Services
Five practices. 70 services.
Offensive security, governance and compliance, AI consulting, managed services and training — delivered by senior practitioners and amplified by our own platform. The people who scope your work are the people who deliver it.
How it fits together
Two halves of the same job.
Testing tells you what an attacker can actually do. Compliance tells you what you have committed to doing about it. Run separately they produce two registers that disagree by the second year, which is why a great many organisations can show a clean audit and a live vulnerability at the same time.
We run them against one register. A penetration test finding lands as evidence against the control it breaks, and a control gap gets tested rather than asserted. That is the whole argument for buying both from one firm — not the discount.
Security Testing
Find it before somebody else does.
Nine testing services, from a single web application to a full internal network and the source code behind both. Every finding is verified by a person, and a retest is included.
VAPT Services
Assessment and penetration testing, end to end.
Read more → Application SecurityWeb Application Testing
OWASP Top 10, ASVS and business logic.
Read more → Application SecurityAPI Security Testing
REST, GraphQL and service-to-service.
Read more → Application SecurityMobile Application Testing
Android and iOS, binary and backend.
Read more → Infrastructure SecurityNetwork Penetration Testing
External perimeter, internal and Active Directory.
Read more → Cloud SecurityCloud Security Assessment
AWS, Azure and GCP configuration and identity.
Read more → Application SecuritySecure Code Review
Manual review and static analysis across 27 languages.
Read more → Adversary SimulationRed Team Assessment
Objective-based adversary simulation.
Read more → Continuous SecurityAttack Surface Management
Continuous external discovery and monitoring.
Read more →Compliance & Advisory
The programme around the testing.
Testing tells you what is wrong today. These services stop it recurring, and produce the evidence your customers and auditors keep asking for.
Compliance & Audit
The hub — one control set, eight frameworks.
Read more → Data Protection · IndiaDPDP Act Compliance
India’s DPDP Act 2023 and Rules 2025 readiness.
Read more → Managed ServicesManaged Security & vCISO
Security leadership and operations, as a subscription.
Read more → AI SecurityAI Security & Governance
LLM testing, AI governance and private deployment.
Read more → Training & AwarenessSecurity Training
Role-based awareness and secure coding.
Read more →How We Work
Six steps, and no surprises.
The same engagement model applies to every piece of work we take on, whatever the service.
Scope
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Authorise
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Test
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
Report
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
Remediate
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
Retest
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Everything We Deliver
All 70 services, by practice line.
The complete list. If what you need is not here, ask — we will tell you honestly whether it is something we should take on.
Offensive Security & VAPT
Find it before somebody else does. Application, API, mobile, network, cloud and code testing, run by people who exploit what they find and prove it.
- Vulnerability Assessment
- Penetration Testing
- External Attack Surface Management
- Web Application Security Testing
- Mobile Application Security
- API Security Testing
- Cloud Security Assessment
- Network Security Assessment
- Active Directory Assessment
- Red Team Exercises
- Purple Team Engagement
- Security Architecture Review
- Secure Code Review
- Threat Modeling
- Zero Trust Readiness Assessment
- Continuous Security Monitoring
- Wireless Security Assessment
- Incident Response Readiness
- Digital Forensics Support
- Ransomware Readiness Assessment
- Third-Party Security Assessment
- Supply Chain Security Review
- IoT & Embedded Device Testing
Governance, Risk & Compliance
Policy, audit and resilience programmes built to satisfy regulators — and to actually be used by the teams who own them.
- ISO 27001 Implementation
- SOC 2 Readiness
- DPDP Act Readiness
- GDPR Compliance
- HIPAA Compliance
- PCI DSS Readiness
- Risk Assessment
- Risk Register Management
- Vendor Risk Management
- Policy Development
- Internal Audit
- Security Awareness
- Compliance Gap Assessment
- Business Continuity Planning
- Disaster Recovery Planning
- Audit Readiness
- AI Governance Frameworks
- AI Risk Assessment
AI Security & Consulting
From strategy to private deployment — adopt AI at enterprise scale without opening a new class of risk.
- Enterprise AI Strategy
- AI Governance
- Private AI Deployment
- AI Security
- AI Risk Assessment
- AI Agents
- AI Workflow Automation
- RAG Implementation
- LLM Security Testing
- AI Compliance
- AI Adoption Roadmap
- ISO 42001 Readiness
Managed Security & vCISO
Senior security leadership and continuous operations, delivered as a subscription instead of a hiring problem.
- Virtual CISO
- Security Operations Advisory
- Compliance Management
- Audit Management
- Continuous Compliance
- Managed Vulnerability Management
- Security Monitoring
- Executive Security Reporting
- Incident Response Retainer
Security Training & Awareness
Role-based programmes that change behaviour — from the service desk to the boardroom.
- Security Awareness Training
- Phishing Simulation & Response
- Secure Coding Practices
- Cloud Security Fundamentals
- Incident Response & Handling
- ISO 27001 / Compliance Awareness
- Data Privacy (DPDP Act / GDPR) Training
- Role-Based & Executive Cyber Awareness
Questions
Choosing a service — answered.
Which service do we need first?
If you have never had an independent test, start with an external network assessment and a penetration test of your most important application. Between them they cover how somebody gets in from the internet and what they can do once they reach your product, which is where the overwhelming majority of real incidents begin. If a customer or auditor has asked for something specific, buy that first — the deadline is real and the rest can follow.
Can we combine services into one engagement?
Yes, and it is usually cheaper than buying them separately. Application testing, API testing and a secure code review of the same system share a great deal of context, so running them together costs meaningfully less than three separate engagements and produces a better report because the findings cross-reference each other.
Do you work on retainer or project by project?
Both. Most clients start with a project — a defined test with a fixed scope and price — and move to a retainer once they want continuous coverage between annual tests. The managed service exists precisely because an annual test leaves fifty-one weeks unwatched.
How quickly can you start?
Typically within two to three weeks of a signed scope, and faster where there is a genuine deadline. Tell us the date you are working to during scoping and we will tell you honestly whether we can meet it rather than agreeing and then explaining later.
What if we need something not on this list?
Ask. We will tell you plainly whether it is something we should take on, and if it is not, we will point you at somebody who should. Taking work we are not the right firm for is a bad trade for both sides.
Next step
Not sure where to start?
Most people are not, and it is the most common reason for the call. Describe the situation in thirty minutes and we will tell you which piece of work actually answers your question — including when the answer is a smaller one than you expected.