Founder-Led Pentest for Indian SaaS Startups

You hit SOC 2. You hit investor diligence. A prospect blocked the contract on a security questionnaire. Cybersecify runs a founder-led pentest of your SaaS application, API, and tenant isolation in 5 to 10 business days. A report your auditor can use as evidence. Free retest. Both founders on every engagement.

Why SaaS Founders End Up Here

Four reasons buyers consistently come to us. If one of these matches, you are in the right place. If none of these match, a pentest probably is not what you need yet. Tell us either way.

Compliance

A SOC 2 or ISO 27001 audit window opened

Your auditor wants pentest evidence with control mapping. The Growth Pentest plan ships SOC 2 Trust Services Criteria + ISO 27001 Annex A mapping per finding, plus a Letter of Attestation signed by the Lead Pen Tester.

Investor

A diligence checklist hit your inbox

Series A or growth-round investors expect a recent third-party pentest report. We deliver a developer-friendly report plus an executive summary your investor or board can read without a security background.

Enterprise

A customer security questionnaire is blocking the deal

Your prospect wants a pentest report and attestation letter before signing. We scope a single-application pentest in days, not weeks, so you can answer the questionnaire and unblock procurement.

Fear

A peer got breached or a near-miss landed in your logs

You saw a competitor pop up in the news. Your on-call paged on a suspicious request. You want a clear, prioritized list of what an attacker would actually exploit. A founder-led pentest gives you that, in plain language.

What a SaaS Pentest Covers

Scope is shaped to your application. The defaults below apply to almost every B2B SaaS engagement we run.

Web Application Layer

Authentication, password reset, MFA, session lifetime, account lockout, social login flows.

API Surface

REST, GraphQL, and gRPC endpoints. BOLA, BFLA, mass assignment, rate limiting, JWT misuse, and OAuth flow abuse.

Authorization + Tenant Isolation

Horizontal IDOR, vertical privilege escalation, cross-tenant access on every endpoint that accepts an ID parameter.

Integration Surfaces

Webhooks, third-party OAuth callbacks, embedded payment flows, file upload pipelines, and customer-facing API tokens.

Methodology

OWASP Web Security Testing Guide v5.0 + OWASP API Security Top 10 (2023) + PTES (Penetration Testing Execution Standard) as the engagement lifecycle. Manual business-logic testing on every engagement. Automated scanning is a baseline, not the report. Reports cite OWASP WSTG test IDs per finding so engineering teams can cross-reference the OWASP source directly.

Deliverables

Founder-reviewed report with reproduction steps, CVSS v3.1 scoring, business impact in plain language, and remediation guidance specific to your tech stack. One free retest within one month of report delivery. Growth Pentest plan adds SOC 2 Trust Services Criteria + ISO 27001 Annex A control mapping per finding, plus a Letter of Attestation signed by the Lead Pen Tester (OSCP) for buyer evidence packages. Audit-prep evidence is on the Growth plan only.

Two Plans. Founder-Led. Retest Included.

Pick the plan that matches the deadline you are working against. Both plans are delivered by the founders directly.

Startup Pentest

For early-stage SaaS

INR 74,999 + taxes
  • 1 scope (web, API, or mobile)
  • 5 business days
  • Founder-led, OSCP-certified
  • 6 founder consulting hours (6-month window)
  • Free retest within one month
See Full Breakdown
Audit-Prep

Growth Pentest

For funded SaaS facing SOC 2 or ISO 27001

INR 1,79,999 + taxes
  • 2 scopes (any combination)
  • 10 business days
  • Founder-led, OSCP-certified
  • SOC 2 + ISO 27001 audit-prep evidence
  • Letter of Attestation (OSCP-signed)
  • 12 founder consulting hours (12-month window)
  • Free retest within 30 days
See Full Breakdown

Audit-prep evidence is on the Growth plan only. Full pricing page covers extra-scope add-ons.

Why Founder-Led Matters for Indian SaaS

Both founders work on every engagement. Ashok Kamat owns scoping, threat modeling, business-logic review, and audit-evidence framing. Rathnakara GN (M.Sc Cyber Security, OSCP) leads the technical pentest. No handoffs to junior analysts, no offshore subcontracting, no account managers between you and the people running the test.

For Indian SaaS startups this matters because your buyer (investor, enterprise customer, or auditor) will read the report or speak to the team behind it. Founder accountability is the signal.

Response time on inbound questions: within a few hours most days, up to 2 business days under heavy load. Daily progress updates during the engagement. The same two people you talk to before signing are the two people delivering the work.

Frequently Asked Questions

How long does a SaaS pentest take?

A single-scope SaaS pentest with the Startup plan takes 5 business days from kickoff to report. A two-scope engagement under the Growth plan takes 10 business days. Daily progress updates keep you informed throughout. A free retest after remediation takes 1 to 3 business days and is included within one month of report delivery.

What is the difference between Startup and Growth Pentest?

Startup Pentest (INR 74,999) covers 1 scope in 5 business days, includes a developer-friendly report, 6 founder consulting hours useable within 6 months, and 1 free retest. Growth Pentest (INR 1,79,999) covers 2 scopes in 10 business days, adds SOC 2 + ISO 27001 audit-prep evidence with control mapping per finding, 12 founder consulting hours useable within 12 months, a Letter of Attestation signed by the Lead Pen Tester, and 1 free retest. Audit-prep evidence is Growth-only.

Do you include SOC 2 audit-prep?

Yes, on the Growth Pentest plan only. Each finding is mapped to SOC 2 Trust Services Criteria (CC6.1, CC6.6, CC6.7, CC6.8, CC7.1, CC7.2) and ISO 27001:2022 Annex A controls (A.8.8, A.8.25, A.8.26, A.8.28). The Letter of Attestation signed by the Lead Pen Tester (OSCP) supports buyer onboarding evidence and vendor risk assessments. Cybersecify delivers audit-prep evidence. We are not a SOC 2 or ISO 27001 certification body.

Can you pentest no-code or vibe-coded apps?

Yes. We pentest applications built on Bubble, Webflow with custom code, Retool internal tools, Airtable interfaces, FlutterFlow apps, and AI-assisted or vibe-coded codebases shipped via Cursor, Copilot, or v0. The methodology is the same: we test the running application, the API surface behind it, and the platform configuration. We document platform-specific risks like exposed workflow logic, public Airtable bases, or unauthenticated API endpoints that the no-code platform exposes by default.

What if our prospect needs the report by next Friday?

Talk to us early. The Startup plan delivers in 5 business days from kickoff once scope and credentials are in place. If your deadline is tighter than that, we can sometimes reshape the scope to fit, but we do not cut corners on methodology. If the timeline genuinely cannot fit a real pentest, we will tell you and recommend a different evidence path so you do not pay for a report that will not stand up to the buyer review.

Get a Pentest Scope on the Calendar

A 30-minute founder-led call. We scope the engagement, walk through deliverables, and answer what you actually need to know. No pitch deck.

Book a Discovery Call