SOC 2 Evidence Groundwork
The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.
Fixed fee · GST incl.
₹44,999
Scope, price and timeline published on every engagement page
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Delivered in
12 working days
Revisions
One round, included
Ownership
Yours from day one
Overview
Automated scanners find the obvious. They do not find the endpoint that lets one customer read another customer's invoices by changing a number in the URL. This is a manual test, run against OWASP Top 10 and business logic, by someone thinking like an attacker with a valid account. Every finding comes with reproduction steps and evidence, so your developers are not left arguing about whether it is real. A free retest after remediation confirms the fixes worked, and you get a summary letter suitable for customers who ask.
Deliverables
Outcomes
Real vulnerabilities found before someone else finds them
A report you can send to customers and auditors
Fixes verified rather than assumed
Process
Scope
targets, roles, test accounts and rules of engagement are agreed
Test
manual testing over several days, with critical findings reported immediately
Report
findings written up with evidence and remediation guidance
Retest
fixes verified and the report updated once your team is done
These are collected in the technical brief that opens in your dashboard the moment payment clears. The clock starts when they arrive, not before.
Answers
Preferably staging. Where production is unavoidable we agree strict limits and timing, and we do not run destructive tests.
It follows the format auditors and enterprise security teams expect for SOC 2, ISO 27001 and customer due diligence.
You get that in writing, which is itself worth having. It has happened, though rarely on a first test.
This is engineering work, not a physical product — nothing ships and there is no stock to run out of. Delivery is to the working days stated above, into systems you control, and the refund terms set out what happens if we miss the date.
Booked alongside
The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.
Fixed fee · GST incl.
₹44,999
A practical gap assessment against India DPDP Act 2023, covering consent, retention, notices and breach procedure.
Fixed fee · GST incl.
₹22,999
We find the credentials committed to your repositories, rotate them, and set up scanning so it stops happening.
Fixed fee · GST incl.
₹12,999
Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.
Fixed fee · GST incl.
₹18,999
GST included
₹29,999
Capacity open this month
No discovery calls to find out a number, no statements of work that take three weeks to sign. Pick the engagement that matches the problem and we assign the engineers.