Skip to main content
Since 2006 — Continuous cybersecurity operations in India

VAPT Services Built on Process, Platform, and Proof — Not Individual Heroics

Security Brigade delivers vulnerability assessment and penetration testing through a platform-driven methodology refined over 6,700+ assessments. CERT-In empanelled since 2008, trusted by more than 1,000 enterprises.

6,700+
Assessments
1,000+
Clients
150+
Team
2006
Founded

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

What you are buying

A scan finds what is known. A test finds what is yours

The distinction decides the price, the timeline and whether the report tells you anything you could not have generated yourself.

The floor

Automated scanning

Signature and version matching against a database of known issues. Fast, cheap, and necessary. It finds the missing patch and the expired certificate, and it cannot find a flaw that exists only in your application.

Breadth

Vulnerability assessment

Systematic coverage of the estate with the output triaged by someone who can tell a real finding from a scanner artefact. The value is in the triage: an untriaged scan report transfers work to you and calls it a deliverable.

Depth

Penetration testing

A tester working the application as an attacker would, chaining weaknesses that are individually unremarkable. Authorisation flaws, business-logic abuse and privilege paths live here, and no scanner reaches them because each depends on understanding what your system is for.

Both, scoped honestly

What VAPT should mean

Assessment for breadth and testing for depth, with the split stated at scoping so you know what you are paying for. A quote that does not distinguish them is quoting one and charging for the other.

Where reports fail

Four states a finding can be in, and only one is finished

Four states a finding can be in, and only one is finished
StateWhat it meansWhat follows
Reproduced, fixed, retested The finding carries reproduction steps, a developer fixed it, and we verified the fix against the same steps with a date on the result. The only state that closes. Everything below is an intermediate position that some reports present as an outcome.
Reported, marked fixed, never retested A ticket says resolved and nobody went back to the original proof. The commonest gap between a clean-looking report and a clean estate. Roughly the point of the exercise is verifying the fix, and the verification is what most engagements quietly drop.
Reported without reproduction steps A severity, a description and a recommendation, with nothing an engineer can run. Generates a meeting. The developer cannot confirm the issue, the tester cannot prove it remotely, and the finding ages into a dispute about whether it was real.
Scanner output, unreviewed Findings passed through from a tool with no human confirming each one exists in your environment. False positives cost engineering trust, and once a team has chased two of them it stops reading the report. This is how a testing programme dies.
Key
  • Actually closed
  • Looks closed
  • Costs you the programme

How we keep it consistent

Three reviews, because a test is only as good as its worst day

Manual testing has a quality problem that vendors do not like discussing: the result depends on who was assigned and how their week went. Two testers of similar seniority produce different coverage on the same application, and the client has no way to see the difference. Our answer is structural. Every engagement passes an L1 security auditor who performs the testing and documents each finding with reproduction steps; an L2 senior consultant who reviews coverage before the report is written, checking the parts of the application that were not reached as carefully as the parts that were; and an L3 security architect who validates severity, business impact and the remediation guidance. The platform behind it, Lemon, records what was covered as well as what was found, so coverage is a number we can show you instead of an assurance we ask you to accept. That is also what makes a retest meaningful: the second engagement starts from a recorded coverage map and a closed-findings history, so it tests the fixes and the new surface, not the same ground again. Testing follows the OWASP Top 10 2025 and ASVS 5.0 where web applications are in scope, and Security Brigade has been CERT-In empanelled continuously since 2008.

Scoping it

What changes the number

FactorHow it moves the engagement
Authenticated roles Each distinct role is a separate test surface, because authorisation flaws only appear when one role reaches another role’s data. An application tested unauthenticated has had its least interesting half examined.
API surface Endpoint count matters less than how many distinct authorisation decisions the API makes. A documented API with consistent entitlement logic tests faster than a smaller one that grew in pieces.
Business logic depth Payments, refunds, limits, approvals and anything with a workflow take real time, and they are where the findings that matter live.
Environment A staging environment matching production is the cheapest thing you can provide. Testing production adds caution, coordination and time.
Retest included Scope it in at the start. A retest priced later is priced as a new engagement, and a finding without a retest is not closed.

Authenticated roles

How it moves the engagement
Each distinct role is a separate test surface, because authorisation flaws only appear when one role reaches another role’s data. An application tested unauthenticated has had its least interesting half examined.

API surface

How it moves the engagement
Endpoint count matters less than how many distinct authorisation decisions the API makes. A documented API with consistent entitlement logic tests faster than a smaller one that grew in pieces.

Business logic depth

How it moves the engagement
Payments, refunds, limits, approvals and anything with a workflow take real time, and they are where the findings that matter live.

Environment

How it moves the engagement
A staging environment matching production is the cheapest thing you can provide. Testing production adds caution, coordination and time.

Retest included

How it moves the engagement
Scope it in at the start. A retest priced later is priced as a new engagement, and a finding without a retest is not closed.

Methodology

What happens between kickoff and the report

Every engagement follows this process through Lemon, our proprietary audit management platform.

Discovery
01

Project Initiation and Kickoff

Lemon creates the project automatically. A Project Manager, L1 Auditor, L2 Senior Consultant, and L3 Security Architect are assigned. A formal kickoff validates scope, timelines, and access requirements including IP whitelisting, server logs, route files, and test accounts.

02

Intelligent Application Fingerprinting

Lemon auto-detects the technology stack — framework, CMS, architecture patterns, exposed endpoints, and APIs. Based on data from 6,700+ past assessments, it determines the optimal testing methodology, selects tools, and defines structured tasks and subtasks.

03

Application Mapping and Coverage Analysis

Auditors perform deep application mapping: module enumeration, JavaScript analysis, API endpoint identification, parameter and session flow analysis, and comprehensive mind-map creation. Parallel automated discovery runs simultaneously. Lemon correlates all outputs with server logs and route files to detect undiscovered functionality.

Testing
04

AI-Driven Coverage Validation

AI models cross-reference auditor mind maps, spidering results, JavaScript analysis, directory listings, route files, and server logs to identify missed endpoints, parameters, or workflows. Discrepancies are flagged for investigation, ensuring no application component goes untested.

05

Manual Security Testing and Business Logic Analysis

Deep manual penetration testing covering authentication and authorisation bypass, session manipulation, parameter tampering, IDOR, transaction abuse, privilege escalation, workflow manipulation, and input validation flaws. Thousands of test cases are executed based on application architecture, business processes, and threat intelligence.

06

Integrated Automated Security Scanning

Lemon orchestrates automated scanning with full client control: scheduled scan windows, advance notifications, IP controls, and pause/resume capability. Manual browsing data is proxied into scanners for deeper discovery. Results are ingested into Lemon and correlated with manual findings.

Delivery
07

AI-Augmented Testing and Validation

During exploitation, AI analyses test case coverage, recommends additional attack scenarios, validates vulnerability reproduction attempts, executes randomised payload testing, and reviews scan configurations for quality issues. This ensures testing is thorough and continuously improving.

08

Multi-Layer Quality Assurance

Every assessment undergoes three-level review. L1 Auditor documents findings with proof-of-concepts. L2 Senior Consultant validates methodology and identifies coverage gaps. L3 Security Architect performs final validation of impact assessments and reporting quality. No project releases without L3 sign-off.

09

Reporting, Retesting, and Certification

Executive and technical reports are delivered with step-by-step PoCs, annotated screenshots, and technology-specific remediation guidance. Multiple rounds of retesting validate fixes as development teams implement them. A Security Assessment Certificate is issued upon successful remediation.

"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
CTO, Enterprise SaaS Company
Chief Technology Officer

Read more client stories →

FAQ

VAPT, answered before you scope it

What is tested, by whom, and what closes a finding. Talk to our team about your estate.

Contact us
What is the difference between vulnerability assessment and penetration testing?+
Assessment is breadth and testing is depth. An assessment covers the estate systematically and triages what is found; a penetration test works an application the way an attacker would, chaining weaknesses that look unremarkable on their own. Authorisation flaws, business-logic abuse and privilege escalation paths are found by the second and not the first, because each one depends on understanding what your system is for. VAPT should mean both, with the split stated at scoping.
Do you just run scanners?+
No. Scanning is the floor of the engagement and never the deliverable. Every finding in our reports has been confirmed by a person in your environment with reproduction steps attached, because an unreviewed scanner report transfers the triage work to you and costs you your engineering team’s trust the first time they chase a false positive.
What makes a finding closed?+
A retest against the original reproduction steps, with a date on the result. A ticket marked resolved is not a closed finding, and the gap between those two is the commonest reason a clean-looking report sits above an estate that has not changed. Scope the retest into the engagement at the start; priced afterwards it is priced as new work.
How do you keep quality consistent between testers?+
Three reviews, and a record of coverage. An L1 auditor performs the testing and documents every finding; an L2 senior consultant reviews coverage before the report is written, examining what was not reached as carefully as what was; an L3 architect validates severity, impact and remediation guidance. Lemon records what was covered as well as what was found, so coverage is something we show you.
Does the auditor need to be CERT-In empanelled?+
For any assessment going to an Indian regulator, yes. Empanelment attaches to the auditing firm for a defined period and CERT-In publishes who holds it, so the practical question is whether the firm held it across the days the work was performed. Security Brigade has held it continuously since 2008.
How long does an engagement take?+
Two to four weeks for a typical web application and its API, driven by the number of distinct authenticated roles and the depth of business logic more than by raw size. The variables that move it most are whether a staging environment matching production is available and how quickly fixes come back for retest.

Stay protected between assessments with ShadowMap

Continuous attack surface monitoring: it discovers new assets, detects credential leaks, and alerts on new exposures the day they appear.

Learn about ShadowMap →

Ready to Start a VAPT Engagement?

Speak with our team to scope your assessment. We will recommend the right approach based on your application landscape, compliance requirements, and risk profile.

Typically responds within 1 business day · No commitment required

Request a Scoping Call