Penetration testing services
What we test, and what that covers.
Scope is written out for every service—areas covered, methodology, duration and exactly what you receive at the end.
Web Application Penetration Test
Manual testing of an authenticated web application against the OWASP ASVS, looking for the logic and access-control flaws that scanners do not find.
- Typical duration
- 5–8 working days
- Starting price
- From ₹45,000
AI & LLM Application Security Assessment
Security testing for applications built on large language models — the chat interface, the RAG pipeline, and the tools the model is allowed to call. Mapped to the OWASP Top 10 for LLM Applications.
- Typical duration
- 6–12 working days
- Starting price
- From ₹60,000
API Penetration Test
REST and GraphQL testing against the OWASP API Top 10, with particular attention to object-level authorisation — the flaw class that most often survives a web app test.
- Typical duration
- 4–7 working days
- Starting price
- From ₹40,000
Mobile Application Penetration Test
Android or iOS testing against the OWASP MASVS, covering the client binary, local storage and the backend it talks to. Priced per platform.
- Typical duration
- 5–8 working days per platform
- Starting price
- From ₹50,000 per platform
External Network Penetration Test
Everything you expose to the internet, enumerated and tested — including the assets you had forgotten were there.
- Typical duration
- 4–8 working days
- Starting price
- From ₹55,000
Internal Network & Active Directory Assessment
An assumed-breach assessment of everything reachable from inside your network: Active Directory, shared resources, infrastructure, and the estate that rarely gets tested — cameras, door controllers, printers and management interfaces.
- Typical duration
- 10–20 working days
- Starting price
- From ₹1,50,000
Cloud Configuration Review
AWS, Azure or GCP configuration reviewed against the provider benchmark and against how the environment is actually used.
- Typical duration
- 5–10 working days
- Starting price
- Scoped per engagement
Secure Code Review
Manual review of the source, following the data from entry point to sink. Finds the classes of flaw that black-box testing structurally cannot reach.
- Typical duration
- 5–12 working days
- Starting price
- Scoped per engagement