Offensive Security

VAPT services that end with a fixed problem.

Vulnerability assessment finds what is wrong. Penetration testing proves what an attacker could do with it. We run both, verify every finding by hand, and stay on the engagement until the fixes hold.

10,046Detection rules
26Assessment modules
100%Findings human-verified
FreeRetest cycle

What VAPT actually means, and what most reports get wrong

VAPT is two pieces of work that are usually sold as one. The vulnerability assessment is broad: it sweeps everything in scope and produces a list. The penetration test is deep: it takes the interesting items from that list and establishes whether they can be chained into something that genuinely hurts. You need both, because breadth without depth gives you a spreadsheet of theoretical risk, and depth without breadth means you tested the three things somebody remembered to mention.

The failure mode we see most often is a 300-page report that is really a tool export with a cover page. Every open port, every missing header, every informational notice, sorted by CVSS and handed over. Nobody reads it. Nothing gets fixed. The next year it is regenerated with a new date.

We do it the other way round. Automation gives us coverage — our engine carries 10,046 detection rules and matches findings against 356,454 CVEs scored by real exploit probability, so nothing obvious is missed. Then a person goes through the candidates, discards the noise, confirms what is genuinely exploitable, and works out what it means for your business. What you receive is short, ranked, and every item in it is real.

Coverage

What a full VAPT engagement covers

Scope is agreed in writing before anything starts. Most clients begin with one or two of these and widen once they have seen a report.

Web applications and portals

Authenticated and unauthenticated testing against the OWASP Top 10 and OWASP ASVS, including business-logic flaws that no scanner will ever find.

APIs and microservices

REST, GraphQL and internal service-to-service interfaces, tested against the OWASP API Security Top 10 — broken object-level authorisation is still the single most common critical we report.

Mobile applications

Android and iOS binaries and their backends, assessed against the OWASP MASVS, including local storage, certificate handling and hardcoded secrets.

Network and infrastructure

External perimeter and internal segments: exposed services, patch state, weak authentication, and lateral movement paths once a foothold exists.

Cloud environments

AWS, Azure and GCP configuration, identity and permission review against CIS benchmarks and the provider’s own well-architected guidance.

Source code

Manual review of authentication, authorisation, cryptography, input handling and secrets management, alongside automated analysis across 27 languages and runtimes.

Active Directory

Domain configuration, privilege paths, delegation and credential hygiene — the assessment that most often changes how an internal network is run.

Wireless and physical entry points

Corporate wireless, guest segregation and the network ports in the reception area everybody forgets about.

Approach

How an engagement runs

The shape of the work follows PTES and NIST SP 800-115. What we do not publish is the internals — payloads, sequencing and tooling chains stay with the engine.

  1. 01 · Scope and authorise

    We agree targets, testing windows, rules of engagement and escalation contacts, then get written authorisation. Production systems get out-of-hours windows if load is a concern.

  2. 02 · Discover

    We map the real attack surface — the subdomains, staging environments and forgotten services that are not on the asset list you sent us. This is where roughly a third of critical findings originate.

  3. 03 · Assess

    Broad automated coverage across the agreed scope, matched against current vulnerability intelligence, with known-exploited flaws escalated on sight rather than by score.

  4. 04 · Exploit and verify

    A human confirms each candidate, establishes real impact, and chains issues where chaining is possible. Anything critical is reported the same day we confirm it — you do not wait for the report.

  5. 05 · Report

    One document with an executive summary, a ranked technical section, evidence and reproduction steps, control mappings and a fix for every finding.

  6. 06 · Remediate and retest

    A walkthrough call with your engineers, then a free retest once fixes are deployed. The report records the state change per finding, so you have a defensible before-and-after.

Run against recognised standards

  • OWASP Top 10 & ASVSWeb application coverage and verification level
  • OWASP API Security Top 10API-specific authorisation and exposure classes
  • OWASP MASVS & MSTGMobile application security verification
  • PTESPenetration testing execution standard
  • NIST SP 800-115Technical security testing and assessment
  • MITRE ATT&CKAdversary technique mapping for internal and red team work
  • CIS BenchmarksHost and cloud configuration hardening
  • ISO 27001 Annex AControl mapping in every report

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Executive summary

Two pages a non-technical director can read: what the risk is in business terms, what it would cost you, and what to do first.

Ranked technical findings

Each with CVSS, exploit probability, affected asset and version, evidence, reproduction steps and a specific fix — not "apply vendor patches".

Control mapping appendix

Every finding mapped to ISO 27001 Annex A, PCI DSS, HIPAA, NIST CSF and OWASP ASVS clauses, so remediation doubles as audit evidence.

Remediation register

A POA&M-style tracker with owners and target dates, in a format your project managers can actually work from.

Machine-readable export

SARIF and JSON alongside PDF and HTML, so findings load straight into your code-scanning dashboard or ticket queue.

Retest certificate

A clean summary after the retest, suitable for handing to a customer, auditor or board.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • An enterprise customer has asked for a penetration test report before they will sign.
  • You are going through ISO 27001, SOC 2 or a DPDP readiness programme and need independent testing evidence.
  • You have launched something significant — a new platform, a payment flow, a customer portal — and it has never been tested.
  • Your last test was a tool export and you want to know what is actually exploitable.
  • You have inherited an estate and genuinely do not know what is exposed to the internet.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

VAPT Services — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

What is the difference between vulnerability assessment and penetration testing?

A vulnerability assessment identifies and catalogues weaknesses across everything in scope — it is broad, largely automated, and answers "what might be wrong here?". A penetration test takes those weaknesses and attempts to exploit them the way an attacker would, to establish what is genuinely reachable and what the real business impact is. VAPT means running both, so you get coverage and proof rather than one or the other.

How long does a VAPT engagement take?

A single web application is typically five to eight working days of testing, plus two to three days for reporting. A network perimeter of under 50 hosts is usually a week. Larger programmes covering multiple applications, internal networks and cloud environments run three to six weeks. We give you a firm number in the written scope before you commit, not a range that moves later.

Will testing take our systems down?

No. Testing that could affect availability — anything resembling denial of service, or high-volume automated activity — is excluded by default and only runs if you specifically ask for it in writing. Production testing is scheduled in agreed windows, we monitor as we go, and there is a named escalation contact on both sides for the duration.

Do you test production or staging?

Whichever gives you a truthful answer. Staging is safer but is rarely configured identically to production, and configuration is where a large share of real findings live. Our usual recommendation is staging for the intrusive parts and production for a controlled, agreed subset. We will tell you plainly what each choice costs you in coverage.

Is a retest included?

Yes. One retest cycle is included in every engagement at no extra cost. You fix, we verify, and the report records the state change per finding rather than becoming a new document with no history.

Do you provide a certificate we can share with customers?

We issue a summary letter after the retest confirming the scope tested, the dates, and the closure status of findings. It is written to be shared with customers, auditors and procurement teams without exposing technical detail that should stay private.

Are your testers certified?

Yes. The team holds industry certifications across offensive security and cloud, and the founding team brings over 20 years of combined experience across cybersecurity, cloud, compliance and enterprise technology. We are happy to share individual credentials under NDA during scoping.

How much does VAPT cost in India?

It depends almost entirely on scope — the number of applications, the size of the network, whether testing is authenticated, and whether you need retesting and remediation support. Rather than publish a number that would be wrong for you, we scope in a 30-minute call and send a written fixed price. Most first engagements with SMEs and startups land in a range that is materially below what the large consultancies quote for the same work.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.