Skip to content

Every engagement lists its scope, timeline and fixed fee before checkout

Techluminate
Security & Compliance TL-SEC-101 Popular

Web Application VAPT

A manual penetration test of your web application, with proof-of-concept evidence for each finding and a retest after remediation.

Timeline
12 working days
Deliverables
7 listed
Practice
Security & Compliance
Fixed fee
₹29,999
01Overview

What this engagement delivers

Automated scanners catch the obvious issues but miss flaws such as an endpoint that exposes another customer's invoices when an ID in the URL is changed. This is a manual assessment against the OWASP Top 10 and your business logic, carried out from the perspective of an attacker holding a valid account. Every finding includes reproduction steps and evidence, so developers can act on it without debate. A retest after remediation is included to confirm the fixes, along with a summary letter for customers who request one.

02Deliverables 7 items

What you receive

  1. Manual penetration test covering authentication, authorisation and business logic
  2. OWASP Top 10 coverage plus API-specific testing
  3. Findings rated by CVSS with reproduction steps and evidence
  4. Broken access control testing across every user role you have
  5. Executive summary written for non-technical readers
  6. Remediation guidance specific to your stack, not generic advice
  7. One free retest within 30 days plus a summary letter for customers
03Process

How the work runs, in 4 stages

  1. Stage 1: Scope

    Targets, roles, test accounts and rules of engagement are agreed

  2. Stage 2: Test

    Manual testing over several days, with critical findings reported immediately

  3. Stage 3: Report

    Findings written up with evidence and remediation guidance

  4. Stage 4: Retest

    Fixes verified and the report updated once your team is done

04Fit & inputs

Who it suits, and what we need from you

Ideal for

  • Products handling payments, health records or personal data
  • Companies asked for a penetration test report by an enterprise buyer
  • Teams that have never had an external security review

What we need from you

  • Test accounts for every role, on staging or a production-like environment
  • Written authorisation to test, signed by someone who can give it
  • A developer contact for any critical finding we need to report urgently

You provide these through the technical brief in your dashboard after checkout.

05Benefits

What changes for your team

  • 01

    Vulnerabilities found and fixed before they can be exploited

  • 02

    A report you can share with customers and auditors

  • 03

    Fixes verified rather than assumed

06FAQ

Questions about this engagement

Preferably staging. Where production is unavoidable we agree strict limits and timing, and we do not run destructive tests.

It follows the format auditors and enterprise security teams expect for SOC 2, ISO 27001 and customer due diligence.

You receive that conclusion in writing, which is useful evidence in its own right for customers and auditors.

This is a remote engineering engagement — nothing is shipped physically. Work is delivered into systems you control. See delivery & handover and refunds & cancellation for the full terms.

Related engagements

Often considered alongside this one.

All Security & Compliance
Security & Compliance TL-SEC-105

Secrets and Dependency Hygiene Sprint

Credentials committed to your repositories found and rotated, with automated scanning set up to stop new ones slipping in.

Full git history secret scan across up to 20 repositories

6 working days Scope published

Fixed fee · GST incl.

₹12,999

Security & Compliance TL-SEC-103

SOC 2 Evidence Groundwork

The technical controls and automated evidence collection a SOC 2 Type II audit requires, in place before the observation window begins.

Control gap assessment against the Trust Services Criteria you are scoping

30 working days Scope published

Fixed fee · GST incl.

₹44,999

Security & Compliance TL-SEC-102

DPDP Act Readiness Review

A practical gap assessment against India’s DPDP Act 2023, covering consent, retention, notices and breach procedures.

Personal data inventory across systems, vendors and storage locations

15 working days Scope published

Fixed fee · GST incl.

₹22,999

Security & Compliance TL-SEC-104

Cloud IAM Permissions Audit

Every identity in your cloud account reviewed against its actual usage, with over-permissioned roles tightened safely.

Inventory of every user, role, service account and access key

10 working days Scope published

Fixed fee · GST incl.

₹18,999

Next step

Bring the problem. Leave with a defined plan.

Pick the engagement that matches what you need, or tell us about the system you are working on and we will point you to the right starting place.