Add-ons · Security
A security test before go-live, and evidence for your board.
Super Intelligence (SI) on your own server is a new system in your building, and it holds your documents. The Security add-on tests it before go-live with a certified testing firm, and helps you show a regulator, a board or a buyer abroad what protects your systems.
Where it starts
Who has to show what protects them
Three kinds of organisation must show what protects their systems. Banks and finance companies work under Bangladesh Bank's ICT security guideline. The organisations named critical information infrastructure under the Cyber Security Act 2026 must run their own response team and file yearly audits, as we read the Act. Exporters answer security questionnaires from buyers abroad.
A board, an auditor or a buyer asks for evidence, not a policy folder.
For Bahlul SI
What it does for the product
Every SI server proposal offers a penetration test between installation and go-live. The standard scope covers the web interface and sign-in, the admin console and management port, the access groups (a user must not get answers or source pages from documents outside their groups), the audit log, and the server's lack of any route to the internet.
A certified testing firm runs the test, and its report reaches you unedited. Your approver decides on every critical and high finding before go-live: fixed and retested, or accepted in writing. The security officer retainer then keeps an eye on the server's access groups, admin accounts and patch status month by month.
Offers and prices
A pack, a test and a retainer
| Offer | Unit | 2027 price | Duration |
|---|---|---|---|
| Cyber readiness and evidence pack | Package | BDT 9 lakh | Five to six weeks |
| Penetration test, with a certified testing firm | Test | BDT 4.5 lakh | Per test, scoped per system |
| Security officer retainer | Month | BDT 1.5 lakh | Monthly |
Proposed 2027 prices, before VAT. One test covers one system: a web or mobile application with its interface, an internet-facing network range, or a new SI server before go-live.
Sold on its own
Evidence for any system, not only SI
The readiness and evidence pack scores about 60 control questions across 15 domains, for one legal entity with up to two sites and 500 users. Each question maps to an ISO/IEC 27001:2022 Annex A theme, to the Cyber Security Act's duties where they apply and, for banks, to Bangladesh Bank's ICT security guideline. You get maturity scores by domain, the key findings, a 90-day plan, a 12-month roadmap, an indexed evidence pack, a first incident response plan where none exists, and a re-score at day 90.
The retainer gives you a named security officer for a set number of days a month: the risk register, policy upkeep, awareness sessions, vulnerability follow-up and a board report. It is offered after a readiness pack, when the 90-day plan needs an owner.
Who delivers
A certified testing firm tests; we manage
A certified testing firm carries out every penetration test. Bahlul World scopes the test, prepares the authorisation letter you sign, books the window, reads the report with you, explains it to management and tracks fixes to the retest. You provide the system owner, a signatory with authority, test accounts, a fresh backup, any hosting vendor's written consent and an emergency contact.
Bahlul World holds no testing certification of its own and claims none. We sell readiness and evidence; the testing firm tests, lawyers read the law, and certification bodies certify.
FAQ
Questions we are asked
Who actually does the penetration test?
A certified testing firm, under a scope we agree with you and an authorisation letter you sign. We manage the test and the fixes, and the firm's report goes to you unedited.
Does the readiness pack make us compliant with the Cyber Security Act?
No. It shows where you stand against the Act's duties as we read them with a partner law firm, and gives you the evidence and the plan. Compliance is a judgement a regulator makes, and certification is for certification bodies.
What can hold up an SI server's go-live?
An open critical or high finding that your approver has not accepted in writing. That is why the window is booked between installation and go-live, with time to fix and retest.
Book the test when you order the hardware
The best time to book the window is the day you order the server. Tell us the go-live date and we will scope the test with the certified testing firm.