Cloud IAM Permissions Audit
Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.
Timeline: 10 working days
₹18,999
GST included
New: Starter plans from ₹100 — fixed-price checks and reviews, GST included
A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.
Overview
Automated scanners find the obvious. They do not find the endpoint that lets one customer read another customer's invoices by changing a number in the URL. This is a manual test, run against OWASP Top 10 and business logic, by someone thinking like an attacker with a valid account. Every finding comes with reproduction steps and evidence, so your developers are not left arguing about whether it is real. A free retest after remediation confirms the fixes worked, and you get a summary letter suitable for customers who ask.
Deliverables
Benefits
Real vulnerabilities found before someone else finds them
A report you can send to customers and auditors
Fixes verified rather than assumed
Process
Targets, roles, test accounts and rules of engagement are agreed
Manual testing over several days, with critical findings reported immediately
Findings written up with evidence and remediation guidance
Fixes verified and the report updated once your team is done
You can share these from your order page after checkout. The timeline starts once they are received.
FAQ
Preferably staging. Where production is unavoidable we agree strict limits and timing, and we do not run destructive tests.
It follows the format auditors and enterprise security teams expect for SOC 2, ISO 27001 and customer due diligence.
You get that in writing, which is itself worth having. It has happened, though rarely on a first test.
Tell us about your project and we will confirm whether this service fits, or suggest a better option.
This is a professional service delivered remotely; nothing is physically shipped. See the Delivery Policy and Refunds & Cancellation for how delivery, delays and refunds are handled.
Related services
Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.
Timeline: 10 working days
₹18,999
GST included
A written check of one domain’s HTTPS set-up, certificate and browser security headers, with the fixes listed.
Timeline: 1 working day
₹100
GST included
The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.
Timeline: 30 working days
₹44,999
GST included
We find the credentials committed to your repositories, rotate them, and set up scanning so it stops happening.
Timeline: 6 working days
₹12,999
GST included
Incl. GST
₹29,999
Next step
Pick a service with a published scope and price, start small with a plan from ₹100, or tell our team what you need.