VITI Security

Service · Pentesting

Penetration testing services - exploit-grade, manual, senior-led.

Manual penetration testing. OWASP, NIST 800-115, and PTES methodology. Fixed-price scope. Reports formatted for SOC 2 / HIPAA / PCI-DSS evidence collection - your auditor will accept what we send.

What's in scope

What our penetration testing services cover.

Engagements combine automated scanning (Vexta + Burp + commercial tools) with manual exploitation. Critical findings flagged daily during the test.

External network

Internet-facing perimeter - web, mail, VPN, exposed services. CVE + misconfig + cred exposure.

Internal network

Authenticated assessment from the LAN: AD weaknesses, lateral movement, privilege escalation.

Web applications

OWASP Top 10 + business-logic + auth/authz. Single-page apps + traditional + APIs.

APIs

REST + GraphQL + gRPC. OWASP API Top 10. OpenAPI-driven or proxy-captured.

Mobile (iOS + Android)

Static + dynamic. Reverse engineering. Cert pinning bypass. Secure storage.

Cloud (AWS / GCP / Azure)

IAM review, public exposure, secrets, services misconfigs. CIS-aligned.

What we deliver

1-4 weeks
Engagement duration
Same engineer
For re-test (included)
0
PDF reports nobody reads - exec summary + tech detail, both

Standards behind our penetration testing services in the USA

No proprietary "AI pentest" methodology. We follow what auditors and incident responders already recognize.

OWASP Top 10
Web apps
OWASP API Security Top 10
APIs
OWASP MASVS / MSTG
Mobile
NIST SP 800-115
Technical guide
NIST SP 800-53
Federal-aligned
PTES
Pentest standard
PCI-DSS v4.0 11.3
Card-data envs
CIS Benchmarks
Cloud + endpoints

Pentest USA FAQ

Will your report satisfy our SOC 2 / HIPAA / PCI-DSS auditor?
In our experience, yes - our reports follow the formats SOC 2 / HIPAA / PCI-DSS auditors expect (executive summary, technical detail, retest evidence, control mapping). We have no formal endorsement from any audit firm; we are not in a referral or partnership arrangement with any of them. Send us your auditor before we kick off and we will confirm the deliverable format works for them.
How fast can we start?
Most engagements kick off within 5 business days of signed proposal. Same week if it's urgent (compliance deadline, post-incident, M&A diligence).
Do you do black-box, gray-box, or white-box?
All three. Black-box (no info) is the most expensive and least efficient. Gray-box (some access + a sample login) is the standard. White-box (source code + architecture diagrams) is fastest and finds the most - recommended for new releases.
What's the typical cost?
Quote-based, fixed-price, invoiced in your local currency (INR / USD / GBP / EUR). Ballpark in USD-equivalent: external-only single-app the equivalent of USD 3k-8k; standard web app + API + supporting infra USD 8k-18k; full external + internal + apps + cloud USD 18k-45k. No hourly surprises.
Do you do red team engagements?
Yes - multi-week stealth engagements simulating advanced persistent threat. Different pricing and scope; ask us. We don't do "purple team" exercises as a substitute for actual red team - we tell clients upfront which one they're paying for.
Are you offshore (India)?
Engineering is India-based. Engagement management has US overlap. Same caliber of work as US-based firms; 50-60% lower cost. We're happy to start with a small pilot if trust needs to be earned.

Pentest your stack before someone else does.

Free 30-minute scoping. Fixed-price proposal in 2 days. Re-test included.