Skip to content

New: Starter plans from ₹100 — fixed-price checks and reviews, GST included

Web Application VAPT

A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.

Price incl. GST
₹29,999
Timeline
12 working days
Deliverables
7 listed below

Overview

About this service

Automated scanners find the obvious. They do not find the endpoint that lets one customer read another customer's invoices by changing a number in the URL. This is a manual test, run against OWASP Top 10 and business logic, by someone thinking like an attacker with a valid account. Every finding comes with reproduction steps and evidence, so your developers are not left arguing about whether it is real. A free retest after remediation confirms the fixes worked, and you get a summary letter suitable for customers who ask.

Deliverables

What you receive

7 items
  1. 01 Manual penetration test covering authentication, authorisation and business logic
  2. 02 OWASP Top 10 coverage plus API-specific testing
  3. 03 Findings rated by CVSS with reproduction steps and evidence
  4. 04 Broken access control testing across every user role you have
  5. 05 Executive summary written for non-technical readers
  6. 06 Remediation guidance specific to your stack, not generic advice
  7. 07 One free retest within 30 days plus a summary letter for customers

Benefits

Why it is worth doing

  • Real vulnerabilities found before someone else finds them

  • A report you can send to customers and auditors

  • Fixes verified rather than assumed

Process

How the work is carried out

  1. 1

    Scope

    Targets, roles, test accounts and rules of engagement are agreed

  2. 2

    Test

    Manual testing over several days, with critical findings reported immediately

  3. 3

    Report

    Findings written up with evidence and remediation guidance

  4. 4

    Retest

    Fixes verified and the report updated once your team is done

Best suited to

  • Products handling payments, health records or personal data
  • Companies asked for a penetration test report by an enterprise buyer
  • Teams that have never had an external security review

What we need from you

  • Test accounts for every role, on staging or a production-like environment
  • Written authorisation to test, signed by someone who can give it
  • A developer contact for any critical finding we need to report urgently

You can share these from your order page after checkout. The timeline starts once they are received.

FAQ

Questions about this service

Preferably staging. Where production is unavoidable we agree strict limits and timing, and we do not run destructive tests.

It follows the format auditors and enterprise security teams expect for SOC 2, ISO 27001 and customer due diligence.

You get that in writing, which is itself worth having. It has happened, though rarely on a first test.

Have a question before you order?

Tell us about your project and we will confirm whether this service fits, or suggest a better option.

Ask about this service

This is a professional service delivered remotely; nothing is physically shipped. See the Delivery Policy and Refunds & Cancellation for how delivery, delays and refunds are handled.

Related services

You may also need

More in Security & Compliance

Incl. GST

₹29,999

Next step

Have something to build, fix or modernise? Start with a conversation.

Pick a service with a published scope and price, start small with a plan from ₹100, or tell our team what you need.