Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Kanpur and Uttar Pradesh

Cybersecurity and VAPT Company in Kanpur

SecureRoot Risk Advisory LLP is a cybersecurity and VAPT company with its registered office in Kanpur Nagar, Uttar Pradesh. From Kanpur we work with organisations in the city, in Lucknow and across the rest of the state. The work is the whole catalogue: manual penetration testing of applications, APIs, networks and cloud accounts, secure code review, ISO 27001, SOC 2, PCI DSS and DPDP Act programmes, and managed security. Each engagement is scoped on one call and priced in writing before it starts, and the team that scopes it delivers it.

Registered Office

Kanpur Office and Registered Office

Kanpur Nagar

Plot No. 110-A Gandhi Gram,Kanpur Nagar,Uttar Pradesh 208007, IN
New Engagements
sales@secureroot.co
Both Offices
Contact Page

Services

What We Deliver Here

Compliance and the DPDP Act

Programmes run from the gap assessment to the audit by the same team that tests the systems in scope. The DPDP Act reaches any organisation processing digital personal data in India, not only technology firms, which is why it sits beside the certification frameworks.

Leadership and Operations Without a Full-Time Hire

For an organisation with no security function of its own: part-time senior leadership, a data protection officer, a monitored security operations centre, hardening of the systems already running, and training for the people who receive the phishing emails.

See All 34 Services

How It Runs

From First Message to Closing Retest

Four stages, the same for a single web application test as for a full ISO 27001 programme. The scope and the price are agreed in writing before any work is done.

  1. 01

    A Reply, Then a Scoping Call

    A consultant reads your request and answers within one business day. The scoping call takes 30 to 45 minutes with the people who would do the work, and pins down which systems, which framework and which deadline matter.

  2. 02

    Scope and Price on Paper

    What is included, what is not, what we need from your team, the timeline and a fixed price. If the scope changes later, the price is revised in writing before the extra work begins, never after it.

  3. 03

    The Work, by the Team That Scoped It

    Testing is manual and led by an engineer, with tooling in support. Critical findings reach you within three hours of discovery. Compliance work stays with the consultant who scoped it, through to the audit.

  4. 04

    Fixes, Retest and Evidence

    Our engineers work alongside yours until each finding is closed, then retest inside the engagement. You finish with the evidence the request was for: a verified retest report, or a programme ready for its auditor.

The Office

Why the Kanpur Office Matters

Kanpur Nagar is where SecureRoot Risk Advisory LLP is registered, and it is the office a client in Kanpur or elsewhere in central Uttar Pradesh deals with. That matters for the work that happens in a room: the gap workshop with the people who own the controls, the internal network test that has to run from inside your premises, and the readout where the leadership team wants the findings explained face to face.

Everything that does not need a room is delivered remotely, and most testing does not. The team works in Indian business hours, so a critical finding is raised during your working day and the fix session happens while your developers are at their desks. Where a Delhi NCR presence helps, the Greater Noida West branch is the same firm and the same team.

Service Area

Serving Kanpur and Uttar Pradesh

How the work reaches each part of the state, and which office it comes from.

  • Kanpur

    Where the registered office is. Workshops, kick-offs and readouts can be held at our office or at yours, and on-site testing needs no travel planning.

  • Lucknow

    Served from Kanpur. Testing and evidence reviews are remote, and on-site days for workshops, audits or internal testing are planned into the scope. There is no Lucknow office.

  • Uttar Pradesh

    The same model across the state: remote by default, with any on-site days written into the scope and the price rather than added later.

  • Delhi NCR

    Covered by the Greater Noida West branch, which has its own pages for penetration testing in Noida and cybersecurity across Delhi NCR.

Kanpur Nagar and Greater Noida West are the only two offices, and we will not list any other. Clients elsewhere in Uttar Pradesh are served from those two and remotely, with on-site days where the work needs them, and the same team serves clients across India.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Is SecureRoot actually based in Kanpur?

Yes. SecureRoot Risk Advisory LLP has its registered office in Kanpur Nagar, Uttar Pradesh, and it is a working office rather than a registration address. The full address, the telephone number and the enquiry mailbox on this page are read from the same record as the contact page and the footer, so they cannot disagree. The firm also has a branch office in Greater Noida West, which serves Delhi NCR. Both belong to one team: the consultants and engineers who scope an engagement for a client in Kanpur are the people who deliver it, whichever office they are working from that week. Workshops, kick-offs and readouts for clients in the city can be held at our office or on your premises, whichever suits the people who need to attend, and the rest of the work is delivered remotely during your working day.

Do you work with organisations in Lucknow and the rest of Uttar Pradesh?

Yes, from Kanpur and remotely. We do not have an office in Lucknow or anywhere else in the state apart from Kanpur Nagar and the Greater Noida West branch, and we would rather say so than list an address we do not have. For most engagements that makes no practical difference: external penetration testing, evidence reviews, policy work and vCISO time are delivered remotely in any case. Where the scope needs a person in the room, such as an internal network test, a gap workshop with control owners or an audit day, the on-site days are agreed on the scoping call and written into the scope and the price before work starts. Clients in western Uttar Pradesh closer to Delhi NCR may be better served by the Greater Noida West branch, and the scoping call is where that gets decided.

Which cybersecurity services can a Kanpur business get from you?

All 34 services in the catalogue, delivered the same way as anywhere else. That covers compliance programmes across 13 frameworks, including ISO 27001, SOC 2, PCI DSS and the DPDP Act; manual penetration testing across seven surfaces, from web and mobile applications and APIs to networks, IoT devices and cloud accounts; secure code review and software composition analysis; hardening reviews of cloud, operating systems, firewalls, Active Directory and databases; and managed services such as SOC as a service, vCISO, vDPO, red team assessments, phishing simulations and awareness training. The service blocks above link the ones clients most often start with, and every service has its own page setting out the methodology and the deliverables. If you are not sure which one your situation calls for, describe the problem on the scoping call and we will tell you.

A customer or auditor has asked us for a VAPT report. Where do we start?

Start with the request itself. Send us the email, the questionnaire clause or the audit requirement that asked for the report, along with the deadline, and book the scoping call. On the call we work out what the request really needs: which applications, APIs or networks are in scope, whether a retest report is expected, and whether the report has to map to a framework such as ISO 27001, SOC 2 or PCI DSS. You then receive a written scope with a timeline and a fixed price. The finished report separates the executive summary your customer or auditor reads from the technical detail your developers work from, and the verified retest report that follows the fixes is usually the document the requester wanted in the first place. If the request can be met with a narrower test than you expected, we say so.

How is the work priced, and is travel to Kanpur or Lucknow extra?

Every engagement is priced against a written scope, not a day rate, so no figure is published on this page. The scoping call establishes the systems, the frameworks, the people involved and the deadline, and the proposal gives a fixed price for exactly that. Any on-site days, whether at your premises in Kanpur, in Lucknow or elsewhere in the state, are identified on that call and included in the scope and the price, so they do not surface later as an unexpected line. If the scope changes once work has begun, the price is revised in writing before the additional work starts, never afterwards. The scoping call and the written proposal cost nothing and carry no obligation. Our guide to penetration testing cost in India, linked below, explains which factors move the number for a testing engagement.

Ready When You Are

Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.