Skip to content
Scope, price and timeline published on every engagement page Engineers assigned within 3 working days of kickoff Your repositories, cloud accounts and licences stay in your name
Security & Compliance Most booked Fixed scope

Web Application VAPT

A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.

Delivered in

12 working days

Revisions

One round, included

Ownership

Yours from day one

Overview

What this engagement is

Automated scanners find the obvious. They do not find the endpoint that lets one customer read another customer's invoices by changing a number in the URL. This is a manual test, run against OWASP Top 10 and business logic, by someone thinking like an attacker with a valid account. Every finding comes with reproduction steps and evidence, so your developers are not left arguing about whether it is real. A free retest after remediation confirms the fixes worked, and you get a summary letter suitable for customers who ask.

Deliverables

What lands in your repositories

7 items
  • Manual penetration test covering authentication, authorisation and business logic
  • OWASP Top 10 coverage plus API-specific testing
  • Findings rated by CVSS with reproduction steps and evidence
  • Broken access control testing across every user role you have
  • Executive summary written for non-technical readers
  • Remediation guidance specific to your stack, not generic advice
  • One free retest within 30 days plus a summary letter for customers

Outcomes

What changes once it ships

Real vulnerabilities found before someone else finds them

A report you can send to customers and auditors

Fixes verified rather than assumed

Process

How the 4 stages run

  1. 01

    Scope

    targets, roles, test accounts and rules of engagement are agreed

  2. 02

    Test

    manual testing over several days, with critical findings reported immediately

  3. 03

    Report

    findings written up with evidence and remediation guidance

  4. 04

    Retest

    fixes verified and the report updated once your team is done

Booked most often by

  • Products handling payments, health records or personal data
  • Companies asked for a penetration test report by an enterprise buyer
  • Teams that have never had an external security review

What we need from you

  • Test accounts for every role, on staging or a production-like environment
  • Written authorisation to test, signed by someone who can give it
  • A developer contact for any critical finding we need to report urgently

These are collected in the technical brief that opens in your dashboard the moment payment clears. The clock starts when they arrive, not before.

Answers

Questions this engagement raises

Preferably staging. Where production is unavoidable we agree strict limits and timing, and we do not run destructive tests.

It follows the format auditors and enterprise security teams expect for SOC 2, ISO 27001 and customer due diligence.

You get that in writing, which is itself worth having. It has happened, though rarely on a first test.

This is engineering work, not a physical product — nothing ships and there is no stock to run out of. Delivery is to the working days stated above, into systems you control, and the refund terms set out what happens if we miss the date.

Booked alongside

Engagements that pair with this one

All Security & Compliance

SOC 2 Evidence Groundwork

The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.

Control gap assessment against the Trust Services Criteria you are scoping
30 working days Scope published

Fixed fee · GST incl.

₹44,999

GST included

₹29,999

Capacity open this month

Read the scope. Know the price. Start on Monday.

No discovery calls to find out a number, no statements of work that take three weeks to sign. Pick the engagement that matches the problem and we assign the engineers.