Latest alerts
  1. Home
  2. FAQ
// faq

Your security questions, answered.

Everything prospective clients usually ask before the first call.

What is VAPT and why do we need it?
Vulnerability Assessment and Penetration Testing combines automated discovery with manual, human-led exploitation to find security weaknesses before attackers do. Customers, auditors, insurers and regulators increasingly ask for a recent VAPT report as proof of due diligence.
How often should we test?
At least once a year, and after every major release, infrastructure change or acquisition. Internet-facing applications that change frequently benefit from quarterly testing.
Is it safe to test our production systems?
Yes, with the right controls. We agree testing windows and rules of engagement, avoid destructive payloads and keep a live channel open with your team. Sensitive tests can run on staging.
How is pricing decided?
By scope: number of applications, user roles, API endpoints or IP addresses, and the depth required. You get a fixed quote and timeline before any work starts — no surprises.
Will our data stay confidential?
Always. We sign an NDA before scoping, store evidence encrypted, share reports through secure channels and delete engagement data on an agreed schedule.
Do you work with companies outside India?
Yes. We support US-based and international firms with VAPT, SOC monitoring and dedicated security staff, working to frameworks such as SOC 2, NIST CSF 2.0 and HIPAA.
What does the DPDP Act mean for my business?
If you process digital personal data of individuals in India, you are a Data Fiduciary under the DPDP Act, 2023. You need clear notices, valid consent, reasonable security safeguards, breach reporting and processes for data-principal rights. Try our free DPDP check to see where you stand.
Can you provide security staff on our behalf?
Yes. Under our Security Staffing model we recruit, employ and manage analysts, SOC engineers and system administrators who work dedicated to your company — on our payroll, under your direction.
Do you also build software and manage servers?
Yes. We manage Linux and Windows servers end-to-end and, through our engineering partners, deliver secure web applications and SaaS products — penetration-tested before launch.
How quickly can you respond to an incident?
Contact us immediately by phone. Existing SOC clients are covered by agreed response SLAs; for new clients we mobilise as fast as possible and help with CERT-In reporting, which must happen within 6 hours of noticing a reportable incident.
// ready when you are

Find out how an attacker sees you — before they do.

Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.

Call Email Under attack? Free DPDP Check