Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Practice Area7 services in this area
VAPT

VAPT Services

We test the way a real attacker would, by hand and with intent, not by handing you a scanner printout. You get findings we have proven, ranked by the damage they do, with a fix you can act on and a retest that confirms it is closed.

Certified ISO/IEC 27001:2022 (certificate IN60432E)

How We Work

VAPT with SecureRoot is people-led work backed by good tooling. We scope tightly with you, map the attack surface, then chase the flaws that actually chain into impact, from web and mobile apps to APIs, thick clients, networks, IoT devices and cloud accounts. Every finding carries a proof of concept, a business-language explanation and clear remediation, and we retest the fixes so you can show they hold.

Jump to the 7 Services

Services in VAPT

Manual, Exploit-Driven Penetration Testing Across 7 Surfaces

7 services in this practice area

Measured Against

PTESCVSS v4.0NIST SP 800-115OWASPWSTGOWASPASVSOWASPAPI Top 10OSSTMMISECOMCISBenchmarks

What We Run

Burp Suite ProfessionalNucleiGhidraWiresharkffufNmapFridaOWASP ZAP

How We Rank What We Find

Whichever surface the test covers, the findings land in the same queue and are ranked by whether they are being exploited in the wild.

VAPT

Worked example

A vulnerability management product view. Illustrative snapshot of a typical programme, not a named client. Headline figures for the quarter across 1,340 in-scope assets and 40 web applications: 4,812 open findings, of which 288 are past their internal SLA; 37 critical findings open; blended mean time to remediate 84 days, computed from the 3,371 closures this quarter, 24 critical at 21 days each, 391 high at 38, 2,100 medium at 74 and 856 low at 130, which is 282,042 finding-days over 3,371 closures; SLA compliance 68 percent, 2,292 of 3,371 closures within SLA. Open findings by CVSS v3.1 band: Critical 37, which is 0.8 percent; High 412, 8.6 percent; Medium 1,954, 40.6 percent; Low 2,409, 50.1 percent. A further 1,106 informational findings are excluded from that total. 19 open findings are listed on the CISA Known Exploited Vulnerabilities catalogue and 4 of those are past their CISA BOD 22-01 due date. Findings over 13 weeks: 2,993 new against 3,371 remediated, so the open backlog fell from 5,190 to 4,812, with a spike of 402 new findings in week 6 when the quarterly authenticated scan ran. Mean time to remediate by severity against target: Critical 21 days against a 15-day target, High 38 against 30, Medium 74 against 90, Low 130 against 180. The table lists 13 representative findings ranked by exploitability, led by CVE-2024-3400, GlobalProtect OS command injection, CVSS 10.0, EPSS 0.944, on KEV, 13 days old and open; CVE-2023-4966, NetScaler session token leak, CVSS 9.4, on KEV, 41 days old and in progress; and CVE-2021-44228, Log4j2 JNDI remote code execution on a legacy build host, CVSS 10.0, on KEV, 402 days old and still open.

SecureRoot VAPTVulnerability Management

4,812

Open

288 past SLA

37

Critical

19 on KEV

84d

MTTR

3,371 closed

68%

Within SLA

2,292 of 3,371

By Severity, 4,812 Open

Critical 37High 412Medium 1,954Low 2,409

19 on CISA KEV, 4 past their CISA due date.

Illustrative snapshot of a typical programme, not a named client.

Illustrative figures for a 1,340-asset estate. 4,812 open findings, 19 of them on the CISA Known Exploited Vulnerabilities catalogue, 4 already past their due date. The overdue rows stay on the board.

Every one of these is scoped, run and reported by the same team. See All Practice Areas

What It Costs

Indicative Ranges, Before You Ask

Every figure below is an indicative range, not a quote. Where you land in it depends on scope, and we confirm a fixed price only once scoping is done.

  • Indicative rangeDepends on scope

    Web application VAPT

    ₹50,000 to ₹4 lakh, retest included

    What sets the figure

    • Manual testing against the OWASP WSTG, anonymous and with the roles you provide
    • The number of user roles, features and endpoints in scope sets where you land in the range
    • Proof of concept for every finding, a report with fixes, and a retest once you remediate
  • Indicative rangeDepends on scope

    Mobile application VAPT

    ₹50,000 to ₹4 lakh, retest included

    What sets the figure

    • Manual Android and iOS testing against the OWASP MASVS, on the binaries or with source
    • Testing one platform or both, and the size of the backend the app talks to, sets where you land in the range
    • Findings reported per platform with fixes, and a retest once you remediate
  • Indicative rangeDepends on scope

    API VAPT

    ₹50,000 to ₹4 lakh, retest included

    What sets the figure

    • Manual testing of REST, GraphQL or SOAP endpoints against the OWASP API Security Top 10
    • The number of endpoints, tenants and authentication schemes in scope sets where you land in the range
    • Proof of concept for every finding, a report with fixes, and a retest once you remediate
  • Indicative rangeDepends on scope

    Network infrastructure VAPT

    ₹50,000 to ₹4 lakh, retest included

    What sets the figure

    • External, internal or both, with Active Directory attack paths where you have a domain
    • The number of hosts, sites and network segments in scope sets where you land in the range
    • Findings mapped to MITRE ATT&CK with fixes, and a retest once you remediate

Indicative ranges in INR as of 2 September 2026; the final quote depends on scope.

Get a Fixed Price for Your Scope

Tell us what is in scope and when you need it. You get a written scope and a fixed price, not a band.

Request an Assessment

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

What does a VAPT with SecureRoot actually cover?

Seven surfaces: web applications, mobile applications on Android and iOS, APIs, thick clients, network infrastructure (external and internal), IoT and embedded devices, and cloud accounts on AWS, Azure, GCP, DigitalOcean and Oracle Cloud. Each is a separate service with its own scope, methodology and pricing band, and you can combine them in one engagement, for example a web application, the API behind it and the cloud account it runs in. The work is manual and exploit-driven: our engineers test by hand, the way an attacker would, and use tooling to widen coverage rather than to replace judgement. Every finding we report has been proven with a proof of concept, is explained in business language and ranked by the damage it does, and comes with clear remediation. A retest is part of the engagement, so you can show the fix held.

How do we start, and what happens on the scoping call?

One scoping call, usually 30 to 45 minutes, with the people who will do the work. Bring the deadline, the auditor's question or the customer questionnaire that started this, and tell us what you run. We map the surfaces that matter against what is urgent, agree the targets, environments, roles and any off-limits actions, and then send you a written scope, a timeline and a fixed price. The price is fixed after scoping, never before, and it does not grow later as an open-ended estimate would. If we are not the right fit for the problem, we say so on the call. Once the scope is signed, we set testing windows and escalation contacts so nothing takes your team by surprise, and the engagement starts from an agreed Rules of Engagement.

How long does a VAPT take?

Most web or API assessments run one to three weeks depending on scope, plus a retest window once your fixes are in. A single web application usually takes one to two weeks, driven by the number of roles, features and endpoints we test by hand; a mobile application depends on whether Android, iOS or both are in scope and how large the backend behind the app is; a network test depends on whether it is external, internal or both and how many hosts and segments it covers. We confirm the timeline once scoping is done. You do not wait for the report to hear bad news: critical findings reach you within three hours of discovery, so your team can start on the fix while the rest of the test continues.

What does a VAPT cost?

Indicative range: ₹50,000 to ₹4 lakh, retest included, for a web application, mobile application, API or network penetration test. Where an engagement lands in that range depends on scope. For a web application it is mainly the number of roles, features and endpoints; for a mobile application, whether we test Android, iOS or both and the size of the backend; for an API, how many endpoints, tenants and authentication schemes we cover; for a network, whether the test is external, internal or both and how many hosts and segments it spans. These are ranges, not quotes. We confirm a fixed price once scoping is done, and that price includes the retest, so there is no separate invoice for verifying your fixes. The indicative ranges are reviewed and stated in INR on each service page.

Do you help with the fixes, and is the retest included?

Yes to both. Every finding carries specific remediation guidance, and the engineer who found the flaw is the one who explains the fix to your developer, in your language and your codebase. Our engineers are available to yours during fix sprints, and when you tell us the fixes are in, we retest each finding and confirm whether it is genuinely closed. The retest is part of the engagement, not a separate invoice, and it produces a verified retest report you can hand to an auditor or a customer. A closed finding means fixed and retested, not acknowledged. If a fix does not hold, the finding stays open and we tell you why, so the report you finally rely on reflects what an attacker would actually find today rather than what was promised.

Can the report be used as evidence for a SOC 2, ISO 27001 or DPDP Act audit?

That is a common reason clients come to us, and the deliverables are built for it. You receive a findings report with proof of concept for every issue, an executive summary, remediation guidance, a verified retest report and an attestation letter, so the evidence trail runs from discovery to confirmed closure. The same team scopes ISO 27001, SOC 2 and DPDP Act programmes and the manual VAPT engagements that test them, so the test can be timed to your audit window and scoped to the systems the auditor will ask about. SecureRoot itself holds ISO/IEC 27001:2022 certificate IN60432E. If you need the compliance side as well, the SOC 2, ISO 27001 and DPDP Act services linked below are run by the same people, from one control set and one evidence base.

Not Sure Which of These You Need?

Tell us what you are being asked to prove, or what you are worried about. We will point you at the right piece of work, even when it is smaller than you expected.