VAPT Services Built on Process, Platform, and Proof — Not Individual Heroics
Security Brigade delivers vulnerability assessment and penetration testing through a platform-driven methodology refined over 6,700+ assessments. CERT-In empanelled since 2008, trusted by more than 1,000 enterprises.
Trusted by India's leading enterprises
What you are buying
A scan finds what is known. A test finds what is yours
The distinction decides the price, the timeline and whether the report tells you anything you could not have generated yourself.
Automated scanning
Signature and version matching against a database of known issues. Fast, cheap, and necessary. It finds the missing patch and the expired certificate, and it cannot find a flaw that exists only in your application.
Vulnerability assessment
Systematic coverage of the estate with the output triaged by someone who can tell a real finding from a scanner artefact. The value is in the triage: an untriaged scan report transfers work to you and calls it a deliverable.
Penetration testing
A tester working the application as an attacker would, chaining weaknesses that are individually unremarkable. Authorisation flaws, business-logic abuse and privilege paths live here, and no scanner reaches them because each depends on understanding what your system is for.
What VAPT should mean
Assessment for breadth and testing for depth, with the split stated at scoping so you know what you are paying for. A quote that does not distinguish them is quoting one and charging for the other.
Where reports fail
Four states a finding can be in, and only one is finished
| State | What it means | What follows |
|---|---|---|
| Reproduced, fixed, retested | The finding carries reproduction steps, a developer fixed it, and we verified the fix against the same steps with a date on the result. | The only state that closes. Everything below is an intermediate position that some reports present as an outcome. |
| Reported, marked fixed, never retested | A ticket says resolved and nobody went back to the original proof. | The commonest gap between a clean-looking report and a clean estate. Roughly the point of the exercise is verifying the fix, and the verification is what most engagements quietly drop. |
| Reported without reproduction steps | A severity, a description and a recommendation, with nothing an engineer can run. | Generates a meeting. The developer cannot confirm the issue, the tester cannot prove it remotely, and the finding ages into a dispute about whether it was real. |
| Scanner output, unreviewed | Findings passed through from a tool with no human confirming each one exists in your environment. | False positives cost engineering trust, and once a team has chased two of them it stops reading the report. This is how a testing programme dies. |
- Actually closed
- Looks closed
- Costs you the programme
How we keep it consistent
Three reviews, because a test is only as good as its worst day
Manual testing has a quality problem that vendors do not like discussing: the result depends on who was assigned and how their week went. Two testers of similar seniority produce different coverage on the same application, and the client has no way to see the difference. Our answer is structural. Every engagement passes an L1 security auditor who performs the testing and documents each finding with reproduction steps; an L2 senior consultant who reviews coverage before the report is written, checking the parts of the application that were not reached as carefully as the parts that were; and an L3 security architect who validates severity, business impact and the remediation guidance. The platform behind it, Lemon, records what was covered as well as what was found, so coverage is a number we can show you instead of an assurance we ask you to accept. That is also what makes a retest meaningful: the second engagement starts from a recorded coverage map and a closed-findings history, so it tests the fixes and the new surface, not the same ground again. Testing follows the OWASP Top 10 2025 and ASVS 5.0 where web applications are in scope, and Security Brigade has been CERT-In empanelled continuously since 2008.
Scoping it
What changes the number
| Factor | How it moves the engagement |
|---|---|
| Authenticated roles | Each distinct role is a separate test surface, because authorisation flaws only appear when one role reaches another role’s data. An application tested unauthenticated has had its least interesting half examined. |
| API surface | Endpoint count matters less than how many distinct authorisation decisions the API makes. A documented API with consistent entitlement logic tests faster than a smaller one that grew in pieces. |
| Business logic depth | Payments, refunds, limits, approvals and anything with a workflow take real time, and they are where the findings that matter live. |
| Environment | A staging environment matching production is the cheapest thing you can provide. Testing production adds caution, coordination and time. |
| Retest included | Scope it in at the start. A retest priced later is priced as a new engagement, and a finding without a retest is not closed. |
Authenticated roles
- How it moves the engagement
- Each distinct role is a separate test surface, because authorisation flaws only appear when one role reaches another role’s data. An application tested unauthenticated has had its least interesting half examined.
API surface
- How it moves the engagement
- Endpoint count matters less than how many distinct authorisation decisions the API makes. A documented API with consistent entitlement logic tests faster than a smaller one that grew in pieces.
Business logic depth
- How it moves the engagement
- Payments, refunds, limits, approvals and anything with a workflow take real time, and they are where the findings that matter live.
Environment
- How it moves the engagement
- A staging environment matching production is the cheapest thing you can provide. Testing production adds caution, coordination and time.
Retest included
- How it moves the engagement
- Scope it in at the start. A retest priced later is priced as a new engagement, and a finding without a retest is not closed.
Methodology
What happens between kickoff and the report
Every engagement follows this process through Lemon, our proprietary audit management platform.
Project Initiation and Kickoff
Lemon creates the project automatically. A Project Manager, L1 Auditor, L2 Senior Consultant, and L3 Security Architect are assigned. A formal kickoff validates scope, timelines, and access requirements including IP whitelisting, server logs, route files, and test accounts.
Intelligent Application Fingerprinting
Lemon auto-detects the technology stack — framework, CMS, architecture patterns, exposed endpoints, and APIs. Based on data from 6,700+ past assessments, it determines the optimal testing methodology, selects tools, and defines structured tasks and subtasks.
Application Mapping and Coverage Analysis
Auditors perform deep application mapping: module enumeration, JavaScript analysis, API endpoint identification, parameter and session flow analysis, and comprehensive mind-map creation. Parallel automated discovery runs simultaneously. Lemon correlates all outputs with server logs and route files to detect undiscovered functionality.
AI-Driven Coverage Validation
AI models cross-reference auditor mind maps, spidering results, JavaScript analysis, directory listings, route files, and server logs to identify missed endpoints, parameters, or workflows. Discrepancies are flagged for investigation, ensuring no application component goes untested.
Manual Security Testing and Business Logic Analysis
Deep manual penetration testing covering authentication and authorisation bypass, session manipulation, parameter tampering, IDOR, transaction abuse, privilege escalation, workflow manipulation, and input validation flaws. Thousands of test cases are executed based on application architecture, business processes, and threat intelligence.
Integrated Automated Security Scanning
Lemon orchestrates automated scanning with full client control: scheduled scan windows, advance notifications, IP controls, and pause/resume capability. Manual browsing data is proxied into scanners for deeper discovery. Results are ingested into Lemon and correlated with manual findings.
AI-Augmented Testing and Validation
During exploitation, AI analyses test case coverage, recommends additional attack scenarios, validates vulnerability reproduction attempts, executes randomised payload testing, and reviews scan configurations for quality issues. This ensures testing is thorough and continuously improving.
Multi-Layer Quality Assurance
Every assessment undergoes three-level review. L1 Auditor documents findings with proof-of-concepts. L2 Senior Consultant validates methodology and identifies coverage gaps. L3 Security Architect performs final validation of impact assessments and reporting quality. No project releases without L3 sign-off.
Reporting, Retesting, and Certification
Executive and technical reports are delivered with step-by-step PoCs, annotated screenshots, and technology-specific remediation guidance. Multiple rounds of retesting validate fixes as development teams implement them. A Security Assessment Certificate is issued upon successful remediation.
"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
FAQ
VAPT, answered before you scope it
What is tested, by whom, and what closes a finding. Talk to our team about your estate.
Contact usWhat is the difference between vulnerability assessment and penetration testing?
Do you just run scanners?
What makes a finding closed?
How do you keep quality consistent between testers?
Does the auditor need to be CERT-In empanelled?
How long does an engagement take?
Stay protected between assessments with ShadowMap
Continuous attack surface monitoring: it discovers new assets, detects credential leaks, and alerts on new exposures the day they appear.
Ready to Start a VAPT Engagement?
Speak with our team to scope your assessment. We will recommend the right approach based on your application landscape, compliance requirements, and risk profile.
Typically responds within 1 business day · No commitment required
Proof