Security services
that find what scanners miss.
Every engagement powered by B-52 — our AI-powered pentesting and red-teaming platform — backed by three-layer expert review.
Testing and response services
Web Application Penetration Testing
Deep manual testing of business logic, auth, API, and OWASP ASVS L2/L3 with AI-validated coverage.
Vulnerability Assessment & Penetration Testing
Comprehensive security testing to identify and exploit vulnerabilities
Mobile Application Security Testing
MASVS-aligned iOS and Android binary analysis, reverse engineering, and mobile-specific vulnerability testing.
Network Penetration Testing
Internal and external network assessments with infrastructure hardening guidance, incl. Active Directory + assumed-breach.
API Security Testing
REST, GraphQL, gRPC, WebSocket - OWASP API Top 10 (2023) with deep business logic analysis.
Cloud Security Assessment
AWS, Azure, GCP security assessments with CIS benchmarks + IAM graph analysis and compliance mapping.
Secure Code Review
Manual and AI-assisted source code analysis with technology-specific remediation guidance. SAST + SCA included.
Red Team Assessment
Full adversary simulation - OSINT, social engineering, exploitation, lateral movement. MITRE ATT&CK aligned.
AI-Resilient VAPT
B-52 powered VAPT positioned against the SEBI AI advisory. AI-augmented attacker + AI-system-defender tracks.
AI Security Testing
AI security testing for LLMs, agentic pipelines and RAG systems.
Breach and Attack Simulation
Validate your security controls with human-led breach and attack simulation.
Configuration and Hardening Review
Server hardening, firewall rule base, network architecture and access control, reviewed against CERT-In benchmarks and CIS baselines by an empanelled auditor.
DevSecOps and CI/CD Security
Security testing triggered from your pipeline, and review of the pipeline itself: IaC, runners, secrets, image signing. Findings arrive as issues, not a PDF.
OT/SCADA Security
Expert OT penetration testing & industrial security assessments for critical infrastructure.
Microsoft 365 Red Team & Identity Attack-Path Assessment
Adversary simulation against your Microsoft 365 tenant: device-code phishing, OAuth token theft, rogue device registration, Graph-based exfiltration.
RASP Security Assessment
Independent assessment of mobile application protections: RASP, obfuscation, anti-tamper, root and jailbreak detection, tested on the APK and IPA you publish. CERT-In empanelled since 2008.
Incident Response
24/7 cyber incident response and digital forensics by CERT-In empanelled experts.
Ransomware Response
Ransomware attack?
Where we write about this in more depth
VAPT India — a library on how penetration tests are scoped and priced, what a report should contain, and which Indian regulators require testing. Red Team India — on adversary simulation — how engagements are scoped, what the report says about your detection, and where Indian regulators ask for it. Security Certification India — on who actually issues an ISO 27001 certificate, why the firm that prepares you cannot be the firm that certifies you, and what "SOC 2 certified" means when no such certificate exists. PCI DSS India — on who produces which artefact in a PCI DSS engagement, what Requirement 11 asks of testing, and where the Indian regulators sit alongside the standard.
Compliance
Audit-ready reporting for every framework
As a CERT-In empanelled firm since 2008, our reports are written for the submission they are going into.
MAS TRM Compliance — Technology Risk Management Audit
MAS Technology Risk Management compliance and audit services. Meet Singapore TRM guidelines with CERT-In empanelled assessments and gap analysis.
RBI Cybersecurity Framework Compliance
RBI cyber security compliance for banks, NBFCs and cooperative banks. CERT-In empanelled since 2008.
ISO 27001 Consulting
ISO 27001 certification India: ISMS implementation, gap assessment, internal audit and coordination with your accredited certification body.
CERT-In Compliance
Empanelled by CERT-In since 2008. What empanelment means, which audits require it, how the process works, and how to verify an auditor's current status.
SEBI CSCRF Compliance
SEBI CSCRF compliance for stock brokers, AMCs, mutual funds and MIIs, from a CERT-In empanelled auditor, with VAPT, ASM and BAS bundled into one cycle.
SOC 2 Compliance
SOC 2 Type 2 audit readiness for Indian SaaS: Trust Services Criteria gap analysis, evidence and monitoring. The report is issued by an independent CPA firm.
PCI DSS Compliance
1 compliance with CERT-In empanelled, QSA-ready assessments. End-to-end payment flow testing and gap analysis.
System Audit Report (SAR) for Data Localisation
SAR is the System Audit Report that RBI and NPCI mandate. CERT-In empanelled since 2008, we verify payment data is stored only in India.
IRDAI Cybersecurity Compliance
IRDAI Information and Cyber Security Guidelines, 2026 compliance for insurers, brokers and TPAs. CERT-In empanelled ISNP and IS audits, scoped to your entity.
DPDP Act Compliance for Indian Enterprises
DPDP Act 2023 compliance, gap analysis & audit readiness for Indian enterprises. DPDP Rules 2025 are live.
HIPAA Compliance
Expert HIPAA compliance services for Privacy Rule, Security Rule & Business Associates. Get comprehensive risk assessment & technical safeguards audit today.
NSE Trading Member VAPT
NSE VAPT submission for trading members under SEBI CSCRF. CERT-In empanelled auditor since 2008.
SBI VSCC (Vendor Site Compliance Certificate) Audit
VSCC is the Vendor Site Compliance Certificate SBI requires for ePay and payment gateway merchants. CERT-In empanelled since 2008, we sign the Form C.
UIDAI AUA-KUA Audit (Aadhaar Compliance)
AUA means Authentication User Agency, KUA e-KYC User Agency. CERT-In empanelled since 2008, auditing both annually for UIDAI with Sub-AUA and Sub-KUA in scope.
GDPR Compliance for Indian Businesses
GDPR compliance for Indian businesses serving EU customers. Gap analysis, DPIA, DPO advisory and audit-ready evidence, from a CERT-In empanelled firm.
Compliance-Focused Vendor Risk Assessment
Vendor risk assessment and TPRM audit for RBI, SEBI and NPCI compliance, delivered as a platform, as a managed service, or as a hybrid of the two.
NPCI / UPI Security and Compliance Audit
NPCI and UPI security audit for PSPs, TPAPs, sponsor banks, BBPS and RuPay. NPCI circular OC-215 requires an audit by a CERT-In empanelled auditor, annually.
RBI Payment Aggregator and Payment Gateway (PA-PG) Audit
RBI Payment Aggregator & Payment Gateway audit by CERT-In empanelled auditors. Annual system audit per 2025 PA Master Direction.
ATM and POS Security Audit
1.
IEC 62443 Compliance
IEC 62443 compliance for industrial control systems: OT security assessments, gap analysis and certification preparation.
Not sure where to start?
Our security architects will assess your risk profile and recommend the right combination of services.
Talk to an ExpertWorking out what to ask for? The types of security audit — what each one examines, and what the RBI Directions specify by clause.