Skip to content
// SERVICES

Penetration testing, from India.

I'm a security analyst and independent penetration tester based in Pune, working with startups, MSSPs and product teams across India and remotely worldwide. Fixed price agreed before anything starts, a retest included rather than sold separately, and a report written by the person who did the testing.

What I test

Web applications and REST APIs, which is where most real findings live — broken object level authorisation, session handling, business logic that can be driven out of order. Mobile applications against MASVS. Internal tooling and thick clients. Cloud configuration where it touches the application.

What I test is manual work with automated coverage underneath, not a scan with a review pass. The distinction matters enough that I wrote a whole piece on how to tell them apart — including the cases where a scan is genuinely the right purchase and you should not pay me.

What it costs, in rupees

Web App Assessmentfrom ₹45,000 · 4–6 days

A single web application or dashboard

Web + API Assessmentfrom ₹85,000 · 7–10 days

A product with a REST API and multiple user roles

Security Engineeringfrom ₹9,000 · Retainer or project

Tooling, automation, SIEM work, or secure builds

Smaller fixed-price workfrom ₹6,000

DMARC rollout, security header hardening, external attack surface review — scoped tightly enough to buy without a call.

Prices are in rupees and quoted in rupees. Invoices are raised from India; if GST applies to your organisation it is added at the prevailing rate and shown separately rather than folded into the headline. International clients are invoiced in USD at a rate agreed at the point of quoting, so a currency move mid-engagement is my problem rather than yours.

What working remotely actually looks like

I work IST, which overlaps comfortably with the Gulf, most of Europe in the afternoon, and the UK for the first half of the day. For US clients the practical arrangement is asynchronous, with a fixed call slot early in my evening — and it is worth saying plainly that if you need someone in your timezone for daily standups, that is a real requirement and I am not it.

Testing is done from a fixed set of source addresses that you receive before the window opens, so your team can allowlist or attribute the traffic. You get a technical contact and an escalation number that is answered outside working hours, which matters more than it sounds when something looks like it might be an incident at 11pm.

Before you commission anything

Read a report first. Mine is published in full — a fictional target, real in every other respect. Any provider should be able to show you one, and it tells you more than a capability statement ever will.

Run the free checks. They take seconds, ask for nothing, and if they come back clean I will say so rather than finding something else to sell. And the preparation guide covers the decisions that need making before any engagement starts, whoever ends up doing it.

Start a conversation

Tell me what you are working on and I will reply with an honest scope and a fixed quote — including telling you if you do not need a test.