Web Application VAPT
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Fixed fee · GST incl.
₹29,999
Scope, price and timeline published on every engagement page
We find the credentials committed to your repositories, rotate them, and set up scanning so it stops happening.
Delivered in
6 working days
Revisions
One round, included
Ownership
Yours from day one
Overview
Almost every codebase that has never been scanned contains a live credential somewhere in its history. Deleting the file does not help, because the commit is still there. We scan the full history of your repositories, verify which found secrets are still valid, and help you rotate them in the right order so nothing breaks. Alongside that, we sort out dependency hygiene: outdated packages with known vulnerabilities, an upgrade path that will not consume a month, and automated scanning so the next problem is caught on the pull request.
Deliverables
Outcomes
Live credentials removed from places that should never have held them
Vulnerable dependencies identified with a sequence you can actually follow
Future secret commits blocked before they reach the remote
Process
Scan
repository history and current branches swept for credentials
Verify
each finding tested to see whether it is still live
Rotate
credentials replaced in a sequence that avoids outages
Prevent
scanning, hooks and update automation put in place
These are collected in the technical brief that opens in your dashboard the moment payment clears. The clock starts when they arrive, not before.
Answers
We can, but it rewrites history and disrupts every clone. Rotation is usually the better answer and we will explain why for your case.
Treat it as compromised and rotate immediately. We prioritise those on day one.
Yes, including npm, Composer and PyPI mirrors where you provide access.
This is engineering work, not a physical product — nothing ships and there is no stock to run out of. Delivery is to the working days stated above, into systems you control, and the refund terms set out what happens if we miss the date.
Booked alongside
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Fixed fee · GST incl.
₹29,999
A practical gap assessment against India DPDP Act 2023, covering consent, retention, notices and breach procedure.
Fixed fee · GST incl.
₹22,999
The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.
Fixed fee · GST incl.
₹44,999
Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.
Fixed fee · GST incl.
₹18,999
GST included
₹12,999
Capacity open this month
No discovery calls to find out a number, no statements of work that take three weeks to sign. Pick the engagement that matches the problem and we assign the engineers.