Penetration Testing, VAPT & Compliance Readiness

Founder-led penetration testing across AI, web, API, mobile, cloud, and IoT, with real-world attack simulation and ISO 27001 and SOC 2 audit readiness. We help you test your security posture and produce the evidence your certification needs.

01

Penetration Testing

We simulate real-world attacks across your applications, APIs, cloud infrastructure, and devices, uncovering vulnerabilities before attackers do.

Both pentest plans include 1 free retest within one month of the report.

Testing a SaaS product for SOC 2, investor diligence, or enterprise onboarding? See our SaaS pentest for India.

02

Audit & Compliance

We help startups and growing businesses reach ISO 27001, SOC 2 and India DPDP Act readiness through structured internal audits, gap assessments, and readiness programs, combining technical validation with governance, documentation, and remediation support.

  • ISO 27001: Information Security Management Audit
  • SOC 2 Type 1: Point-in-Time Control Assessment
  • SOC 2 Type 2: Ongoing Control Effectiveness Audit
  • DPDP Act: India data protection readiness and evidence
  • Gap Analysis & Readiness Assessment
  • Policy & Procedure Documentation
  • Evidence Collection & Audit Preparation
03

Platform Programmes

Amazon, Shopify and Microsoft each gate access to customer data behind a security programme. We deliver the testing and the evidence each one asks for. No separate price list: a programme is scoped onto the plans above.

Amazon SP-API Data Protection Policy

What it requires: Applications holding a restricted role must have an annual penetration test. Clause 2.7.2 names the scope categories and is silent on who performs the test. The report is evidence you hold rather than evidence you file: Amazon requires you to keep records and to certify compliance on written request, with a right to audit.

What we deliver: The penetration test and the report an SP-API submission takes, with findings mapped to the numbered sections of the Data Protection Policy. Clause 2.7.2 enumerates four scope categories, so a DPP engagement is normally four scopes: the web application, the API, the network and the cloud. That is the Growth plan plus two additional scopes, and the page carries the price and the timeline before you talk to us.

Shopify Partner protected customer data

What it requires: Apps requesting protected customer data must meet the Level 1 and Level 2 control lists: sixteen controls covering access, encryption, separation, logging, retention and an incident response policy. Shopify does not mandate a penetration test to list an app, and we publish that plainly. What it does require is proof of compliance on request, systems configured to Internet industry standards, a 24 hour breach notification, and evidence at a Level 2 data protection review. Testing is how that proof gets produced.

What we deliver: Mainly the penetration test, with findings indexed against the sixteen Level 1 and Level 2 controls so you can show where each one is touched. Note the limit we publish: those controls contain no testing requirement, so the index shows coverage, it does not evidence the organisational controls themselves. Where an app is suspended and going through reinstatement, that comes with the incident response work the reinstatement needs: readiness on the security incident response policy control 7 requires, and the independent post-incident assessment and written report that produce Section 8 proof. Shopify alone decides reinstatement and we will never claim otherwise.

Microsoft 365 Certification

What it requires: The certification assessment requires an independent penetration test, with the report submitted as evidence alongside the control documentation.

What we deliver: The independent penetration test and the report the assessment takes. The certification itself is issued by Microsoft through its own assessor. We deliver and evidence the testing leg; we do not issue the certification.

Working to a platform deadline? Say which programme and the date on the contact form. It changes how we sequence the work.

Every pentest scope above is priced the same way: Startup INR 74,999 for one scope, Growth INR 1,79,999 for two. If you would rather see what you receive before talking to anyone, the sample report is published without an email gate.

Frequently Asked Questions

What security services does Cybersecify offer?

Cybersecify is a penetration testing firm. Penetration testing and VAPT across AI, web, API, Android, iOS, desktop, cloud, IoT, internal network and external network is our core work, with real-world attack simulation on the Growth plan. We also provide audit and compliance readiness for ISO 27001 and SOC 2. Both co-founders are hands-on across every engagement, and the team is based in Bengaluru, India. If you are comparing local providers, we wrote a guide on how to choose a pentest company in Bangalore.

How much does a penetration test cost and how long does it take?

The Startup Pentest is INR 74,999 and covers 1 scope in 5 business days, with 6 hours of founder-led consulting and 1 free retest. The Growth Pentest is INR 1,79,999 and covers 2 scopes in 10 business days, adding SOC 2 and ISO 27001 evidence, 12 hours of founder-led consulting, and 1 free retest. Timelines are quoted in business days, Monday to Friday. Both plans include a free retest within one month of the v1.0 report.

Do you run the SOC 2 audit and issue the certification, or just the penetration test?

We deliver the penetration test and the audit-readiness work: gap analysis, control implementation guidance, evidence collection, and the pentest evidence auditors expect. We do not issue the SOC 2 report or the ISO 27001 certificate ourselves. A SOC 2 report is issued by a licensed CPA firm and ISO 27001 certification by an accredited certification body. What we do provide, on the Growth plan, is our own Letter of Attestation signed by our lead penetration tester, confirming the test was performed and the fixes retested. That letter supports your audit and your customer security reviews, but it is not the SOC 2 report itself.

Who actually does the work, and is it really founder-led?

Yes. Both co-founders are involved in every engagement. Rathnakara GN (OSCP) leads the hands-on technical testing. Ashok Kamat handles scoping, business-impact framing, and compliance alignment. The people who scope your engagement are the people who run it. No junior analysts, no offshore handoffs. Senior team members hold certifications including CISSP, CEH, CREST, CompTIA PenTest+ and ISO 27001 Lead Auditor.

What is included with a pentest plan besides the test itself?

Every pentest plan includes a detailed report with an executive summary and technical findings, developer-friendly remediation guidance, founder-led consulting hours (6 hours on Startup, 12 hours on Growth), and 1 free retest within one month of the v1.0 report. The retest verifies your fixes and produces a v2.0 report. The Growth plan adds SOC 2 and ISO 27001 control mapping per finding and a Letter of Attestation signed by our lead penetration tester.

Which service do I need: penetration testing or audit and compliance?

If a customer, investor, or auditor has asked for a penetration test, or you are onboarding an enterprise client, start with a pentest. If you are working toward ISO 27001 or SOC 2, the audit and compliance track takes you from gap analysis to audit-ready. Many startups combine a pentest with compliance work, since the pentest evidence feeds directly into a SOC 2 or ISO 27001 audit. If you are unsure, tell us your trigger and we will point you to the right starting point.

Do you cover Amazon SP-API, Shopify Partner, or Microsoft 365 Certification requirements?

Yes, and they are not priced separately. A programme is a compliance requirement that maps onto the scopes in our plans rather than a product of its own, so you buy a Startup or Growth engagement scoped to what it demands. The three differ and we will not flatten them. Amazon SP-API requires an annual penetration test for restricted roles and says nothing about who may perform it, and we map findings to the numbered sections of the Data Protection Policy. Microsoft 365 Certification requires an independent penetration test whose report cannot be scanner output, and Microsoft issues the certification itself through its own assessor, so we deliver and evidence the testing leg. Shopify does not mandate a penetration test to list an app, and any vendor telling you otherwise is wrong. What Shopify requires is proof of compliance on request, so we index findings against the sixteen Level 1 and Level 2 controls, and where an app is suspended we add the incident response work reinstatement needs. Shopify alone decides reinstatement and we will never claim to deliver that outcome.