Manual, exploit-driven VAPT services for web applications, mobile apps, APIs, cloud and networks — delivered from Delhi NCR to clients across India and worldwide. We break in the way a real attacker would, then hand your developers the exact fix.
An automated scan tells you a parameter looks injectable. A penetration test shows you the 40,000 customer records it pulled out, the admin session it hijacked and the S3 bucket it reached from there. That gap — between a theoretical finding and a proven breach — is the entire point of hiring a human.
Roughly 70% of what we report on a typical engagement is invisible to scanners: broken object-level authorisation, business-logic abuse, race conditions in payment flows, tenant isolation failures and privilege escalation chains. Those are the findings that end up in breach post-mortems.
Every engagement is fixed-price, scoped in writing, and ends with a free retest so you can prove the holes are actually closed.
// illustrative output — client identifiers redacted
Most clients start with one and expand. Each can be booked standalone or combined into a full-scope engagement.
Full OWASP Top 10 and ASVS Level 2 coverage — injection, broken access control, SSRF, deserialisation, plus the business-logic abuse no scanner has a signature for.
Static and dynamic analysis against OWASP MASVS: insecure local storage, certificate pinning bypass, hardcoded secrets, root/jailbreak detection and the backend the app talks to.
Endpoint enumeration, BOLA and BFLA, mass assignment, rate-limit bypass, JWT flaws and GraphQL introspection abuse — mapped to the OWASP API Security Top 10.
Perimeter testing from the internet and assumed-breach testing from inside the LAN: exposed services, weak credentials, SMB and Active Directory attack paths, lateral movement.
IAM privilege escalation paths, public storage, over-permissive roles, exposed metadata services, insecure defaults and misconfigured security groups.
Rogue access points, WPA2/WPA3 handshake attacks, guest-network segmentation failures and captive-portal bypass across your office footprint.
Authorised phishing, smishing and pretext calling campaigns that measure your real human attack surface — then feed the results into targeted staff training.
Goal-oriented, multi-vector, low-and-slow simulation of a real threat actor. Tests your detection and response, not just your patch level.
Prompt injection, tool-abuse and data-exfiltration testing for LLM features and autonomous agents — aligned to the OWASP Top 10 for LLM Applications.
Aligned to PTES, the OWASP Web Security Testing Guide and NIST SP 800-115 — so your auditor recognises the process and your engineers can follow the trail.
NDA signed, targets agreed, testing windows fixed, escalation contacts named and an authorisation-to-test letter executed. Nothing is touched before this document exists.
Passive and active intelligence: subdomain and asset discovery, technology fingerprinting, exposed credential checks against breach corpora, and public exposure mapping across code repos and cloud storage.
Port, service and application scanning to inventory the full attack surface, followed by manual enumeration of parameters, endpoints, user roles and trust boundaries that automation walks straight past.
We map the discovered surface against realistic attacker goals for your business — steal the customer database, move money, take over an account — so testing effort lands where a breach would actually hurt.
The manual core of the engagement. Creative, chained exploitation to prove real impact: injection, broken access control, authentication bypass, race conditions and business-logic abuse.
Where authorised, we demonstrate privilege escalation, lateral movement and how much data is actually reachable from the first foothold — the difference between “a bug” and “a breach.”
Executive summary, CVSS v3.1 rated findings with proof of concept, developer-ready remediation, a live read-out call with your engineers, and a free retest to confirm the fixes hold.
Before a full engagement we run a short, non-intrusive trial audit and hand back an audit trail: every issue logged, scored, tied to a business consequence and given a deadline. Below is that exact deliverable from a live assessment — client identity anonymised as Test Site.
These items are a sample from a short, non-intrusive trial scan. They show the kind of risk present rather than the full list. A complete audit finds, confirms and prioritises every issue across every system and regulation.
From publicly available signals alone we mapped this snapshot of the client's digital footprint. No credentials, intrusive scanning or exploitation were used to gather it.
This footprint tells us the client collects and stores personal data of website visitors — which brings it squarely within scope of India's DPDP Act 2023 and, for EU visitors, GDPR.
A partial log of issues identified during the trial, each mapped to its business impact and a recommended remediation window.
| ID | Finding | Severity | CVSS | Business impact | Fix by |
|---|---|---|---|---|---|
| TA-01 | Missing HTTP security headers | CRITICAL | 9.1 | Clickjacking, injection & SSL-strip exposure of visitor data | 24 hrs |
| TA-02 | Email domain can be spoofed (no DMARC/DKIM) | CRITICAL | 9.3 | Business-email compromise & invoice fraud impersonating your brand | 24 hrs |
| TA-03 | Unprotected contact-form endpoint | HIGH | 8.6 | Spam floods & poisoned lead data; infrastructure abused on your behalf | 7 days |
| TA-04 | No HTTPS enforcement (SSL stripping) | HIGH | 8.2 | Session interception & data capture on untrusted networks | 7 days |
…and more. This is a partial trial log — additional findings across TLS configuration, consent handling, information disclosure and resource integrity are withheld from this preview and confirmed in the full engagement.
Left unaddressed, gaps like these expose a business to statutory penalties alongside direct commercial harm. Figures below are statutory maximums — indicative of exposure, not assessed fines.
| Framework | What can trigger it | Maximum exposure |
|---|---|---|
| DPDP Act 2023 | Failure to take reasonable security safeguards to prevent a data breach | Up to ₹250 crore |
| DPDP Act 2023 | Failure to notify the Data Protection Board & affected users of a breach | Up to ₹200 crore |
| GDPR (EU visitors) | Processing personal data without a lawful basis or valid consent | €20M or 4% of global turnover |
| IT Act 2000 §43A | Negligence in handling sensitive personal data causing wrongful loss | Uncapped compensation |
Beyond fines: mandatory breach disclosure, loss of client contracts and remediation under deadline — typically far costlier than fixing proactively.
…further observations under the IT Act & SPDI Rules and PCI-DSS relevance are reserved for the full assessment.
These findings are practical, not hypothetical. Each one points to an attack that takes little effort to carry out, and to a legal obligation that already applies. The good news: most of what a trial audit surfaces is inexpensive to fix and removes a large share of the risk.
Request a free trial audit for your site →No “contact us for pricing.” Below is a real, unedited BytePatch quotation format for a mid-sized SaaS web application and its API — line items, tester-days, day rate, taxes and terms. Your numbers change with scope; the structure does not.
| # | Line item | Scope unit | Days | Rate | Amount |
|---|---|---|---|---|---|
| 01 | Scoping, threat modelling & rules of engagement | 1 engagement | 0.5 | ₹12,000 | ₹6,000 |
| 02 | Web application penetration test — OWASP Top 10 + ASVS L2 | 1 app, ~60 screens | 4.0 | ₹12,000 | ₹48,000 |
| 03 | REST API penetration test — OWASP API Top 10 | 42 endpoints | 2.0 | ₹12,000 | ₹24,000 |
| 04 | Authentication, session & access-control testing (IDOR / BOLA) | 3 user roles | 1.0 | ₹12,000 | ₹12,000 |
| 05 | Business-logic abuse testing | 6 critical flows | 1.0 | ₹12,000 | ₹12,000 |
| 06 | External infrastructure & TLS configuration review | 4 hosts | 0.5 | ₹12,000 | ₹6,000 |
| 07 | Reporting — exec summary, CVSS v3.1 findings, PoC, remediation | 1 report | 1.5 | ₹12,000 | ₹18,000 |
| 08 | Remediation read-out call + developer Q&A | 90 minutes | 0.25 | ₹12,000 | ₹3,000 |
| 09 | Retest of remediated findings (within 30 days) | 1 cycle | 1.0 | — | Included |
| 10 | Retest letter & security attestation for your clients | 1 document | — | — | Included |
Sample figures for illustration. Your quotation is issued after a free 30-minute scoping call — book one here or build a rough number yourself with the instant estimate tool.
Starting prices in INR, exclusive of GST, at standard delivery. Final quote is fixed after a free scoping call.
Every issue in your report is written like this: scored, evidenced, reproducible, and closed with a fix a developer can actually ship.
Any authenticated user can read any other tenant's invoices by incrementing a numeric ID. During testing this exposed 41,206 invoice records across 380 tenants, including GSTINs, billing addresses and order values — a reportable personal-data breach under the DPDP Act.
Authorise on the object, not the route. Resolve the tenant from the session server-side and scope every query to it — never trust an identifier supplied by the client.
Then add a regression test asserting a 404 for cross-tenant IDs, and sweep the remaining 11 endpoints that take a resource ID in the path.
Two pages your board, your insurer and your biggest client can all read. Risk posture, business impact and the three things to fix first — no jargon.
Every issue with a CVSS v3.1 vector, CWE reference, OWASP mapping, reproduction steps and screenshot or request/response proof of concept.
Prioritised by real risk, not scanner severity. Written for the developer who has to close it, with code-level guidance for your actual stack.
A live session with your engineering team to walk the findings, answer questions and agree the fix order before anyone opens a ticket.
We retest the remediated findings free within 30 days and issue a retest letter you can hand to clients, auditors and procurement teams.
All collected evidence and client data is destroyed 30 days after sign-off, confirmed to you in writing. Your data does not live on our disks.
Industry-standard offensive tooling, plus the custom scripts we write for your specific stack. Tools find the surface; the tester finds the breach.
Every finding is mapped to the frameworks you actually get assessed against, so one test satisfies several obligations at once.
A focused assessment of one web app starts at ₹16,000. A full manual grey-box test typically runs ₹35,000–₹90,000 depending on roles, endpoints and logic flows in scope. Full-scope engagements start around ₹64,000. We quote a fixed price after a free scoping call — no hourly surprises.
VAPT bundles two things. The vulnerability assessment is broad and mostly automated. The penetration test is narrow and manual — a human exploits those weaknesses, chains them and proves business impact. Most compliance regimes want both.
A single web app is 5–10 working days from kickoff: 3–6 days testing, 1–2 days reporting, then the read-out. Full-scope engagements run 3–6 weeks. The retest is scheduled separately and usually takes a day.
No. Most engagements are grey box — you give us test credentials per role and we work from outside like an attacker with a valid account. White-box access finds more, faster, and we recommend it for high-risk systems, but it's optional.
No. DoS and load testing are explicitly out of scope unless commissioned. We throttle automation, agree testing windows in writing, and run anything potentially intrusive only with your written approval. Where staging mirrors production, we prefer to test there.
Yes — when authorised. Unauthorised access is an offence under Sections 43 and 66 of the IT Act, 2000. Every engagement starts with a signed authorisation-to-test letter and written rules of engagement. We never test an asset you can't demonstrate authority over.
At minimum annually, and after any major release, architecture change, cloud migration or acquisition. SOC 2 and ISO 27001 programmes generally expect an annual test plus a retest. Fast-shipping product teams often move to quarterly.
Yes. Every finding ships with remediation written for the developer who has to close it. We run a read-out call, stay available during remediation, and retest the fixes free within 30 days.
Red-team engagements, phishing simulations and adversary emulation from certified ethical hackers.
Read more →The full security programme — audits, threat modelling, zero-trust design, compliance and incident response.
Read more →A practical developer's guide to the ten risks we test for on every web application engagement.
Read more →Free 30-minute scoping call, a fixed-price quotation within 24 hours, and an NDA signed before a single detail is shared.