VAPT Services
We test the way a real attacker would, by hand and with intent, not by handing you a scanner printout. You get findings we have proven, ranked by the damage they do, with a fix you can act on and a retest that confirms it is closed.
Certified ISO/IEC 27001:2022 (certificate IN60432E)
How We Work
VAPT with SecureRoot is people-led work backed by good tooling. We scope tightly with you, map the attack surface, then chase the flaws that actually chain into impact, from web and mobile apps to APIs, thick clients, networks, IoT devices and cloud accounts. Every finding carries a proof of concept, a business-language explanation and clear remediation, and we retest the fixes so you can show they hold.
Jump to the 7 ServicesServices in VAPT
Manual, Exploit-Driven Penetration Testing Across 7 Surfaces
7 services in this practice area
- 01Web ApplicationManual testing of your web apps against the OWASP WSTG
- 02Mobile ApplicationAndroid and iOS app testing against the OWASP MASVS
- 03APIREST, GraphQL and SOAP testing against the OWASP API Top 10
- 04Thick Client ApplicationDesktop app testing across binary, traffic and backend
- 05Network InfrastructureExternal and internal network testing with lateral movement
- 06IoT and EmbeddedDevice testing across firmware, hardware and radio
- 07CloudConfiguration and IAM testing across AWS, Azure and GCP
Measured Against
PTESCVSS v4.0NIST SP 800-115OWASPWSTGOWASPASVSOWASPAPI Top 10OSSTMMISECOMCISBenchmarksWhat We Run
Burp Suite ProfessionalNucleiGhidraWiresharkffufNmapFridaOWASP ZAPHow We Rank What We Find
Whichever surface the test covers, the findings land in the same queue and are ranked by whether they are being exploited in the wild.
Worked example
A vulnerability management product view. Illustrative snapshot of a typical programme, not a named client. Headline figures for the quarter across 1,340 in-scope assets and 40 web applications: 4,812 open findings, of which 288 are past their internal SLA; 37 critical findings open; blended mean time to remediate 84 days, computed from the 3,371 closures this quarter, 24 critical at 21 days each, 391 high at 38, 2,100 medium at 74 and 856 low at 130, which is 282,042 finding-days over 3,371 closures; SLA compliance 68 percent, 2,292 of 3,371 closures within SLA. Open findings by CVSS v3.1 band: Critical 37, which is 0.8 percent; High 412, 8.6 percent; Medium 1,954, 40.6 percent; Low 2,409, 50.1 percent. A further 1,106 informational findings are excluded from that total. 19 open findings are listed on the CISA Known Exploited Vulnerabilities catalogue and 4 of those are past their CISA BOD 22-01 due date. Findings over 13 weeks: 2,993 new against 3,371 remediated, so the open backlog fell from 5,190 to 4,812, with a spike of 402 new findings in week 6 when the quarterly authenticated scan ran. Mean time to remediate by severity against target: Critical 21 days against a 15-day target, High 38 against 30, Medium 74 against 90, Low 130 against 180. The table lists 13 representative findings ranked by exploitability, led by CVE-2024-3400, GlobalProtect OS command injection, CVSS 10.0, EPSS 0.944, on KEV, 13 days old and open; CVE-2023-4966, NetScaler session token leak, CVSS 9.4, on KEV, 41 days old and in progress; and CVE-2021-44228, Log4j2 JNDI remote code execution on a legacy build host, CVSS 10.0, on KEV, 402 days old and still open.
4,812
Open
288 past SLA
37
Critical
19 on KEV
84d
MTTR
3,371 closed
68%
Within SLA
2,292 of 3,371
By Severity, 4,812 Open
19 on CISA KEV, 4 past their CISA due date.
Illustrative snapshot of a typical programme, not a named client.
Every one of these is scoped, run and reported by the same team. See All Practice Areas
What It Costs
Indicative Ranges, Before You Ask
Every figure below is an indicative range, not a quote. Where you land in it depends on scope, and we confirm a fixed price only once scoping is done.
- Indicative rangeDepends on scope
Web application VAPT
₹50,000 to ₹4 lakh, retest included
What sets the figure
- Manual testing against the OWASP WSTG, anonymous and with the roles you provide
- The number of user roles, features and endpoints in scope sets where you land in the range
- Proof of concept for every finding, a report with fixes, and a retest once you remediate
- Indicative rangeDepends on scope
Mobile application VAPT
₹50,000 to ₹4 lakh, retest included
What sets the figure
- Manual Android and iOS testing against the OWASP MASVS, on the binaries or with source
- Testing one platform or both, and the size of the backend the app talks to, sets where you land in the range
- Findings reported per platform with fixes, and a retest once you remediate
- Indicative rangeDepends on scope
API VAPT
₹50,000 to ₹4 lakh, retest included
What sets the figure
- Manual testing of REST, GraphQL or SOAP endpoints against the OWASP API Security Top 10
- The number of endpoints, tenants and authentication schemes in scope sets where you land in the range
- Proof of concept for every finding, a report with fixes, and a retest once you remediate
- Indicative rangeDepends on scope
Network infrastructure VAPT
₹50,000 to ₹4 lakh, retest included
What sets the figure
- External, internal or both, with Active Directory attack paths where you have a domain
- The number of hosts, sites and network segments in scope sets where you land in the range
- Findings mapped to MITRE ATT&CK with fixes, and a retest once you remediate
Indicative ranges in INR as of 2 September 2026; the final quote depends on scope.
Get a Fixed Price for Your Scope
Tell us what is in scope and when you need it. You get a written scope and a fixed price, not a band.
What does a VAPT with SecureRoot actually cover?
Seven surfaces: web applications, mobile applications on Android and iOS, APIs, thick clients, network infrastructure (external and internal), IoT and embedded devices, and cloud accounts on AWS, Azure, GCP, DigitalOcean and Oracle Cloud. Each is a separate service with its own scope, methodology and pricing band, and you can combine them in one engagement, for example a web application, the API behind it and the cloud account it runs in. The work is manual and exploit-driven: our engineers test by hand, the way an attacker would, and use tooling to widen coverage rather than to replace judgement. Every finding we report has been proven with a proof of concept, is explained in business language and ranked by the damage it does, and comes with clear remediation. A retest is part of the engagement, so you can show the fix held.
How do we start, and what happens on the scoping call?
One scoping call, usually 30 to 45 minutes, with the people who will do the work. Bring the deadline, the auditor's question or the customer questionnaire that started this, and tell us what you run. We map the surfaces that matter against what is urgent, agree the targets, environments, roles and any off-limits actions, and then send you a written scope, a timeline and a fixed price. The price is fixed after scoping, never before, and it does not grow later as an open-ended estimate would. If we are not the right fit for the problem, we say so on the call. Once the scope is signed, we set testing windows and escalation contacts so nothing takes your team by surprise, and the engagement starts from an agreed Rules of Engagement.
How long does a VAPT take?
Most web or API assessments run one to three weeks depending on scope, plus a retest window once your fixes are in. A single web application usually takes one to two weeks, driven by the number of roles, features and endpoints we test by hand; a mobile application depends on whether Android, iOS or both are in scope and how large the backend behind the app is; a network test depends on whether it is external, internal or both and how many hosts and segments it covers. We confirm the timeline once scoping is done. You do not wait for the report to hear bad news: critical findings reach you within three hours of discovery, so your team can start on the fix while the rest of the test continues.
What does a VAPT cost?
Indicative range: ₹50,000 to ₹4 lakh, retest included, for a web application, mobile application, API or network penetration test. Where an engagement lands in that range depends on scope. For a web application it is mainly the number of roles, features and endpoints; for a mobile application, whether we test Android, iOS or both and the size of the backend; for an API, how many endpoints, tenants and authentication schemes we cover; for a network, whether the test is external, internal or both and how many hosts and segments it spans. These are ranges, not quotes. We confirm a fixed price once scoping is done, and that price includes the retest, so there is no separate invoice for verifying your fixes. The indicative ranges are reviewed and stated in INR on each service page.
Do you help with the fixes, and is the retest included?
Yes to both. Every finding carries specific remediation guidance, and the engineer who found the flaw is the one who explains the fix to your developer, in your language and your codebase. Our engineers are available to yours during fix sprints, and when you tell us the fixes are in, we retest each finding and confirm whether it is genuinely closed. The retest is part of the engagement, not a separate invoice, and it produces a verified retest report you can hand to an auditor or a customer. A closed finding means fixed and retested, not acknowledged. If a fix does not hold, the finding stays open and we tell you why, so the report you finally rely on reflects what an attacker would actually find today rather than what was promised.
Can the report be used as evidence for a SOC 2, ISO 27001 or DPDP Act audit?
That is a common reason clients come to us, and the deliverables are built for it. You receive a findings report with proof of concept for every issue, an executive summary, remediation guidance, a verified retest report and an attestation letter, so the evidence trail runs from discovery to confirmed closure. The same team scopes ISO 27001, SOC 2 and DPDP Act programmes and the manual VAPT engagements that test them, so the test can be timed to your audit window and scoped to the systems the auditor will ask about. SecureRoot itself holds ISO/IEC 27001:2022 certificate IN60432E. If you need the compliance side as well, the SOC 2, ISO 27001 and DPDP Act services linked below are run by the same people, from one control set and one evidence base.
Not Sure Which of These You Need?
Tell us what you are being asked to prove, or what you are worried about. We will point you at the right piece of work, even when it is smaller than you expected.
Related Reading
Articles on VAPT
- Types of Penetration Testing: A Complete Guide
- API Security Testing Services: OWASP API Top 10 Coverage and Retesting
- Cloud Security Best Practices: A Practical 2026 Guide
- Penetration Testing Cost in India: 2026 Pricing Guide
- AWS Cloud Security Audit Checklist for Indian SaaS Teams
- OWASP Top 10 Vulnerabilities Explained (With Fixes)
Locations
Delivered Across Delhi NCR
Related Compliance
Testing for an Audit? Start Here
- SOC 2If the test is evidence for a Type 1 or Type 2 report, the same team builds the control set it supports.
- ISO 27001For an ISMS audit, we scope the test to the systems the auditor will ask about and time it to your audit window.
- DPDP ActIf personal data is in scope, DPDP Act readiness and the testing of the systems that hold it run as one programme.
Elsewhere
Other Practice Areas
- ComplianceCertifications and Privacy Programmes Across 13 Frameworks
- Secure Code Review (SCR)Manual, line-by-line review of your most sensitive code paths, backed by SAST triage.
- Software Composition Analysis (SCA)Know every third-party and open-source dependency you ship, and every risk it carries.
- Hardening and Configuration ReviewBenchmark-Based Configuration Hardening Across Cloud, OS, Network and Data Tiers
- Managed ServicesOngoing Offensive, Defensive and Advisory Security Run by Our Team