Web Application VAPT
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Fixed fee · GST incl.
₹29,999
Scope, price and timeline published on every engagement page
The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.
Delivered in
30 working days
Revisions
One round, included
Ownership
Yours from day one
Overview
SOC 2 fails on evidence, not on intentions. Auditors want to see that access reviews happened, that changes were approved, that backups were restored and logs retained, over a period of months. Retrofitting that after the window has started is painful. We implement the technical controls first: automated access reviews, change management through pull requests, centralised logging with retention, vulnerability management with SLAs. Evidence collection is automated where possible so your team is not screenshotting consoles the week before the audit.
Deliverables
Outcomes
Evidence accumulates automatically instead of being reconstructed
The observation window starts with controls already operating
Fewer auditor findings, which means a shorter and cheaper audit
Process
Assess
current controls compared against the criteria in scope
Implement
technical controls built and integrated with your existing tooling
Automate
evidence collection scheduled so it accumulates without manual effort
Rehearse
a mock evidence request run as an auditor would issue it
These are collected in the technical brief that opens in your dashboard the moment payment clears. The clock starts when they arrive, not before.
Answers
No. Audits must come from a licensed CPA firm. We prepare you and work alongside whichever auditor you choose.
The technical controls overlap heavily. ISO also needs an ISMS and management system documentation, which we scope separately.
Type II needs a three to twelve month observation window after controls are operating. This work shortens the run-up, not the window.
This is engineering work, not a physical product — nothing ships and there is no stock to run out of. Delivery is to the working days stated above, into systems you control, and the refund terms set out what happens if we miss the date.
Booked alongside
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Fixed fee · GST incl.
₹29,999
We find the credentials committed to your repositories, rotate them, and set up scanning so it stops happening.
Fixed fee · GST incl.
₹12,999
A practical gap assessment against India DPDP Act 2023, covering consent, retention, notices and breach procedure.
Fixed fee · GST incl.
₹22,999
Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.
Fixed fee · GST incl.
₹18,999
GST included
₹44,999
Capacity open this month
No discovery calls to find out a number, no statements of work that take three weeks to sign. Pick the engagement that matches the problem and we assign the engineers.