VITI Security

Major service · Cybersecurity

Cybersecurity that doesn't require translation. Audits that don't take six months.

From vulnerability assessments and pentests to SOC 2, ISO 27001, HIPAA, and PCI prep - practical security work for the SMBs that actually move.

What's covered

The full security stack, scoped to your stage.

Pick the modules you need now; we'll flag what to tackle next. No selling you everything on day one.

VAPT

Vulnerability assessment and pentesting on infra, web apps, APIs, mobile, and cloud. Findings prioritized, fixes guided.

Compliance prep

SOC 2, ISO 27001, HIPAA, PCI-DSS, GLBA - we run the gap analysis and the remediation.

Incident response readiness

Runbooks, tabletop exercises, on-call rota, evidence preservation. We make the bad day boring on purpose.

Security training

Phishing simulations, dev secure-coding workshops, exec briefings. Plain-English, role-appropriate, measurable.

Continuous monitoring

Vexta-powered scans + log review + monthly posture report. Catch drift between audits.

M&A security due diligence

Quick-turn security and compliance review of an acquisition target. Usually delivered inside a week.

Start here

Which framework you need, and in what order.

If an enterprise customer is holding up a contract, it is almost certainly SOC 2 they want, and Type I first is usually the faster path to unblocking the deal. If you handle health data it is HIPAA, if you touch card data it is PCI-DSS, and those are floors rather than choices. ISO 27001 matters most when you sell internationally.

  • A gap assessment tells you the distance. It is usually cheaper than the certification and it is the only honest basis for a budget.
  • Certification is issued by an independent auditor you retain, never by us. A firm that implements your controls cannot also attest to them, and any firm offering both should worry you.
  • Most of the underlying controls overlap. Access management, logging, change control and vendor review count toward almost every framework, so sequencing them well means the second certification costs far less than the first.
  • Deadlines drive cost more than scope does. A customer holding a signature changes the shape of the engagement more than another fifty employees would.
Get a gap assessment scoped
Which framework you need, and in what order.

How we work differently

We own the engine that runs before a human writes a finding.

Most firms in this market resell a scanner licence and mark it up. That changes what they can tell you, and what it costs you.

No licence markup in your fee

Vexta is ours. There is no third-party subscription buried in the price with our margin on top, which is a large part of why fixed-price scoping works at SMB scale at all.

We can show you the check

When a finding fires we can show you the exact test that produced it, and change it if your environment makes it a false positive. A firm reselling someone else’s scanner can only forward your question to a vendor.

Verified before you read it

Findings are proven, refuted or unproven before they reach your report. You are not handed three hundred maybes and told to work out which ones are real.

No reseller agreements

We hold none, and take no referral fees. When we recommend a tool, nothing about that recommendation pays us.

Manual work where it matters

Automation maximises coverage; it does not find business-logic flaws, chained privilege escalation or authorisation bypasses. A senior engineer does that part, and the report says which findings came from which.

Re-test included

After your team ships fixes we test again at no extra cost, with the same engineer. Closing the loop is the part most engagements skip, and it is the only part that changes your actual risk.

A first engagement

What happens, week by week.

A typical first assessment. Longer programmes follow the same shape with more surface.

  1. Day 0

    Scoping call, then a fixed price

    Thirty minutes on what is in play - infrastructure, applications, cloud, whatever compliance pressure brought you here, and what a bad day would actually cost you. A written scope and a fixed number follow within two business days. If the honest answer is that you need something smaller, that is what the proposal will say.

  2. Week 1

    Testing starts, findings flow immediately

    Automated coverage across the agreed surface with Vexta running underneath, then manual testing on top. Anything critical is escalated the day it is found, not saved for the report. You get daily check-ins rather than a fortnight of silence.

  3. Week 2-3

    The report, written for two audiences

    An executive summary for whoever funds the fix, and technical detail with reproduction steps for whoever ships it. Every finding carries a fix, a complexity estimate and a plain-English reason it matters. Delivered as a document you own, plus a live walkthrough with your engineers.

  4. After fixes

    Re-test, then a decision

    Your team ships the remediation and we test the same surface again, same engineer, at no additional cost. At that point you either have what you needed and we stop, or you move to monitoring so drift is caught between assessments instead of at the next audit.

Be honest with yourself

When this is not what you need.

Three situations where buying a security engagement from us would be the wrong call.

You need a certificate, not readiness

We prepare you for an audit; we cannot issue the certificate. ISO 27001 comes from an accredited certification body and a SOC 2 report from an AICPA CPA firm, both of which you retain separately. Any firm offering to both implement and certify is selling you a conflict of interest.

You need an empanelled signature

We follow CERT-In-aligned methodology but we are not a CERT-In empanelled firm. If your regulator or contract names that requirement, you need the firm that holds the empanelment. We will prepare the documentation so their engagement is shorter.

Nobody can act on the findings

A report is only worth what gets fixed. If you have no engineering capacity at all, the useful sequence is managed IT first and testing second - otherwise you are buying a list of problems nobody will close, and your risk is unchanged at the end of it.

What you walk away with

1 week
Typical first findings
100%
Findings reviewed with you
0
PDF reports nobody reads

How the work runs

A security engagement that ends in fixes, not a filing cabinet.

Most security reports get skimmed once and shelved. We run engagements as a loop that closes - find, prioritize, fix, verify - so the posture actually moves.

01

Scope

A short call to map what is in play - infra, apps, cloud, compliance pressure, and what a bad day would cost you. We propose only what matters for your stage and price it fixed.

02

Assess

We run the testing: VAPT across your surface, gap analysis against the framework you need, and Vexta scans under the hood. First findings typically land inside a week.

03

Prioritize + remediate

Every finding comes with a fix, a complexity estimate, and a plain-English reason it matters. We hand it to your team or do the remediation ourselves - your call.

04

Re-test + monitor

After fixes ship we re-test with the same engineer, no context lost. From there you can move to continuous monitoring so drift is caught between audits rather than at the next one.

Common questions about this service

What does a security engagement cost?
A one-off assessment is fixed-price and typically lands in the equivalent of USD 3k-25k depending on how much surface is in scope. Ongoing engagements combining scheduled testing, remediation support and monitoring typically run the equivalent of USD 5k-15k a month. Send a scope and you get a fixed number within two business days - not a range that moves once we have you on a call.
How do I know which framework to start with?
If an enterprise customer is holding up a contract, it is almost certainly SOC 2 they want, and Type I first is usually the faster path to unblocking the deal. If you handle health data it is HIPAA, if you touch card data it is PCI-DSS, and those are floors rather than choices. ISO 27001 matters most when you sell internationally.
How is this different from a one-off pentest?
A one-off pentest gives you a report. This gives you a remediation partner: every finding carries a fix recommendation, a complexity estimate and, if you want it, hands-on remediation - then a free re-test with the same engineer once your team has shipped. If all you need is a point-in-time report for a customer or an auditor, buy the pentest and skip the rest.
Do you handle the actual audit, or just the prep?
The prep, which is the heavy lift, and we sit alongside you during fieldwork. The audit itself is performed by an independent firm you retain - an accredited certification body for ISO 27001, an AICPA CPA firm for SOC 2. We cannot attest to controls we implemented, and neither can anyone else who is being straight with you.
Which compliance frameworks do you cover?
Most-asked: SOC 2 Type I & II, ISO 27001, HIPAA, PCI-DSS, GLBA, GDPR. If you have a framework not on this list, ask.
Do you use automated scanning or manual testing?
Both, and the report tells you which findings came from which. Automation maximises coverage - it is how you get across an entire estate in days. Manual testing is what finds business-logic flaws, chained privilege escalation, race conditions and authorisation bypasses, none of which a scanner will surface. A firm selling you only the first and calling it a pentest is overcharging you for a tool subscription.
Whose scanner do you use?
Ours. Vexta is built in-house, which means there is no third-party licence cost inside your fee, we can show you the exact check that produced any finding, and we can change that check when your environment makes it a false positive. Most firms in this market resell someone else’s scanner and can only forward your question to a vendor.
What is a typical engagement length?
A first assessment runs 1-3 weeks depending on surface. A compliance readiness programme runs 8-16 weeks and depends almost entirely on your starting maturity rather than your size. Continuous monitoring is month-to-month and ongoing.
What happens after you find something critical?
You hear about it the day we find it, not in the report two weeks later. Critical findings are escalated immediately with enough detail for your team to act, and we will help contain it if that is what the situation needs.
Do we keep the findings if we stop working with you?
Yes, all of it, from the day it is written. The report, the evidence, the risk register and any documentation produced are yours. Nothing is held in a tool only we can log into and nothing is withheld to make leaving awkward.
Who actually does the testing?
A named senior engineer, told to you before work starts, and the same person does the re-test. We are deliberately small, so the person who scoped the engagement is the person doing it - there is no handoff from the people who sold it to a delivery team you have never met.

Get scoped this week. Findings the next.

30-minute scoping call, fixed-price proposal in two business days, work starts when you say yes.