Penetration testing services

Penetration testing
that proves it.

A penetration test should end an argument, not start one. We attack your applications, networks, cloud and people the way a real adversary would, then hand you the exact chain that worked, the evidence behind it, and the order to fix it in.

A scanner finds patterns. An operator finds a way in.

Automated tooling is where a test starts, never where it ends. Every engagement we run is driven by a person who reads the application, understands the business logic, chains the small problems together, and proves the impact. What you get back is not a severity list. It is a story with evidence attached.

Everything with
an attack surface.

Six testing services, scoped separately or run together as one programme. Each is delivered by the same operator who scoped it.

Web

Web application penetration testing

Authorization, business logic, injection, SSRF and file handling, tested by hand against every role in your application. See the method.

API

API penetration testing

REST and GraphQL, including the endpoints missing from your documentation. Object level authorization, token handling and mass assignment. See the method.

Network

Network penetration testing

External perimeter and internal estate, from edge exploitation through lateral movement to Domain Admin. See the method.

Mobile

Mobile application penetration testing

iOS and Android on real devices, plus the backend the app actually talks to. See the method.

Cloud

Cloud penetration testing

AWS, Azure and Kubernetes, where the compromise usually starts at the identity layer. See the method.

Adversary

Red teaming

One objective, no scope map, full chain. For teams who already run tests and want to know if detection works. See the method.

Seen in the field

What it looks like
in practice.

An illustrative example of the class of issue this engagement is built to find, and what changes after it.

Illustrative example, not client data

operator@overwatch: finding chain, one engagement Illustrative example

BeforeRated separately

# three findings, each dismissed on its own
LOW     Username enumeration on login
LOW     Verbose error on password reset
MEDIUM  Session not rotated after reset

# "accepted risk, low severity"
# closed on three separate tickets

AfterChained by an operator

# the same three, used in order
1. Enumerate a valid admin username
2. Confirm the reset token via error text
3. Reuse the pre reset session after takeover

CRITICAL  Full admin account takeover
# proven end to end, with a repro

Severity is not additive. Three low and medium findings that every scanner would let you defer combined into full administrative takeover. Chaining is the part automation cannot do, and it is the reason a test needs a person.

Black box, grey box,
white box.

How much we are told up front changes what the test is worth. Most engagements should be grey box, and here is the honest reason why.

ModelWhat we getWhat it simulatesBest for
Black boxA name or an IP range, nothing elseAn external attacker with no inside knowledgeValidating the perimeter and public attack surface
Grey boxCredentials for each user role, plus architecture notesA user, a customer, or an attacker after initial accessAlmost everything. The best coverage per rupee spent
White boxFull source, configuration and architectureAn attacker with total insight, or an insiderPre launch review, high assurance systems, complex logic

Tell us what to test.

Request a quote

How an engagement
actually runs.

Four phases, a fixed timeline, and a fixed number agreed before anything starts.

01

Scope and rules

We agree the targets, the environments, the test windows and the safety rules in writing. You get a fixed price and a fixed date range. No hourly drift.

02

Recon and mapping

We map the real attack surface, which is usually larger than the one in the ticket. Forgotten subdomains, staging hosts, undocumented endpoints and stale credentials.

03

Manual exploitation

The bulk of the engagement. Every candidate issue is verified by exploiting it. Nothing reaches your report because a tool flagged a version number.

04

Report and retest

A written report, a live debrief with your engineers, and one round of retesting after you fix, included in the original price.

Deliverables

What you
walk away with.

Written for two audiences at once, because both have to act on it.

01

An executive summary

One page, in plain language, that a board or a customer can read. Business risk, not CVSS arithmetic.

02

The attack chain

The full path from entry to objective, step by step, so your team can see how small issues combined into a breach.

03

Reproducible findings

Every finding with the exact request, the response, and the steps to reproduce it. Your engineers should never have to guess what we did.

04

Prioritised remediation

Ordered by real exploitability in your environment, not by a generic score. What to fix this week, and what can wait.

05

A live debrief

A working session with your engineers. Questions answered by the person who ran the test, not an account manager.

06

Free retesting

One retest round after remediation, so you can prove the fix to an auditor or a customer.

Remote by default,
global in practice.

We are based in New Delhi and deliver remotely for clients across Asia, Europe, the Middle East and North America. Testing does not require anyone to be in the room.

Delivery

Fully remote engagements

Scoping, testing, debrief and retest all run remotely over your preferred channel. Physical and social engineering work is scoped separately and case by case.

Hours

Overlap that actually works

We agree test windows against your timezone up front, including out of hours or weekend windows for production systems that cannot take daytime risk.

Contracting

NDA before scoping

Every engagement runs under NDA, signed before we discuss detail. We are comfortable with your paper or ours, and with customer security addenda.

The usual
questions.

How much does a penetration test cost?

It depends on scope, but the number is fixed before we start and does not move. A single web application is typically a one to two week engagement. Give us the scope on a call and you get a written number, not a range that grows later.

How long does a penetration test take?

Most application and network engagements run one to two weeks of active testing, plus reporting. Larger estates and red team work run longer. You get a date range in the proposal and we hold it.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment enumerates weaknesses, usually with tooling, and tells you what might be wrong. A penetration test proves what is actually exploitable by exploiting it. The second answers the question the first only raises. We cover both under VAPT if you need the pair.

Will testing take our systems down?

No. We test carefully, agree safety rules in writing, and never run destructive or denial of service payloads without explicit written sign off. Production testing is normal and we do it constantly.

Do you retest after we fix the findings?

Yes, one full retest round is included in the original price. You get an updated report you can hand to an auditor or a customer.

Who actually performs the test?

The founder, Abhimanyu Gupta, plus a small bench of operators. The person who scopes your engagement is the person who tests it and the person who debriefs your team. Work is never resold or offshored to a third party.

Tell us what to test.

A senior operator replies within one business day. No sales pipeline, no bot.