VITI Security

Service · VAPT

VAPT services - exploit-grade, standards-aligned.

Vulnerability assessment and penetration testing on infra, web apps, APIs, mobile, and cloud. CERT-In-aligned methodology; OWASP + NIST 800-115 + PTES across the rest of the stack.

What we test

What our VAPT services cover.

Every engagement combines automated scanning (Vexta + commercial tools) with manual exploitation by a senior pentester.

External network

Internet-facing assets: web servers, mail, VPN, exposed services. CVE + misconfig + exposed credentials.

Internal network

Authenticated assessment of the LAN: lateral movement, privilege escalation, AD/identity weaknesses.

Web applications

OWASP Top 10 + business-logic + auth/authz. Manual testing, not just scanner output.

APIs (REST + GraphQL)

Auth, authz, rate limits, injection, data exposure. OpenAPI-spec-driven or proxy-captured.

Mobile (iOS + Android)

Static + dynamic analysis. Reverse-engineering. Cert pinning, secure storage, IPC.

Cloud (AWS / GCP / Azure)

IAM, public buckets, exposed secrets, misconfigured services. Mapped to CIS benchmarks.

What you walk away with

1-3 weeks
Typical assessment duration
100%
Findings reviewed with you
CERT-In
Aligned methodology (India)

Standards we follow

We don't invent methodology. We follow what auditors actually accept.

CERT-In Guidelines
India
OWASP Top 10
Global · web apps
OWASP API Security Top 10
Global · APIs
NIST SP 800-115
US · technical guide
PTES
Global · pentest standard
CIS Benchmarks
Global · cloud + endpoints

How an engagement runs

4 phases. Each with a clear deliverable.

You stay informed every step. No mystery-box pentest.

01

Scope + rules

In-scope assets, out-of-scope guardrails, escalation contacts, NDAs. Fixed price for the engagement.

02

Test

1-3 weeks of active testing. Daily check-ins. Critical findings flagged immediately, not at the end.

03

Report + walkthrough

Auditor-ready PDF + executive summary. Live walkthrough of every finding with engineering.

04

Re-test (included)

After your team ships fixes, we re-test for free. Same engineer. No context loss.

VAPT FAQ

Are you CERT-In empanelled?
We work to CERT-In-aligned methodology - same standards, same deliverables - but we are not ourselves a CERT-In empanelled firm. If your regulator or contract requires a CERT-In empanelled signature, you will need to retain an empanelled firm of your choice for the signoff; we hand off cleanly and can prep the documentation pack so the empanelled firm has less to redo. Most non-empanelled-mandated buyers accept our reports directly.
What's the difference between automated scanning and a real pentest?
Automated scanning (Vexta, Burp, etc.) finds known vulnerabilities - CVEs, misconfigs, OWASP-pattern matches. A real pentest adds manual exploitation: chaining findings, business-logic bugs, race conditions, authorization bypasses. We do both - automated to maximize coverage, manual to find what scanners miss.
How long does a typical engagement take?
Single web app: 1 week. Web app + API + supporting infra: 2 weeks. Full external + internal + apps + cloud: 3-4 weeks. Cluster-scale environments scoped separately.
What does a pentest cost?
Fixed-price proposals only, invoiced in your local currency (INR / USD / GBP / EUR depending on where you are). One-off pentests typically land in the equivalent of USD 3k-25k depending on scope. Continuous-engagement retainers (quarterly pentests + remediation support) typically the equivalent of USD 5k-15k/month. Send us a scope; you will have a fixed-price proposal in 2 business days.
Do you do attack-surface management (ongoing)?
Yes - typically as a retainer combining Vexta scanning + manual review + monthly posture report. Catches drift between point-in-time pentests.
What about US clients - same methodology?
Same methodology, US-relevant standards in the deliverables (NIST 800-115, OWASP, CIS). For US clients in regulated sectors, we tailor the report to HIPAA / PCI-DSS / SOC 2 controls as needed.

Pentest your stack before someone else does.

Scoping call this week. Findings the next. Re-test included.