Web Application VAPT
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Timeline: 12 working days
₹29,999
GST included
New: Starter plans from ₹100 — fixed-price checks and reviews, GST included
The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.
Overview
SOC 2 fails on evidence, not on intentions. Auditors want to see that access reviews happened, that changes were approved, that backups were restored and logs retained, over a period of months. Retrofitting that after the window has started is painful. We implement the technical controls first: automated access reviews, change management through pull requests, centralised logging with retention, vulnerability management with SLAs. Evidence collection is automated where possible so your team is not screenshotting consoles the week before the audit.
Deliverables
Benefits
Evidence accumulates automatically instead of being reconstructed
The observation window starts with controls already operating
Fewer auditor findings, which means a shorter and cheaper audit
Process
Current controls compared against the criteria in scope
Technical controls built and integrated with your existing tooling
Evidence collection scheduled so it accumulates without manual effort
A mock evidence request run as an auditor would issue it
You can share these from your order page after checkout. The timeline starts once they are received.
FAQ
No. Audits must come from a licensed CPA firm. We prepare you and work alongside whichever auditor you choose.
The technical controls overlap heavily. ISO also needs an ISMS and management system documentation, which we scope separately.
Type II needs a three to twelve month observation window after controls are operating. This work shortens the run-up, not the window.
Tell us about your project and we will confirm whether this service fits, or suggest a better option.
This is a professional service delivered remotely; nothing is physically shipped. See the Delivery Policy and Refunds & Cancellation for how delivery, delays and refunds are handled.
Related services
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Timeline: 12 working days
₹29,999
GST included
A written check of one domain’s HTTPS set-up, certificate and browser security headers, with the fixes listed.
Timeline: 1 working day
₹100
GST included
Share an export of users and roles from one business tool and we list the accounts and permissions that should be removed or reduced.
Timeline: 3 working days
₹300
GST included
Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.
Timeline: 10 working days
₹18,999
GST included
Incl. GST
₹44,999
Next step
Pick a service with a published scope and price, start small with a plan from ₹100, or tell our team what you need.