Cyber Security
Penetration testing services in Kolkata
Hands-on testing against your applications and networks, with findings written so a developer can fix them, not just file them.
What we test and how the engagement is scoped
Scoping starts with an asset inventory and a threat conversation. A public marketing site, a customer portal holding personal data and an internal finance application deserve different depths of testing, and paying the same rate for all three wastes budget.
Web application and API testing follows the OWASP Web Security Testing Guide and is checked against the OWASP Top 10:2025, where broken access control, security misconfiguration and software supply chain failures now lead the list. Mobile testing follows the OWASP Mobile Application Security guidance across the client, the storage layer and the backend.
Network testing covers external perimeter and internal segments, including authenticated internal testing that simulates a compromised laptop, which is a far more realistic starting point than an anonymous internet attacker.
Manual testing, because scanners miss the expensive bugs
Automated scanning is the first ten per cent of the work. It finds outdated components and obvious misconfiguration, and it cannot find the flaws that actually cost money: one user reading another user record by changing an identifier, a price recalculated on the client, a coupon that can be replayed, or a workflow step that can be skipped.
Those are business logic and authorisation flaws, and finding them requires a tester who understands what your application is for. We test with multiple accounts at different privilege levels precisely so horizontal and vertical access control can be probed properly.
Testing methodology draws on the Penetration Testing Execution Standard and NIST SP 800-115 for structure, so coverage is repeatable rather than dependent on one tester having a good week.
The report, and the retest that closes the loop
Each finding includes the affected component, reproduction steps a developer can follow, evidence, business impact in plain terms, a CVSS rating for consistency, and a specific remediation recommendation rather than a link to a generic article.
The report opens with an executive summary that a non-technical director can read in five minutes, because the person approving the remediation budget is rarely the person who will write the fix.
A retest of remediated findings is included within an agreed window, and the retest letter is what most auditors and enterprise customers actually want to see. Without it you have a list of problems rather than evidence of resolution.
Testing that satisfies auditors, customers and regulators
Annual testing supports ISO 27001:2022 technical verification expectations, and card environments need it under PCI DSS. Market intermediaries operate under the SEBI cyber security and cyber resilience framework, which sets expectations around periodic assessment and reporting.
Enterprise procurement teams increasingly ask suppliers for a recent independent test report before signing, so a current test is often a sales asset as much as a control.
All testing is authorised in writing, run within an agreed window with an emergency stop contact, and conducted so that production availability is protected. Denial of service testing is only performed where explicitly requested and separately agreed.
What you get with penetration testing
- Written scope, rules of engagement and authorisation before testing begins
- Manual testing of web applications and APIs against the OWASP Top 10:2025
- Authenticated multi-role testing for horizontal and vertical access control
- External and internal network testing with configuration review
- Mobile application testing across client, storage and backend where in scope
- Findings report with reproduction steps, evidence, CVSS and specific fixes
- Executive summary written for non-technical stakeholders
- Free retest of remediated findings within the agreed window
How an engagement runs
Every project goes through the same six stages, so you always know what happens next and what it costs.
01
Requirement analysis
We map what you actually need before proposing anything.
02
Strategic planning
Scope, milestones and a fixed number, agreed in writing.
03
Implementation
Built in the open, with a live staging link from week one.
04
Quality assurance
Functional, security and performance testing before sign-off.
05
Deployment
A launch plan with rollback, monitoring and zero surprises.
06
Continuous support
We stay on for as long as you use what we built.
FAQ
Penetration Testing: questions we are asked
A vulnerability scan is automated and finds known issues such as outdated components and weak configuration. Penetration testing adds a human who chains findings together and probes business logic, authorisation and workflow flaws that no scanner detects. VAPT covers both, and the manual half is where the expensive bugs are usually found.
Cost is driven by scope: the number of applications, roles, API endpoints and network hosts, and whether mobile is included. A single web application with two user roles is a short engagement; a platform with several integrated services is not. We quote from a scoping questionnaire, and the retest is included.
At least annually, and additionally after any significant architectural change, new authentication method, major feature release or migration. Certification schemes and enterprise customers usually expect an annual cadence with evidence of remediation, so pairing the test with a retest letter is what actually satisfies them.
Testing is conducted within an agreed window under written rules of engagement, with an emergency stop contact and destructive techniques excluded by default. Denial of service testing is only carried out if you specifically request it and it is separately agreed. Where risk is high we test a staging environment that mirrors production.
Yes. You receive a full technical report plus an executive summary, and a retest letter once findings are remediated. That letter is usually what enterprise procurement teams and certification auditors ask for, since it demonstrates resolution rather than just identification of issues.
Often bought together
What pairs well with penetration testing
Cyber Security
Enterprise Security
End-to-end security architecture for large-scale organizations.
Cyber Security
Security Consultancy
Strategic advice on security posture and risk management.
Web Services
Web Development
Robust and scalable web applications built with the latest technologies.
Web Services
App Development
Native and cross-platform mobile apps for iOS and Android.
Get a written quote for penetration testing.
Tell us what you are trying to achieve and we will come back with scope, timeline and a fixed number — or tell you honestly that we are not the right team.
Talk to a specialist