Web Application VAPT
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Fixed fee · GST incl.
₹29,999
Scope, price and timeline published on every engagement page
A practical gap assessment against India DPDP Act 2023, covering consent, retention, notices and breach procedure.
Delivered in
15 working days
Revisions
One round, included
Ownership
Yours from day one
Overview
The Digital Personal Data Protection Act changes what Indian businesses must do with personal data, and most product teams have not mapped where that data actually sits. We inventory it: the database, the analytics tool, the support inbox, the marketing platform, the spreadsheet on someone's laptop. Then we assess your consent flows, retention practice and processor contracts against the Act, and produce a remediation plan with effort estimates. This is engineering-led rather than legal advice, and we say plainly where you need a lawyer instead.
Deliverables
Outcomes
You know where personal data lives, often for the first time
Consent and retention practice defensible rather than assumed
A prioritised plan instead of a vague sense of exposure
Process
Discover
systems interviewed and personal data located, including shadow copies
Map
flows documented from collection through to deletion
Assess
practice compared against the Act clause by clause
Plan
gaps prioritised with owners, effort and a suggested sequence
These are collected in the technical brief that opens in your dashboard the moment payment clears. The clock starts when they arrive, not before.
Answers
No. It is a technical and process readiness review. We work alongside your legal counsel and flag anything needing their judgement.
The inventory and flow maps serve both. A full GDPR assessment adds scope and we will quote it.
Yes. Obligations scale with volume and sensitivity, but they start from the first data principal.
This is engineering work, not a physical product — nothing ships and there is no stock to run out of. Delivery is to the working days stated above, into systems you control, and the refund terms set out what happens if we miss the date.
Booked alongside
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Fixed fee · GST incl.
₹29,999
Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.
Fixed fee · GST incl.
₹18,999
The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.
Fixed fee · GST incl.
₹44,999
We find the credentials committed to your repositories, rotate them, and set up scanning so it stops happening.
Fixed fee · GST incl.
₹12,999
GST included
₹22,999
Capacity open this month
No discovery calls to find out a number, no statements of work that take three weeks to sign. Pick the engagement that matches the problem and we assign the engineers.