)}

Penetration Testing in Bengaluru

Founder-led penetration testing for AI-first and API-first SaaS startups. Every engagement is led by Rathnakara GN (M.Sc Cyber Security, OSCP), with Ashok Kamat hands-on alongside him. No offshore handoff, no junior analyst delivering what a senior consultant sold.

The short version, if you are comparing vendors right now

Cybersecify is a penetration testing company based in Bengaluru. A single-scope test is INR 74,999 and takes 5 business days. Two scopes, typically a web application and the API behind it, is INR 1,79,999 over 10 business days, and adds SOC 2 and ISO 27001 evidence mapping for teams with an audit in front of them. Both plans include founder-led consulting hours and one free retest, returned as a full replacement report at v2.0.

Testing is manual, methodology-driven work against OWASP WSTG v4.2, OWASP ASVS 5.0.0, and PTES. Automated tooling is used for reconnaissance and surface mapping only. We do not ship scanner output as a penetration test report.

You can read the full deliverable before you talk to us. Our sample pentest report is published in full with no email gate, and pricing is public. The rest of this page is what a Bengaluru SaaS team actually needs to decide: how scoping works, what changes the price, what is out of scope, who does the testing, and what the Indian regulatory drivers really require.

Eight Questions to Ask Any Pentest Firm in Bangalore

Including us. These are the questions that separate a real engagement from an invoice with a PDF attached, and the answers below are ours.

01

Who will actually do the testing, by name?

Ask for the name and credentials of the person who will be in your application, not the name of the firm. Many quotes are won by a senior consultant and delivered by whoever is free. If the answer is a generic team description, ask again. On our engagements the answer is Rathnakara GN, who leads every pentest, with Abhinay on delivery and the team led by Theertha running L1 support during the test.

02

Is this a manual penetration test or a scanner report?

A scanner finds known signatures. It does not find that user A can read the invoices belonging to user B, because that requires understanding what an invoice means in your product. Ask what proportion of the engagement is manual and ask to see a sample finding that a scanner could not have produced. Broken authorization between tenants is the standard tell.

03

Can I see a real sample report before I sign?

The report is the product. A vendor who will not show you a redacted real one before you pay is asking you to buy an unseen deliverable. Ours is published in full at /sample-report/ with no email gate.

04

Is a retest included, and what does the retest produce?

A pentest that ends at the finding list leaves you with a document full of open issues, which is worse than useless in an audit or a data room. Ask whether retesting costs extra, how long you have to remediate before the free window closes, and whether you get a new report or an email saying it looks fixed.

05

What methodology do you follow, and which version?

Ask for named, released standards. OWASP WSTG v4.2, OWASP ASVS 5.0.0, OWASP API Security Top 10 2023, OWASP Top 10:2025, PTES, and NIST SP 800-115 are the ones that matter for application and API work. A vendor citing a version that has not been released is either careless with detail or hoping you will not check.

06

What is explicitly out of scope?

A vendor who cannot tell you what they will not do has not thought about the engagement. Denial of service, load and stress testing, social engineering of your staff, physical access, and third-party SaaS you do not own should all be out of scope by default and only added with written authorization.

07

What is the total price, and what triggers a change order?

Ask what happens if the application turns out to be larger than scoped, if a second environment appears mid-test, or if you want a third scope added. Fixed-price quotes that quietly become time and materials are the most common billing surprise in this market.

08

Who owns the report and the data you collect?

The report should be yours to share with auditors, investors, and customers without asking permission. Check what happens to the evidence, screenshots, and any data captured during testing when the engagement closes, and how long it is retained.

We wrote the longer version of this as a standalone guide: how to choose a penetration testing company in Bangalore, and a vendor-neutral list of questions to ask before signing.

Four Reasons Startups Buy a Pentest, and What Each One Needs

The reason you are buying should decide the scope and the plan. Most mis-scoped engagements come from skipping this step.

A compliance deadline

Growth Pentest

What it looks like: You are in a SOC 2 Type 2 observation window or an ISO 27001 certification cycle and the auditor has asked for evidence of application security testing.

What it needs: Findings mapped to controls, not just a finding list. The Growth Pentest includes SOC 2 and ISO 27001 evidence mapping, so each finding is tied to the control it evidences. Auditors ask for the remediation trail as well as the report, which is why the retest and v2.0 matter more here than anywhere else. Startup Pentest does not include this mapping.

An investor asked for it

Startup or Growth

What it looks like: A term sheet, a data room checklist, or a technical diligence call has produced the question: do you have a recent penetration test?

What it needs: A report an outsider can read. Diligence teams are usually not security specialists, so the executive summary and the risk narrative carry the weight. What they are really testing is whether you treat security as an engineering practice or as a document you bought. A v1.0 with open findings and a v2.0 showing them closed tells a better story than a thin clean report.

An enterprise customer is onboarding you

Growth Pentest

What it looks like: A security questionnaire has landed, procurement is asking for a third-party assessment, or the deal is held at the vendor risk review stage.

What it needs: Speed and specificity. The questionnaire usually names a scope, for example the production web application and the customer-facing API, and asks for testing within the last 12 months. Match the pentest scope to what the questionnaire names, not to what is easiest to test. Two scopes covering app and API is the common shape, which is the Growth Pentest base.

Something already happened

Talk to us first

What it looks like: Suspicious activity in logs, a customer reporting data they should not be able to see, a bug bounty style email from a stranger, or a near miss you cannot fully explain.

What it needs: Triage first, testing second. A pentest is not incident response, and running one on a live incident wastes both. The right sequence is to scope the incident, contain it, then test to find whether the same class of flaw exists elsewhere. If personal data was involved, the reporting clocks described further down this page start at detection, not after your investigation finishes.

A Bengaluru Pentest Firm, Not an Offshore Vendor

Being in the same city is not, on its own, a reason to hire anyone. Here is where it genuinely changes the engagement.

Same Timezone, Faster Kickoff

Scoping questions get answered the same day rather than on the next overlap window. That matters most during testing: when a tester hits an environment problem or needs a role provisioned, an hour of delay in a 5 business day engagement is real testing time lost.

In-Person Threat Modelling

An hour at a whiteboard with your engineers usually finds the parts of the system that are dangerous but undocumented: the internal admin tool, the legacy endpoint nobody owns, the tenant boundary that is enforced in one service but not another. That hour reliably improves the scope.

The Indian Regulatory Context

DPDP Act obligations, CERT-In incident reporting, and RBI expectations for anyone touching payments are the frameworks your buyers and auditors will actually ask about. We work in them daily rather than treating India as an export market.

Six Scope Types, Priced the Same Way

Every test type below is available as a standalone scope or combined into a multi-scope engagement. A scope costs the same and takes the same 5 business days whichever type it is.

Internal network testing is available from the Growth plan onward. There, one scope covers a single Active Directory domain, up to 256 live hosts, and up to 3 segmentation boundaries. Larger estates and multi-forest environments are quoted as a custom proposal rather than squeezed into a fixed price.

How Scoping Works, and What Actually Changes the Price

Scoping is the single decision that determines both what the test costs and whether it finds anything worth the money.

What counts as one scope

One scope is one application or one interface. A single web application is one scope. The API behind it is a second scope, because it is a separate attack surface with its own authorization model and its own set of consumers, and testing the web UI does not test it. An Android build and an iOS build are two scopes for the same reason: different local storage, different runtime protections, different platform behaviour. One cloud account is one scope. One IoT device family is one scope. This is why so many SaaS engagements land on two scopes, and why the Growth Pentest includes two as its base.

What raises the price

  • More scopes. This is the only lever in our pricing. A second scope on the Startup plan is INR 44,999 and adds 5 business days. On Growth, scopes beyond the base two are INR 74,999 each, and from the third onward they run in parallel up to 3 at a time, adding 5 business days per parallel batch. A 3 or 4 scope engagement therefore completes in 15 business days rather than stretching to a month.
  • Scale that breaks the fixed-price assumption. Internal network estates beyond one Active Directory domain, or engagements of 5 or more scopes, move to a custom scoping proposal. We would rather quote a timeline we can staff than take a fixed fee and cut testing depth to fit it.
  • Work that is not a pentest. Red team simulation, social engineering, and physical assessment are separate engagements with separate authorization. They are not silently folded into a pentest quote.

What does not raise the price

  • Finding a lot. The fee is the same whether we find 3 issues or 30. Any pricing model that varies with finding count creates an incentive nobody should want on either side of the table.
  • The retest. One full retest is included in both plans, covering every original finding rather than a sample.
  • Questions during and after the engagement. Startup includes 6 hours of founder-led consulting usable for 6 months from kickoff, Growth includes 12 hours usable for 12 months. Remediation pairing, an architecture question the test raised, or help answering a customer security questionnaire all come out of those hours.
  • Reasonable clarification of the target. If scoping reveals the application is materially larger than described, we tell you before testing starts and agree a change in writing. We do not discover it mid-engagement and invoice for it afterwards.

What to give us so the test is worth paying for

Almost all of the difference between a shallow test and a useful one is decided before day one, and most of it is on your side:

  • Test accounts for every role. At minimum two accounts in two different tenants, plus one account per privilege level. Without these, the entire authorization class of findings cannot be tested, and that class contains the issues that hurt most.
  • A staging environment that matches production. Same code, same authorization model, representative data shape. Where it diverges, tell us, and the divergence is recorded as a scope limitation in the report rather than quietly ignored.
  • API documentation if it exists, and no panic if it does not. A collection export or an OpenAPI spec saves reconnaissance time that gets spent on testing instead. We test undocumented APIs regularly; documentation simply buys you more depth for the same fee.
  • Allowlisting for your WAF and rate limiter. Otherwise a meaningful part of the engagement is spent measuring your WAF rather than your application.

If you want to work through this before talking to anyone, our guide on how to scope your first penetration test covers the same ground vendor-neutrally.

Scope to v2.0, in Business Days

Business days are Monday to Friday. The weekend is our quality buffer and is not counted against your timeline, which is why a 5 business day engagement is quoted as 5 and not as a vague "one week".

01

Scope and rules of engagement

Before day 1

We agree the exact targets, the environment to test against, the test accounts and roles you provide, the testing window, and what is out of bounds. You receive a written scope document and an authorization letter before any packet is sent. Nothing is tested that is not named in that document.

02

Reconnaissance and mapping

Day 1

Automated tooling maps the attack surface: endpoints, parameters, authentication flows, roles, and third-party dependencies. This is the only phase where tooling leads. Its output is a map, not a finding list.

03

Manual testing and exploitation

Days 1 to 4 per scope

The work that decides whether the engagement was worth paying for. Authorization boundaries between tenants and roles, business logic abuse, chained exploits, and privilege escalation are tested by hand against OWASP WSTG v4.2, OWASP ASVS 5.0.0, and PTES. Every candidate finding is proven with a working proof of concept before it goes in the report.

04

Report

Day 5 per scope

The v1.0 report is delivered at the close of the engagement: 5 business days for one scope, 10 for two. Each finding carries a CVSS score with the full vector, a CWE and OWASP category, steps to reproduce, the raw HTTP request and response, business impact, and remediation guidance written for the engineer who has to fix it.

05

Remediation support

Your timeline

Your engineers can talk directly to the people who found the issues. Startup Pentest includes 6 hours of founder-led consulting usable for 6 months from kickoff, Growth includes 12 hours usable for 12 months. Most teams spend these hours on remediation pairing and on the architecture question the pentest surfaced.

06

Retest and v2.0

Within one month of v1.0

When your fixes are in, we retest every original finding at no extra cost. The retest itself takes 1 to 3 business days. You receive report v2.0, a full replacement for v1.0 with updated status on every finding and fresh proof of the fixed state.

One point worth being explicit about, because it is where quoted timelines usually go wrong elsewhere: the fixed part of the schedule is testing and the v1.0 report. The retest is scheduled when your engineers have finished the fixes. One month from v1.0 is the latest the free retest can start, not a waiting period. If you remediate in a week, the engagement closes in a week.

What Is Actually in the Report

The report is the product. You should not have to buy it to see it, so ours is published in full.

A pentest report has two readers with opposite needs. Your CEO, your auditor, and your prospective customer need the risk picture in a page. Your engineers need enough detail to reproduce and fix each issue without a follow-up call. A report that serves only one of them fails the other, which is how firms end up shipping either a 200 page scanner dump or a two page summary nobody can act on.

For the decision makers

  • Executive summary with an overall risk rating and the top priorities in plain language
  • Scope and methodology: exactly what was tested, from where, in which environment, against which standards
  • Findings summary table with severity, status, and affected component
  • Scope limitations and out-of-scope items stated openly rather than buried

For the engineers

  • Per finding: CVSS score under v3.1 and v4.0 with the full vector, so the score can be reproduced and challenged
  • CWE identifier and OWASP Top 10:2025 category
  • Numbered steps to reproduce, the raw HTTP request and response, and annotated screenshots
  • Business impact written in terms of your product, not generic risk boilerplate
  • Remediation guidance aimed at the control that matters, with example patterns rather than copy-paste code we cannot test in your stack

Growth Pentest reports add a compliance evidence package mapping each finding to the SOC 2 and ISO 27001 control it evidences. Startup Pentest reports are structurally identical but omit that mapping. Both include the retest section that records the v1.0 to v2.0 remediation trail, which is usually the part an auditor or a diligence team reads most closely.

What We Do Not Do

Out of scope by default. Any of these can be added, but only on your written request and authorization.

Excluded unless you authorize it

  • Denial of service, load, and stress testing
  • Social engineering of your staff, including phishing simulation
  • Physical security assessment
  • Third-party SaaS and infrastructure you do not own or control

What a pentest is not

  • It is not incident response. If you think something has already happened, that is a different conversation and a different sequence
  • It is not a certification. We deliver audit preparation evidence, we are not a certification body or an attestation firm
  • It is not continuous. It is a snapshot of the scoped systems during the testing window
  • It is not a guarantee. Best-effort testing inside an agreed timebox will not find every possible flaw, and anyone claiming otherwise is overselling

The reason to publish this rather than leave it in the contract: a vendor who cannot tell you what they will not do has not thought carefully about the engagement. Every exclusion above also appears in the scope document you sign, and the report repeats the ones that applied so a reader six months later knows what the test did and did not cover.

Who Will Be in Your Application

Founder-led is a delivery promise, not a marketing line. It means both founders work on your engagement rather than appearing on the sales call and handing off.

Rathnakara GN

Co-founder and Chief Hacking Officer

Holds the OSCP and an M.Sc in Cyber Security from REVA University. Leads every penetration testing engagement we run. If you want to know who found the finding, this is usually the answer.

Ashok Kamat

Co-founder and CEO

Holds the CCIO certification from ISAC, at the Cadet level of the National Security Database programme. Hands-on across scoping, compliance mapping, and the reporting side of every engagement.

Behind the founders there is a named delivery bench rather than an anonymous pool. Abhinay owns pentest delivery. Theertha leads the team that runs L1 work during a test and owns retesting as its main line. You will know who is in your application before testing starts, and the report names its lead assessors.

At team level our certifications include CISSP, CEH, CREST, ISO 27001 Lead Auditor, and CompTIA PenTest+. We attribute those to the team because that is what they are. The OSCP and the M.Sc belong to Rathnakara individually, and we do not pluralise them into a claim about everyone here. If a vendor talks about "our OSCPs" without naming them, ask for the names.

The Standards We Test Against

Named, released versions. If a quote cites a version that has not been released, that is worth a follow-up question.

  • OWASP Web Security Testing Guide v4.2. The test-case backbone for web application work: identity management, authentication, authorization, session management, input validation, error handling, and business logic.
  • OWASP ASVS 5.0.0. The verification requirements we test against, useful when you need to state a security level to a customer or an auditor rather than just a finding count.
  • OWASP API Security Top 10 2023. API-specific risk classes, which differ enough from web risks that testing a UI does not cover them. Broken object level authorization is the one that most often turns out to be real.
  • OWASP Top 10:2025. The current edition, used as the reporting taxonomy so findings map to categories your engineers and auditors already recognise.
  • PTES. The engagement structure: pre-engagement, intelligence gathering, threat modelling, vulnerability analysis, exploitation, post-exploitation, reporting.
  • NIST SP 800-115. The technical guide auditors most often recognise when they ask which methodology an assessment followed.

Standards give the engagement coverage and repeatability. They do not find the interesting bugs on their own. The findings that justify the fee are the ones that require understanding your product: that a user in one tenant can reach an object belonging to another, that a workflow can be completed out of order to skip a payment step, that an endpoint enforces a role check on the UI path but not on the direct API call. Those come from manual testing by someone thinking about your business logic, which is why we use automated tooling for surface mapping and reconnaissance only.

See the Full Methodology

The Indian Rules That Actually Drive This Purchase

Three obligations come up in nearly every Bengaluru SaaS scoping call. None of them names penetration testing outright, which is exactly why the requirement gets misread.

DPDP Act 2023: reasonable security safeguards

Section 8(5) of the Digital Personal Data Protection Act 2023 requires every Data Fiduciary to take reasonable security safeguards to prevent a personal data breach. The Act does not define "reasonable" in technical detail and does not mention pentesting. In practice, the industry standards auditors and regulators fall back on, ISO 27001, SOC 2, and OWASP, all treat application security testing as a core component, which is why a current pentest report plus a remediation trail is the simplest defensible artifact to hold. The penalty for failure to take reasonable security safeguards resulting in a breach runs up to INR 250 crore. Note what that means practically: the report alone is not the evidence, the report plus proof you fixed what it found is.

CERT-In: 6 hours from detection

The CERT-In Directions of 28 April 2022, issued under Section 70B of the IT Act 2000, require cyber incidents listed in their Annexure I to be reported to CERT-In within 6 hours of noticing them. The word doing the work is "noticing". The clock starts at detection, not at occurrence and not when your investigation concludes. This is why a pentest and an incident response plan are complementary rather than interchangeable: the pentest tells you what an attacker could do, and the plan is what lets you meet a 6 hour deadline without an emergency legal review. We cover the mechanics in detail in our guide to the CERT-In 6-hour rule. One honest clarification, since this claim is made loosely in this market: CERT-In empanelment is a separate designation. We do not hold it and we do not claim it. It is required only if your sector or your customer independently demands an empanelled auditor, and for most SaaS pentests it does not.

Enterprise security questionnaires

Not a regulation, but for most Bengaluru SaaS companies this is the obligation that actually forces the purchase. A large Indian bank, an enterprise buyer, or an international customer sends a vendor security questionnaire, and somewhere in it is a question asking for evidence of independent application security testing within the last 12 months. Read the question carefully before scoping, because it usually names the systems it cares about. Scope the pentest to what the questionnaire names. Buying a test of the wrong surface is the most expensive scoping mistake we see.

Is the spend proportionate?

A fair question to ask any vendor, so here is the comparison using published figures rather than our own arithmetic. the IBM Cost of a Data Breach Report 2026 puts the average breach cost in India at INR 25.5 crore, an all-time high and a 15.9 percent rise on the INR 22 crore recorded for 2025. That is an all-sector average, not a SaaS-specific figure, and averages hide enormous variance.

The caveat matters more than the ratio, and you should apply it to anyone quoting these numbers at you, ourselves included: this compares a certain cost against an uncertain event, and no pentest removes breach risk. What a pentest reliably does is find the classes of flaw that scanners miss before someone else finds them, and produce evidence a buyer, an auditor, or an investor will accept. Treat the comparison as a sense of proportion, not a return on investment calculation.

Related reading: DPDP Act pentest requirements for Indian SaaS and penetration testing cost in India in 2026.

Transparent Pentest Pricing

Two plans, published. No discovery call required to find out what it costs.

Startup Pentest

For early-stage startups with one surface that matters

INR 74,999 + taxes
  • 1 scope: web app, API, mobile app, cloud, or IoT
  • 5 business days to the v1.0 report
  • Manual testing led by our OSCP-certified co-founder
  • 6 hours founder-led consulting, usable 6 months from kickoff
  • Developer-ready report with reproduction steps and fix guidance
  • 1 free retest within one month, returned as v2.0
  • Second scope INR 44,999, adds 5 business days, caps at 2 scopes
View Full Details
Most Popular

Growth Pentest

For funded teams with an audit or an enterprise deal in front of them

INR 1,79,999 + taxes
  • 2 scopes, any combination
  • 10 business days to the v1.0 report
  • Manual testing led by our OSCP-certified co-founder
  • 12 hours founder-led consulting, usable 12 months from kickoff
  • SOC 2 and ISO 27001 evidence mapping per finding
  • Real-world attack simulation beyond OWASP Top 10
  • Internal network testing available as a scope
  • 1 free retest within one month, returned as v2.0
View Full Details

Growth plan: additional scopes are INR 74,999 each, and scopes beyond the base two run in parallel up to 3 at a time, so a 3 or 4 scope engagement completes in 15 business days. Engagements of 5 or more scopes move to a custom scoping proposal. See the full pricing page for the complete breakdown.

Frequently Asked Questions

How much does penetration testing cost in Bengaluru?

Our Startup Pentest plan is INR 74,999 for 1 scope (web app, API, mobile app, cloud, or IoT) delivered in 5 business days. A second scope is INR 44,999 and adds 5 business days, with a maximum of 2 scopes on this plan. The Growth Pentest plan is INR 1,79,999 for 2 scopes delivered in 10 business days and adds SOC 2 and ISO 27001 evidence mapping and real-world attack simulation. Both plans include 1 free retest within one month of the v1.0 report. All prices exclude taxes.

How long does a penetration test take?

The engagement runs 5 business days per scope. One scope is 5 business days, two scopes is 10 business days. Business days are Monday to Friday and the weekend is our quality buffer, not counted against your timeline. From the third scope onward, which is a Growth plan capability because Startup caps at 2 scopes, scopes run in parallel up to 3 at a time and add 5 business days per parallel batch, so a 3 or 4 scope engagement completes in 15 business days. Engagements of 5 or more scopes move to a custom scoping proposal.

What counts as one scope?

One scope is one application or one interface: a single web application, a single API, one mobile platform, one cloud account, or one IoT device family. An Android app and an iOS app are two scopes because they are two builds with different storage and runtime behaviour. A web application and the API behind it are two scopes because they are two attack surfaces with different authorization models. Internal network testing is available from the Growth plan onward, where one scope covers a single Active Directory domain, up to 256 live hosts, and up to 3 segmentation boundaries.

Do you provide SOC 2 and ISO 27001 support?

The Growth Pentest plan includes SOC 2 and ISO 27001 evidence mapping, where every finding is tied to the control it evidences so the report can go straight into your audit evidence. The Startup plan does not include this mapping. To be clear about what this is and is not: we deliver audit preparation work, we are not an ISO 27001 certification body and we are not a SOC 2 attestation firm. A pentest report is one input to an audit, not a substitute for one.

What certifications does your team hold?

Team certifications include CISSP, CEH, CREST, ISO 27001 Lead Auditor, and CompTIA PenTest+. Rathnakara GN, our co-founder and Chief Hacking Officer, holds the OSCP individually and an M.Sc in Cyber Security from REVA University, and leads every penetration testing engagement. Ashok Kamat, co-founder and CEO, holds the CCIO certification from ISAC at the Cadet level of the National Security Database programme.

Who actually performs the test?

Rathnakara GN leads every penetration testing engagement and Ashok Kamat is hands-on alongside him. That is what founder-led means here: both founders work on your engagement rather than appearing on the sales call and handing off. Abhinay owns pentest delivery and Theertha leads the team that runs L1 work during the test and owns retesting. You will know the names of the people in your application before testing starts.

What is included in the retest and what does it cost?

The retest is included at no extra cost in both plans. After your team applies fixes, we re-test every original finding, not a sample, and confirm whether each one is remediated or still open. The retest itself takes 1 to 3 business days on our side. You receive report v2.0, which is a full replacement for v1.0 with updated status on every finding plus fresh proof of the fixed state for each one. The free retest window runs for one month from the v1.0 report, which is the latest the retest can start, not a mandatory wait.

What is explicitly out of scope in a Cybersecify pentest?

Denial of service testing, load and stress testing, social engineering of your staff, physical security assessment, and testing against third-party SaaS you do not own are out of scope by default. Any of them can be added, but only with your written request and authorization. We do not test what we are not authorized to test, and we say so in writing before the engagement starts.

Should we test staging or production?

Staging is the default when it is a faithful copy of production, because it removes the risk of affecting live customers. The requirement is that staging runs the same code, the same authorization model, and a representative data shape. Where staging diverges from production, that divergence becomes a scope limitation recorded in the report. Production testing is possible with agreed rate limits and a defined testing window, and the choice belongs to you.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment runs automated scanners to find known issues and produces a list. A penetration test uses manual work to confirm which of those issues are real, chain them together, and demonstrate business impact, and it finds the entire class of flaw that scanners cannot see at all, such as one tenant reading data belonging to another tenant. We use automated tooling for surface mapping and reconnaissance only. We do not ship scanner output as a penetration test report.

Do you only work with companies in Bengaluru?

No. We work with clients across India and internationally. Being based in Bengaluru means local clients can have in-person threat modelling sessions and same-timezone communication, and it means we work daily with the Indian regulatory context that applies to them. The testing methodology and the deliverable are the same regardless of where you are.

Does a penetration test guarantee our application is secure?

No, and any vendor who tells you otherwise is selling you something they cannot deliver. A penetration test is best-effort and it is a snapshot in time: it reflects the state of the scoped systems during the testing window, tested by people working within an agreed timebox. New code, new dependencies, and new attack techniques all change the picture after the report is issued. What a pentest reliably gives you is evidence of the flaw classes that were found and fixed, and a defensible record that you tested.