Aller au contenu principal

FAQ

Frequently asked questions.

Answers to the questions we get asked the most. Pricing, timelines, methodology, security. If your question isn't here, write to us.

General

General.

What types of clients do you work with?
SMEs, scale-ups, and large accounts. We work as easily with pre-MVP founders as with CIOs refactoring business-critical SaaS.
What is your geographic coverage?
Based in Paris, we work across France and French-speaking Europe. Remote is the default for weekly check-ins.
Pricing

Pricing and budgets.

What are your rates?
Senior day rates range from €700 to €950 ex-VAT depending on duration and complexity. Fixed-price projects are delivered with a defined scope and a firm budget.
Do you accept small budgets?
Yes, when the scope is clear and deliverable in under 4 weeks. For projects under €10k we offer a Starter package with a strict scope.
Method

Methodology and process.

How does a typical project run?
Discovery (1-2 weeks), design (2-4 weeks), engineering in 2-week sprints, production launch, then optional managed support. Weekly check-ins, demos, and a preview environment per feature.
Do you work with an agile methodology?
Yes — 2-week sprints, prioritised backlog, demos, retros. But with discipline: no "we'll figure it out as we go". ADRs and documentation ship continuously.
IP

Intellectual property.

Who owns the code?
You own the code from the very first commit, on your own Git repositories (GitHub, GitLab, Bitbucket). No lock-in, no hidden proprietary codebase.
What about the intellectual property of the design?
Figma deliverables and the design system are transferred in full ownership at the end of the project. You can evolve them in-house.
Security

Security and confidentiality.

How do you handle sensitive data?
GDPR compliance by default, HDS for health data, NIS2 for essential operators. Secrets in a vault, PII-free logs, immutable audit trail.
Do you sign NDAs?
Yes, systematically. We also sign GDPR-compliant data-processing agreements for personal data processed on your behalf.
Maintenance

Maintenance and post-launch.

Do you offer maintenance after delivery?
Yes — managed support on a monthly retainer with 4/8/24-hour SLAs depending on severity. Optional 24/7 on-call. Monthly reporting, quarterly committee.
What happens if I want to bring maintenance in-house?
We train your teams, hand over the knowledge base, and support the transition. No deliberate lock-in — our goal is your autonomy.

By service

Service-specific questions.

Each service has its own subtleties. Below are the answers to service-specific questions, grouped by expertise.

How long does a corporate website take?
An 8–12 page corporate site ships in 6 to 10 weeks depending on editorial depth and the number of translations.
Do you work with our teams?
Yes. We run agile with weekly checkpoints, demos and a shared preview environment. The code is yours.
Do you host the site?
We offer managed hosting (Vercel or a Docker container on your infrastructure) with supervision, alerting and an optional SLA.
What if I want to edit the content myself?
We integrate a headless CMS (Sanity, Payload, Strapi) or a Markdown editor depending on your needs. Editors never write code.
React Native or native?
80% of projects are covered by React Native — cost and iOS/Android consistency gains. We switch to native for 3D, BLE, or highly specific needs.
How much does an app cost?
A serious mobile app starts at €40k for an MVP, €80–150k for a full version. We answer within 48 hours with a precise range.
Do you publish on the App Store and Play Store?
Yes — full handling of the submission process, reviews, and compliance with Apple/Google guidelines.
What happens after launch?
Corrective and evolutionary maintenance, crash monitoring, OTA updates (RN), or native releases depending on the support contract.

AI & Data

Details
Which models do you use?
We are agnostic: OpenAI, Anthropic, Mistral, self-hosted open-source models. The choice depends on the use case, cost and confidentiality.
Is my data used to train the models?
No — by default we use APIs in zero data retention mode (OpenAI Enterprise, Anthropic, Mistral) or self-hosted models.
How do you handle hallucinations?
RAG with verifiable citations, guardrails, structural validation, continuous evaluation dataset. Every critical output is traceable.
What ROI for an internal RAG use case?
On an internal document assistant, average search time drops from 15 minutes to under 2. Typical ROI within 6 months for >100 employees.

Automation

Details
Which processes can be automated?
Any repetitive task with clear rules: data entry, reporting, follow-ups, exports, synchronisations, document validation.
n8n, Make, Zapier or bespoke?
Zapier for simple non-critical cases, Make for mid-market, n8n for sovereignty, Temporal for complexity.
How much does it cost?
A typical workflow: €4k to €12k. ROI is measured in months against the time freed. Initial audit free up to 1 day.
What if the process changes?
Versioned workflows, tests, preview environment. Changes are traceable and reversible.

Cloud & DevOps

Details
AWS, GCP, Azure, Scaleway or OVH?
Depends on the case: AWS/GCP for service depth, Scaleway/OVH for European sovereignty and cost. No vendor lock-in.
Should we migrate to Kubernetes?
Not always — for simple loads, Docker Compose or a PaaS (Vercel, Render, Clever Cloud) is enough. K8s is justified at scale and for multi-service.
Do you offer on-call?
Optional, as an extra. By default we train your teams for on-call duty and provide the runbooks. VALRY LABS on-call available under contract.
How do you reduce cloud costs?
Tagging, right-sizing, savings plans, spot instances, archiving. Typical FinOps audit: 15 to 35% savings identified.

Cybersecurity

Details
What's the difference between an audit and a pentest?
Audit = methodical review of posture (code, config, process). Pentest = active attack simulation, on a defined target.
Are you certified?
The team includes OSCP, CEH, CISSP profiles. For formal ISO 27001 / SOC 2 certification, we work with auditor partners.
Do you write the full GDPR compliance package?
Yes — register, DPIA, processor contracts, data-subject information. For the DPO role we recommend a specialised legal partner.
How does a pentest unfold?
Scoping (perimeter, windows, modes), reconnaissance, exploitation, post-exploitation, report, retest. Typical duration: 1 to 3 weeks.
When will I see results?
Technical quick wins in 4–8 weeks. Foundational SEO: 3 to 6 months for the first gains, 6 to 12 months for the durable ones.
Do you guarantee position #1?
No — nobody honest can. We guarantee a serious strategy, deliverables, and measurable KPIs (impressions, clicks, conversions).
Do you work on WordPress or Next.js?
Both. We are particularly fond of Next.js for SEO (Server Components, Metadata API, native performance).
And the content — who writes it?
We handle the writing (EN/FR) through our content team, or train yours. Editorial briefs provided in every case.

Technical Marketing

Details
GA4 or Plausible?
Depends on the need: GA4 for depth (free but complex), Plausible for simplicity and GDPR. The two can be combined.
What is server-side tracking?
Events go through your server (not the browser) — better data quality, GDPR-friendly, less blocked by ad-blockers.
Is Consent Mode v2 mandatory?
To use Google Ads in Europe, yes. We implement the full v2, with a consent register.
Do you run the ad campaigns?
Yes — Google Ads, LinkedIn Ads, Meta Ads. Setup, creatives, weekly optimisation, transparent reporting.

Consulting & Architecture

Details
Truly independent of vendors?
Yes — no commercial partnership with any vendor. We bill time and expertise, not commissions.
How much does an audit cost?
Short audit (1 week): €8–15k. Full audit with due diligence: €25–60k depending on codebase size. Quote within 48 h.
Do you work with our teams?
Yes — on-site coaching, pair programming, knowledge transfer. The goal is your teams' autonomy.
For investors / M&A?
Full technical due diligence: code, IP, security, debt, team. Executive + detailed report within 2 to 4 weeks.

Maintenance

Details
Which SLAs do you offer?
4 h (business critical), 8 h (standard), 24 h (non-critical). Hours included in the monthly package, beyond it extra.
Maintenance on an existing product?
Yes — VALRY LABS or third-party code (subject to an initial audit). We progressively modernise the legacy.
What does the monthly package cover?
A pre-defined volume of hours (typically 20–80 h/month), supervision, security fixes, small evolutions, reporting.
Is 24/7 on-call included?
Optional. Monthly on-call package + consumption in case of intervention. Recommended for business-critical products.

Didn't find your answer?

Write to us. Reply within 48 business hours, no commitment.