We are an AI Trust and IT Risk Protection consultancy. We build AI governance, compliance programs (ISO 27001, PCI DSS, SOC 2, LGPD, BACEN), offensive and defensive cybersecurity, on-demand Security Office and business continuity. All of it runs on our own methodology, delivered by certified specialists.
FREQUENTLY ASKED QUESTIONS
The questions you would ask in a first conversation
We gathered here what people ask us most about security, compliance and artificial intelligence. If your question is not on this page, talk to us on WhatsApp.
100 / 100
About DM11
The company started in 2009, carrying almost 30 years of cybersecurity project experience from our executive partner. More than 2 million assets have been protected and more than 5,300 projects delivered across the 17 years, plus more than 900,000 vulnerabilities detected in the last two years.
Three things. We do not sell tools, so the recommendation you get is technical and never commission driven. Our team holds the international certifications the market demands. And we have been preparing clients for the requirements of banks, the Big Four and major digital retail players for 17 years.
We resell nothing. That is a deliberate business decision. When we assess your environment and recommend a path, you know the technical analysis is the only criterion behind that recommendation.
The main ones include CISA and CGEIT (ISACA), CEH (EC-Council), ISO/IEC 27001 Lead Auditor from BSI, DPO and PDPP from EXIN, COBIT 5, ITIL and PMP. On the offensive side the team also holds CPTE, CNSE and CSAE (AcadiTI), the Solyd family covering pentesting, wireless, Android and hardware, the DSFE forensics credential and Qualys certification in vulnerability management.
Every project has assigned specialists and a reporting routine agreed with you at the start. You get reports with a prioritized action plan and live sessions to walk through the results, not a document dropped in your inbox.
We serve clients from agribusiness to financial services, across a wide range of sizes. The strategy is tailored by size and sector, precisely because what makes sense for a regulated financial institution is not what makes sense for a fast-growing company. The right scope comes out of the initial assessment.
Yes. Our office sits in the Berrini area of Brooklin, São Paulo, but projects run remotely or on site depending on what the work requires. Where your operation is located does not limit what we can deliver.
It starts with a conversation to understand your context, your moment and what is putting pressure on you: an audit, a demanding client, a regulator, an AI rollout. Then we propose an assessment that sizes the real scope. Only after that do we talk about a work plan.
Our own team. The pentesters are in-house and certified, with zero subcontracting, and we run our own Cyber Intelligence Center. That matters because whoever enters your environment answers directly for confidentiality and method.
Confidentiality is the condition our work exists on. In digital forensics, for example, we deliver reports fit to support court proceedings, with absolute secrecy over the material analyzed. The same discipline applies to any project: access limited to what is strictly necessary, and evidence handled with full traceability.
We work in English, Portuguese and Spanish. Formal documentation is produced in Portuguese or English, the languages accepted in the international contexts our clients have to answer to, such as SOC 2, ISAE 3402, GDPR, TISAX and the EU AI Act. If your headquarters or your auditor requires material in another language, we align that in the scope.
AI and governance
It is the confidence your company needs in order to grow using AI. In practice, it means bringing governance, risk management, regulatory compliance and AI application security into a single program. It was the natural next step for a firm already doing IT GRC, cybersecurity and business continuity.
Because your company already uses AI, with or without a policy. Without governance, biased models and hallucinations inside critical processes make decisions and get them wrong at scale, and autonomous agents operate with no clear boundaries. You structure this now, or a regulator, a client or an incident structures it for you.
It is the first certifiable international standard for artificial intelligence governance. It defines the AI Management System (AIMS): roles, policies, approval flows for use cases and human oversight, all documented and auditable. We structure your compliance from the initial assessment through certification readiness.
It depends on where you operate and who you sell to. Companies active in Europe or supplying AI systems to the European market fall within scope. We run a gap assessment against the EU AI Act and classify your systems by regulatory risk category, so the answer is precise for your case.
The Brazilian AI legal framework is moving through Congress as Bill 2338/2023, and the ANPD, Brazil's data protection authority, named artificial intelligence and emerging technologies one of its four enforcement priorities for 2026 and 2027 through Resolution CD/ANPD no. 30, of December 2025. Companies that structure now avoid the rushed compliance scramble, which always costs more and delivers less. Verified on 27 July 2026.
We inventory every AI use in the company, official and unofficial, and classify each one by regulatory, security, privacy and reputational risk. You get a prioritized map with a treatment plan and indicators you can take to the board. We apply the same method standard that made oitenta20® work.
It is employees using generative AI tools with internal data and no oversight at all. Every prompt can carry personal data, trade secrets or intellectual property outside the company. The AI Risk Assessment inventory is built to surface exactly those unofficial uses.
It is an attack where malicious instructions are placed in the model input to divert the application's behavior, bypass restrictions or extract information that should stay protected. We test for it in penetration tests of AI applications and LLMs, alongside jailbreak techniques.
AI systems create attack surfaces that did not exist before: training data poisoning, model extraction and sensitive information leaking through the responses. We cover those vectors with penetration testing, MLSecOps across ML pipelines and model supply chain analysis (AI/ML BOM).
It is the deliberate contamination of the data used to train or feed a model, so its decisions come out distorted later. The damage shows up in production, when the model is already deciding. We run data poisoning and model extraction detection inside our AI cybersecurity practice.
Adversarial testing run against your models, pipelines and generative applications, following references such as MITRE ATLAS and the OWASP Top 10 for LLM. We apply offensive and defensive methodology across the entire lifecycle, not just at launch.
Models that make decisions about people have to account for those decisions. We assess bias and fairness in the models and in the training data, verify the explainability of automated decisions under article 20 of LGPD, Brazil's data protection law, and align with references such as the OECD AI Principles and UNESCO AI Ethics. The output is audit reports for regulators and stakeholders.
You do, and it only works if it is communicated and trained. We write the policy together with the responsibility matrix, set up the AI committee and the approval flows for use cases, then take it to the business in awareness tracks tailored by profile: legal, IT and business.
Before the question arrives from outside. Regulators, clients and boards are already asking for answers about AI use, and an AI Risk Assessment reveals in weeks what an incident would reveal in the worst possible way. If you cannot say how many AI systems run in your operation, that is your signal.
Governance, risk and compliance
It is the discipline that brings technology governance, risk management and compliance into a single system. Instead of addressing each standard in isolation, you build controls that serve several requirements at once. Less internal effort, evidence reused, audits that stop being a surprise.
It is the international standard for Information Security Management Systems, and in practice it is the credential that unlocks the most enterprise business in Brazil. We run it from assessment to certification: gap analysis, compliance plan, control implementation, risk management and audit preparation. After that we stay on for ISMS maintenance and continuous improvement, with BSI-certified Lead Auditors on the team.
It depends on the size of the scope, the current maturity of your controls and how available your team is to produce evidence. The gap analysis is what turns that question into a real schedule. Without it, any promised deadline is a guess.
It is the standard for a privacy information management system. Until 2019 it was an extension and could not be certified without ISO 27001 already in place; the revision published on 14 October 2025 made the standard independent, so a company can now certify privacy without first building a full security management system. Having ISO 27001 still helps, because clauses 4 to 10 are the same, but it is no longer a prerequisite. It makes sense once privacy is already part of your commercial pitch.
We assess the scope of your payment environment, run the gap assessment, implement the controls and cardholder data encryption, write policies and procedures, train the teams and organize the evidence in the format the assessor expects. DM11 prepares, it does not “certify”: when your route requires a formal assessment, it is conducted by a partner QSA credentialed by the PCI Security Standards Council. Keeping the preparer and the assessor separate is what makes the assessment worth anything.
Type I attests to the design of controls at a specific point in time. Type II evaluates how effectively those controls operate over an observation period, which is far more demanding and is what large clients usually ask for. We support you throughout the Type II observation period.
It is an international assurance report on the controls of a service organization, frequently requested when your clients need to rely on your processes to close their own audits. We prepare the scope, the control design and the evidence collection so you reach the auditor without surprises.
BACEN is Brazil's central bank. Financial and payment institutions need a formal cybersecurity policy, an incident response plan that includes notifying the regulator, and controls over contracting cloud processing and storage. We start by mapping which requirements apply to your institution specifically, implement the workstreams needed and keep compliance monitoring running continuously.
LGPD is Brazil's data protection law. The project runs from mapping data flows and defining legal bases to privacy and governance policies, mechanisms to handle data subject rights and team training. We integrate all of it into your security program instead of treating privacy as a parallel project.
You can outsource it, but that is not always the best route. With DPO Backoffice®, your Data Protection Officer stays in-house, close to the business, and gains a team of digital law, cybersecurity and GRC specialists alongside them. It costs less than hiring and retaining a senior specialist, and the knowledge stays inside your company.
You need a defined process, not improvisation case by case. We implement the mechanisms to handle data subject rights and take care of the privacy routine: consent, incoming requests, incidents and the risks posed by processors and third parties.
Because your suppliers are part of your risk surface, and the client auditing you will ask about them. We assess critical suppliers, review contracts and security clauses, standardize questionnaires and evidence, and monitor the ecosystem on a regular cycle.
That questionnaire is where a lot of deals stall. A well-built security dossier answers most of the questions before they arrive, with controls in place and evidence ready. We organize that base so due diligence stops being an obstacle and becomes an argument.
Audits turn into crises when the evidence is produced the week before. We work on control design, continuous evidence collection and auditor readiness, using our own methodology and specialists who have sat on both sides of the table.
It is not. Compliance proves you meet a set of requirements within a defined scope. Security is the real capacity to withstand an attacker, and that is only measured by testing: penetration tests, phishing simulations, crisis exercises. A mature program does both and uses each one to reinforce the other.
It can, and that is exactly how the cost of compliance comes down. Addressing each standard in isolation burns internal teams in endless evidence cycles. With NosConformes®, we map every audit and regulatory requirement into a single management point and take advantage of the overlaps between them.
Compliance means implementing the controls and processes the standard requires. Certification is the attestation issued by an independent certification body after auditing that compliance. Many companies only need to be compliant to answer clients; others need the certificate to bid. We define which is which during the assessment.
It stops you from deciding investment by urgency. The Cybersecurity strategy and master plan service shows where you are, where you need to get to and the investment sequence that makes sense for your size and sector, with progress indicators for the board. Strategy comes before tooling.
Cybersecurity
A pentest is a controlled attack on your environment, run by specialists, to find out how far a real intruder could get. Our team uses the same techniques attackers use, but within an agreed scope and with everything logged. What you get at the end is not a list of theories, it is proof of what is exploitable and the path to close each door.
A scan is automated and flags indications. A pentest validates those indications and goes further: business logic flaws, authentication bypasses and exploitation chains only surface when a professional thinks like an attacker. Those are precisely the flaws intruders prefer, because no tool sees them on its own. In practice we use both: automation for coverage, humans for depth.
Black box simulates the external attacker who knows nothing about you. Grey box starts from limited access, like a regular user or a partner. White box hands documentation, source code and credentials to the testing team, which gives the deepest coverage per hour invested. The choice depends on what you want answered, and we define it with you before we start.
If your last test is more than twelve months old, you are deciding in the dark. Beyond the annual cycle, test whenever something material changes: a new application in production, a cloud migration, a third-party integration or an architecture change. Companies that deploy frequently usually prefer the subscription model, with recurring tests throughout the year.
We follow OWASP methodology and go deep on authentication, authorization, business logic and data leakage. We test what the application does and also what it lets you do when someone runs the flow out of the expected order. The result comes with exploitation evidence and remediation guidance for the development team.
We test REST and GraphQL APIs. The focus is authentication, access control, exposing more data than needed and logic abuse, which is where APIs tend to fail without anyone noticing. Many companies protect the interface well and forget the API behind it answers anyone who knows how to call it.
Yes, for Android and iOS. We analyze local storage, communication with the server, resistance to reverse engineering and the integration with backend APIs. An app is a binary in anyone's hands, so everything embedded in it should be treated as public.
All three are part of our scope. On the external network we assess the full internet-facing surface. Internally we simulate what happens after someone gets in, including lateral movement and privilege escalation. On wireless we look at corporate and guest networks, with particular attention to segregation and authentication.
We test configuration and exploitation across AWS, Azure and Google Cloud, following CIS benchmarks and Cloud Security Alliance practices. Cloud misconfiguration is among the leading causes of data leaks, and what was safe in the data center can be exposed the moment it moves. We also review identity, encryption and monitoring, because in the cloud the perimeter is the permission.
A retest validates that the fixes actually worked. Once your team addresses the findings, we go back to the same points and confirm they are closed. Retesting is included in our pentest projects and in every Ethical Hacker as a Service plan. A report without a retest is a diagnosis without a discharge.
You get the vulnerabilities found with technical evidence, the criticality of each one and a prioritized action plan, not a raw list sorted by generic severity. There is an executive read for the board and the technical detail your IT team needs to fix things. We close with a results presentation session, so questions get answered by the people who ran the test.
SAST analyzes source code at rest, looking for flaws in how the application was written. DAST tests the running application from the outside, the way an attacker would. Each sees what the other cannot reach, which is why we apply both. Your development team gets remediation guidance, and we can integrate the analyses into the development cycle.
We design realistic campaigns by department, role and exposure level, and measure who opened, who clicked and who reported. Nobody is exposed or punished: we work with influence and empathy, never with manipulation or fear. Every click becomes immediate training for that person, and the management report speaks in terms of groups and trends. Tracking is non-intrusive and respects privacy.
It is the continuous process of identifying, prioritizing and tracking the remediation of flaws in your environment. The difference is in the prioritization: we map your assets, connect each one to the business processes it supports and rank by the real risk to you. A medium-severity flaw in a critical system can matter more than a critical one on an isolated server.
We investigate incidents with collection, preservation and analysis of digital evidence, under absolute confidentiality. We reconstruct the event timeline, analyze devices, recover data and work to identify attribution. When the case goes to legal, we deliver a forensic report fit to support court proceedings.
It is threat intelligence applied to your context, not a generic indicator feed. We monitor actors, campaigns and exposures relevant to your sector, including credential leaks and misuse of your brand. Those external signals turn into defensive decisions before the attack, and help prioritize what to address first. We run our own Cyber Intelligence Center for this.
The risk exists in any real test, which is exactly why it is planned. We agree on the execution window, the scope, the sensitive assets and a direct contact channel before any activity starts. Critical risks trigger an immediate alert rather than waiting for the final report. If an environment cannot tolerate downtime, we adjust the approach for that target.
Start with the prioritized action plan in the report, which already orders the work by what reduces the most risk with the least effort. Our team supports yours in interpreting each finding technically and defining the fix, and we coordinate follow-up when you contract vulnerability management. Once fixed, we retest and you have closure evidence for the auditor and for the client who asks.
Security Office as a Service
You contract exactly the competence you need, at the right intensity, without the fixed cost of building an internal team. Instead of opening a role, waiting out the hiring process and hoping to retain the professional, you get senior specialists who are already trained. Building a complete security team takes years, and risk does not wait for headcount.
A senior security executive leads your strategy, risk management, corporate policies and reporting to the board. It makes more sense when you need senior decision-making but do not have the workload for a full-time dedicated professional, or when the market price exceeds what the role can support today. It also works well as a bridge: the CISO as a Service builds the program while you prepare the internal hire.
We offer Data Protection & Privacy as a Service, with specialists keeping LGPD and GDPR current: assessment of processing activities, policies, responses to data subjects and incidents, and dialogue with the ANPD, Brazil's data protection authority. In most cases we recommend DPO Backoffice®, where the Data Protection Officer stays inside your company and receives support from a team of digital law, cybersecurity and GRC specialists. Your professional knows the business, the technical and legal depth comes from outside.
It is offensive security by subscription: certified ethical hackers test your systems on a recurring basis, always within the law and the agreed scope. On the Advanced plan, work begins within 24 hours of activation, covering web, mobile, APIs, cloud and networks. Every plan includes a report with recommendations, a retest and a results presentation session.
We move security into your pipeline instead of leaving it to the end of the cycle. That includes continuous test automation, code analysis wired into CI/CD, alignment with secure development standards and training for the engineering teams. The goal is for the flaw to show up at commit, not in a pentest report three months later.
Continuity treated as an ongoing service, not a document in a drawer. We handle the analysis of risks and critical processes, the contingency and recovery plans, disaster simulations with the teams and continuous updates to the program. A plan that has never been tested fails on exactly the day you need it.
It depends on the size of the company, the sector and the regulatory load you carry. The level of dedication is adjusted case by case, and we size it during the initial assessment, before any proposal. You are free to scale up whenever the moment calls for more intensity.
We work so the knowledge stays in your house, with policies, processes and documentation under your control from day one. When you decide to hire internally, the program is already structured and the new professional takes over something that works instead of starting from scratch. We can help define the profile and hand over gradually, reducing our dedication step by step.
It does, and that is a common scenario. Security demands distinct competences, such as offensive work, governance, privacy and continuity, and a lean team rarely covers all of them with the same depth. We step into the specific gap, whether that is executive seniority or offensive capability, without competing with the people already inside.
Legal responsibility stays with your company, and no service model transfers that. What we do is support that response technically: required policies, documentation, evidence, an incident response plan and dialogue with authorities when needed. Our team brings a range of specialists, including CISA and ISO 27001 Lead Auditor credentials, and prepares clients for the requirements of banks, regulators and Big Four audits.
We define indicators at the outset, based on what your board needs to track. In practice that usually covers maturity progress measured before and after, vulnerabilities addressed and time to fix, results from awareness campaigns and audit readiness. Executive reporting is part of the service, not an add-on.
Access is granted on a least-privilege basis, within a formally agreed scope, and every activity is logged. We work under absolute confidentiality, including forensic investigations whose reports reach the courts. Our pentesters are in-house and certified, with zero subcontracting, so nobody outside DM11 touches your environment.
Business continuity
It is your company's ability to keep operating when something goes wrong, whether that is an attack, an infrastructure failure or a critical supplier going dark. In practice it means knowing which processes cannot stop, how long they can stay down and what to do in the first hours. It is a set of decisions made before the crisis, rather than a document filed away.
BIA stands for Business Impact Analysis. It answers something simple and uncomfortable. What does each hour of downtime cost for each process in your company? We map the critical processes, measure the financial, operational and reputational impacts, and those numbers are what tell you where to invest in recovery. Without a BIA, any continuity plan is guesswork.
RTO is how long a process can stay down before the damage becomes unbearable. RPO is how much information you accept losing, measured in time: if your backup runs every 12 hours, you can lose up to 12 hours of data. We define both per process inside the BIA, because a billing system and an internal portal rarely share the same urgency.
A backup is one piece, not the plan. It stores the data, but it does not say who calls whom, in what order systems come back, how the company communicates with clients during the outage or what to do if the backup itself is compromised. Many companies learn the difference at the worst possible moment, when they realize they have the data but no way to get the operation running.
It is DM11's continuity method: qualify the risks in the environment, mitigate the weak points and create continuity, test everything to validate what was done, and turn each round into continuous improvement. The logic behind it is direct: a fragile company breaks in a crisis, a resilient company holds and returns to what it was, an antifragile company comes out stronger. Every incident becomes structured learning instead of a forgotten scare.
A plan that has never been tested is a plan that does not exist yet. We recommend regular exercises and a test whenever there is a material change in systems, suppliers or team structure. We run everything from tabletop exercises with leadership to disaster simulations and technical recovery tests, and each round produces an improvement plan for the next.
The first hours define the narrative. We structure the detection, escalation, communication and decision flows so your team responds with method instead of panic. That covers who has authority for each decision, what gets communicated to clients and regulators, and how everything is recorded for the review afterwards. Then we train people on those flows.
Usually both. Standards such as ISO 27001 and the resolutions from BACEN, Brazil's central bank, require continuity explicitly, and enterprise clients ask about plans and tests during due diligence before signing. The difference is that a program built for the auditor delivers paper, while a program built for the business delivers an operation still standing when the incident arrives.
DM11 products
oitenta20® is DM11's IT Risk Assessment. It X-rays your environment through structured interviews and technical assessments across the critical security disciplines, from identity management to incident response. It is for anyone who needs to decide where to invest and does not yet have a clear, comparable view of their own exposure.
Because oitenta20® applies the Pareto principle to information security. Instead of treating every control as if it carried the same weight, we identify the 20 controls with the greatest impact on the company's technology environment, selected to act on the vulnerabilities, exposures and attack scenarios that concentrate most of the risk. The idea is to prioritize roughly 20% of the measures capable of producing about 80% of the expected effect on the risks that matter most. Less dispersion, more security where it really counts.
You receive a maturity and exposure score per discipline, a map of the actions that mitigate most of the risk with sequence and estimated effort, and an executive read in business language. Because maturity is measurable, you can compare progress with each new cycle and use the result as the basis for the roadmap and the annual budget.
No. Jigphish® is DM11's managed phishing simulation program, and it works with influence and empathy, never with manipulation or fear. Tracking is done safely and non-intrusively, respecting people's dignity. Every click becomes a teachable moment and targeted training, not punishment.
EHaaS is penetration testing by subscription, run by certified in-house pentesters. Instead of contracting each test as an isolated project, you keep a cadence of testing across the targets that matter: web applications, mobile, APIs, cloud and external and internal networks. Every plan includes analysis by a certified professional, a report with recommendations, a retest and a results presentation session.
There are four. Basic covers the external surface, web applications and exposed networks, and is a solid starting point. Intermediate extends to internal networks and adds a dedicated project manager. Advanced covers web, mobile, APIs, cloud and networks, for critical digital operations. Custom designs scope, cadence and SLAs together with your team. In the first conversation we point to what fits your environment.
With DPO as a Service you outsource the Data Protection Officer, and access to internal data and knowledge of the business goes with them. With DPO Backoffice®, your DPO stays in-house and gains a multidisciplinary team of digital law, cybersecurity and GRC specialists alongside them. The knowledge stays internal, the privacy culture takes root in the team, and the scope flexes with your needs.
It is DM11's Secure Code Review platform. When your customer asks for evidence of a security review of your code, SastAction® delivers three reports, one technical, one executive and one public to attach in a bid, without installing anything in your environment and with no mandatory integration with your pipeline. The AI model runs inside DM11's environment, your code never goes to any provider and is deleted within 30 days, with findings mapped to OWASP and CWE.
It is centralized management of your regulatory and audit obligations. We map every applicable requirement, current and upcoming, identify where different standards overlap and build a process for planning, fulfilling and tracking them. Instead of answering each standard from scratch, you reuse what is already done and free your internal teams for strategic work.
You can. Each product solves a specific pain and works on its own. Many companies start with an oitenta20® to see the full picture, or with a Jigphish® pilot campaign, and only then decide whether to widen the scope. If you do not know where to start, we talk it through and point to the right product for the most urgent pain, without pushing what you do not need.
Yes, and that is where they pay off most. oitenta20® usually reveals the priorities that EHaaS, Jigphish® or SastAction® will go after. Cyber Antifrágil® uses the qualified risks to build continuity. NosConformes® organizes the evidence the others produce. You can contract one at a time and connect them as maturity grows.
They do, because they produce real evidence and not just a good-looking report. Jigphish® generates the proof of an active awareness program that several standards require, EHaaS documents penetration tests and retests, DPO Backoffice® sustains LGPD compliance and NosConformes® centralizes everything in a single management point. The auditor asks, you show.
Engagement and proposals
You can write to contato@dm11.com.br, call +55 (11) 4837-5758, reach us on WhatsApp or fill in the form on the contact page. Describe the challenge with as much context as you can, because that shortens the path to a proposal that actually fits. A specialist answers, not a sales script.
It depends on scope, timeline and the seniority involved. In a diagnostic conversation we get to know your environment and the outcome you need, and our commercial team presents the proposal with the figures.
It is a diagnostic conversation, with no commitment. We want to understand your context: sector, size, what security already exists, what is putting pressure on you right now, whether that is an audit, a client, an incident or a regulator. From there we point to the path that makes sense, even when that means telling you that you do not need that service yet.
It varies with the service and the agreed scope. Subscription services such as EHaaS go live quickly after activation, and one plan comes with priority start. Broader programs, such as standards compliance or continuity, require scope and calendar alignment with your team before starting. We set the schedule together with you in the proposal.
Both models exist. An oitenta20® or a forensic investigation are engagements with a beginning, middle and end. EHaaS, Jigphish®, DPO Backoffice® and the Security Office services make more sense as subscriptions, because risk is not an isolated event and compliance does not maintain itself. We choose the format based on your need, not on our commercial model.
Yes. We work in English, Portuguese and Spanish, and we work with international standards and frameworks every day, including ISO 27001, ISO/IEC 42001, PCI DSS, SOC 2, GDPR and the EU AI Act, for operations with a presence abroad. Formal documentation is produced in Portuguese or English, the languages auditors and headquarters tend to require. If your case involves another time zone or regulatory requirements from another jurisdiction, mention it in the first contact so we can align the engagement format upfront.
Every company has a different situation. Talk to us.
Talk to a DM11 specialist. The first conversation is diagnostic, with no commitment.