Penetration testing services
Penetration testing
that proves it.
A penetration test should end an argument, not start one. We attack your applications, networks, cloud and people the way a real adversary would, then hand you the exact chain that worked, the evidence behind it, and the order to fix it in.
A scanner finds patterns. An operator finds a way in.
Automated tooling is where a test starts, never where it ends. Every engagement we run is driven by a person who reads the application, understands the business logic, chains the small problems together, and proves the impact. What you get back is not a severity list. It is a story with evidence attached.
Everything with
an attack surface.
Six testing services, scoped separately or run together as one programme. Each is delivered by the same operator who scoped it.
Web
Web application penetration testing
Authorization, business logic, injection, SSRF and file handling, tested by hand against every role in your application. See the method.
API
API penetration testing
REST and GraphQL, including the endpoints missing from your documentation. Object level authorization, token handling and mass assignment. See the method.
Network
Network penetration testing
External perimeter and internal estate, from edge exploitation through lateral movement to Domain Admin. See the method.
Mobile
Mobile application penetration testing
iOS and Android on real devices, plus the backend the app actually talks to. See the method.
Cloud
Cloud penetration testing
AWS, Azure and Kubernetes, where the compromise usually starts at the identity layer. See the method.
Adversary
Red teaming
One objective, no scope map, full chain. For teams who already run tests and want to know if detection works. See the method.
Seen in the field
What it looks like
in practice.
An illustrative example of the class of issue this engagement is built to find, and what changes after it.
Illustrative example, not client data
BeforeRated separately
# three findings, each dismissed on its own LOW Username enumeration on login LOW Verbose error on password reset MEDIUM Session not rotated after reset # "accepted risk, low severity" # closed on three separate tickets
AfterChained by an operator
# the same three, used in order 1. Enumerate a valid admin username 2. Confirm the reset token via error text 3. Reuse the pre reset session after takeover CRITICAL Full admin account takeover # proven end to end, with a repro
Severity is not additive. Three low and medium findings that every scanner would let you defer combined into full administrative takeover. Chaining is the part automation cannot do, and it is the reason a test needs a person.
Black box, grey box,
white box.
How much we are told up front changes what the test is worth. Most engagements should be grey box, and here is the honest reason why.
| Model | What we get | What it simulates | Best for |
|---|---|---|---|
| Black box | A name or an IP range, nothing else | An external attacker with no inside knowledge | Validating the perimeter and public attack surface |
| Grey box | Credentials for each user role, plus architecture notes | A user, a customer, or an attacker after initial access | Almost everything. The best coverage per rupee spent |
| White box | Full source, configuration and architecture | An attacker with total insight, or an insider | Pre launch review, high assurance systems, complex logic |
Tell us what to test.
Request a quoteHow an engagement
actually runs.
Four phases, a fixed timeline, and a fixed number agreed before anything starts.
01
Scope and rules
We agree the targets, the environments, the test windows and the safety rules in writing. You get a fixed price and a fixed date range. No hourly drift.
02
Recon and mapping
We map the real attack surface, which is usually larger than the one in the ticket. Forgotten subdomains, staging hosts, undocumented endpoints and stale credentials.
03
Manual exploitation
The bulk of the engagement. Every candidate issue is verified by exploiting it. Nothing reaches your report because a tool flagged a version number.
04
Report and retest
A written report, a live debrief with your engineers, and one round of retesting after you fix, included in the original price.
Deliverables
What you
walk away with.
Written for two audiences at once, because both have to act on it.
01
An executive summary
One page, in plain language, that a board or a customer can read. Business risk, not CVSS arithmetic.
02
The attack chain
The full path from entry to objective, step by step, so your team can see how small issues combined into a breach.
03
Reproducible findings
Every finding with the exact request, the response, and the steps to reproduce it. Your engineers should never have to guess what we did.
04
Prioritised remediation
Ordered by real exploitability in your environment, not by a generic score. What to fix this week, and what can wait.
05
A live debrief
A working session with your engineers. Questions answered by the person who ran the test, not an account manager.
06
Free retesting
One retest round after remediation, so you can prove the fix to an auditor or a customer.
Remote by default,
global in practice.
We are based in New Delhi and deliver remotely for clients across Asia, Europe, the Middle East and North America. Testing does not require anyone to be in the room.
Delivery
Fully remote engagements
Scoping, testing, debrief and retest all run remotely over your preferred channel. Physical and social engineering work is scoped separately and case by case.
Hours
Overlap that actually works
We agree test windows against your timezone up front, including out of hours or weekend windows for production systems that cannot take daytime risk.
Contracting
NDA before scoping
Every engagement runs under NDA, signed before we discuss detail. We are comfortable with your paper or ours, and with customer security addenda.
The usual
questions.
How much does a penetration test cost?
It depends on scope, but the number is fixed before we start and does not move. A single web application is typically a one to two week engagement. Give us the scope on a call and you get a written number, not a range that grows later.
How long does a penetration test take?
Most application and network engagements run one to two weeks of active testing, plus reporting. Larger estates and red team work run longer. You get a date range in the proposal and we hold it.
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment enumerates weaknesses, usually with tooling, and tells you what might be wrong. A penetration test proves what is actually exploitable by exploiting it. The second answers the question the first only raises. We cover both under VAPT if you need the pair.
Will testing take our systems down?
No. We test carefully, agree safety rules in writing, and never run destructive or denial of service payloads without explicit written sign off. Production testing is normal and we do it constantly.
Do you retest after we fix the findings?
Yes, one full retest round is included in the original price. You get an updated report you can hand to an auditor or a customer.
Who actually performs the test?
The founder, Abhimanyu Gupta, plus a small bench of operators. The person who scopes your engagement is the person who tests it and the person who debriefs your team. Work is never resold or offshored to a third party.
Related
Where to
go next.
Tell us what to test.
A senior operator replies within one business day. No sales pipeline, no bot.