Web Application VAPT
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Timeline: 12 working days
₹29,999
GST included
New: Starter plans from ₹100 — fixed-price checks and reviews, GST included
Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.
Overview
Permissions accumulate. A developer needed production access for one incident in 2023 and still has it. A CI role was given administrator rights because the correct policy was fiddly to work out. We pull the access analyser and CloudTrail data, compare granted permissions against what each identity has actually used over 90 days, and write least-privilege policies to replace the broad ones. Nothing is tightened blindly: every change is proposed, reviewed with you, and applied where it will not break a working system.
Deliverables
Benefits
A compromised key gives an attacker far less than it does today
Departed staff and dormant credentials are found and removed
A repeatable quarterly review your team can run without us
Process
Identity inventory and activity logs are gathered and analysed
Granted permissions measured against real usage per identity
Tightened policies drafted and reviewed with the owning teams
Changes rolled out in agreed batches with rollback ready
You can share these from your order page after checkout. The timeline starts once they are received.
FAQ
That is why we use 90 days of real usage data and roll out in batches. Anything ambiguous is flagged rather than guessed at.
Yes, with the equivalent identity services. Mention your provider at checkout.
Only with your written approval, batch by batch. Nothing is revoked unilaterally.
Tell us about your project and we will confirm whether this service fits, or suggest a better option.
This is a professional service delivered remotely; nothing is physically shipped. See the Delivery Policy and Refunds & Cancellation for how delivery, delays and refunds are handled.
Related services
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Timeline: 12 working days
₹29,999
GST included
We find the credentials committed to your repositories, rotate them, and set up scanning so it stops happening.
Timeline: 6 working days
₹12,999
GST included
Share an export of users and roles from one business tool and we list the accounts and permissions that should be removed or reduced.
Timeline: 3 working days
₹300
GST included
A written check of one domain’s HTTPS set-up, certificate and browser security headers, with the fixes listed.
Timeline: 1 working day
₹100
GST included
Incl. GST
₹18,999
Next step
Pick a service with a published scope and price, start small with a plan from ₹100, or tell our team what you need.