetted network, but responsibility for your engagement always stays with our core team.
Security & Compliance
Our security work follows recognised industry standards and methodologies, including the OWASP Top 10, the OWASP Testing Guide, and secure development lifecycle practices. Our team is led by a certified cybersecurity professional, and we are happy to share the specific qualifications and methodology relevant to your engagement.
Confidentiality is paramount, especially in investigations and security work. Strict NDAs are standard for all engagements, communications and stored data are protected with strong industry-standard encryption, and access to your information inside our team is limited to the people working on your case.
Security is our baseline, not an add-on: server-side input validation at every trust boundary, parameterized database queries only, deny-by-default authentication and authorization on every endpoint, no secrets in source code, encrypted sensitive data, and sanitized error messages. For systems that handle money we add double-entry ledgers, idempotency keys, and append-only audit trails. We describe precisely which controls were implemented - we never hand-wave with the word "secure".
Yes - when authorized and scoped. Every security assessment we perform runs under a written scope and rules of engagement signed by the system owner, uses non-destructive methods, and is coordinated with your team. We do not test systems without documented authorization, full stop.
Through our responsible disclosure program: email support@losbebesinc.com with a description, reproduction steps, and impact. We acknowledge reports within two business days and do not pursue legal action against researchers acting in good faith. See our Responsible Disclosure page for the full policy.
Support & Handover
You do. Standard engagements transfer all IP for the delivered work to the client - you own the code for your applications, bots, and tools. For investigations, all findings and evidence are strictly your property and confidential.
Yes. You can choose a maintenance retainer (updates, monitoring, security patches, small improvements) or a full handover to your own team. Either way, launch includes monitoring, backups, and documentation, so the system is operable from day one.
That is the goal. Every delivery includes source code, deployment configuration, and documentation, and we offer training sessions for your technical staff. We build your capability, not dependency on us - if you later choose another provider, everything they need is already in your hands.
For clients on a maintenance retainer, we define response targets in the agreement, with priority handling for outages and security incidents. For urgent incident response - even from organizations we have not worked with before - contact us via WhatsApp or email and we will tell you immediately whether we can take the case.
Still Have Questions?
We're happy to answer any questions you have. Reach out and we'll respond within one business day.
Contact Us