Skip to content

Scope, fee and working days are published on every engagement

CorePhysix Labs Technology lab

Specification SEC·101

SEC · Security & Compliance Defined scope Fixed fee

Web Application VAPT

Manual penetration testing of your web application with evidence for each finding and a retest, so real risks are fixed and proven fixed.

Fee · GST incl.
₹29,999
Duration
12 working days
Deliverables
7

01 Overview

Automated scanners catch the obvious issues but miss flaws such as an endpoint that shows one customer another customer's invoices when an ID in the URL is changed. This is a manual test that works through the OWASP Top 10 and probes your business logic the way an attacker holding a valid login would. Each finding comes with reproduction steps and evidence, a free retest after remediation confirms the fixes, and you receive a summary letter to share with customers who ask.

02 Deliverables

7 items

What you receive at handover

  1. D01 Manual penetration test of authentication, authorisation and business logic
  2. D02 Coverage of the OWASP Top 10 plus API-specific tests
  3. D03 Findings scored with CVSS, each with reproduction steps and evidence
  4. D04 Broken access control testing across every user role in your application
  5. D05 Executive summary that non-technical readers can follow
  6. D06 Remediation guidance specific to your stack rather than generic advice
  7. D07 One free retest within 30 days and a summary letter for your customers

03 Outcomes

What should be true once it ships

  • Exploitable weaknesses are found and closed before an attacker finds them
  • You hold a report that customers and auditors can review
  • Remediation is confirmed by retesting rather than assumed

04 Process

How the 4 stages run

  1. Scope Targets, roles, test accounts and rules of engagement are agreed
  2. Test Manual testing runs over several days, with critical issues reported as soon as they are found
  3. Report Findings are written up with evidence and remediation guidance
  4. Retest Once your team has made the fixes, we verify them and update the report

05 Fit & inputs

A good fit for

  • Applications that handle payments, health records or personal data
  • Businesses asked for a penetration test report by an enterprise customer
  • Teams that have not yet had an external security review

What we need from you

  • Test accounts for every role, on staging or an environment close to production
  • Written authorisation to test, signed by someone entitled to give it
  • A developer contact for critical findings that need urgent attention

These inputs are collected through the technical brief in your dashboard after payment. The duration is counted from when they arrive.

06 Answers

Questions about this engagement

We prefer staging. If production is unavoidable, we agree strict limits and timing, and no destructive tests are run.

It follows the format auditors and enterprise security teams expect for SOC 2, ISO 27001 and customer due diligence reviews.

You receive that conclusion in writing, which is useful evidence in its own right.

This is technology work delivered digitally — nothing is shipped. Work is delivered into systems you control within the duration stated above, and the delivery and refund policies set out what happens if a date is missed.

REL Related

Often considered alongside.

All Security & Compliance

DPDP Act Readiness Review

A gap assessment against the DPDP Act, 2023 covering consent, retention, notices and breach handling, with a prioritised remediation plan.

Inventory of personal data held across your systems, vendors and storage locations

Fixed fee · GST incl.

₹22,999

Duration

15 working days

Cloud IAM Permissions Audit

Every cloud identity checked against what it actually uses, with over-broad permissions tightened in safe batches to limit breach impact.

Inventory of all users, roles, service accounts and access keys

Fixed fee · GST incl.

₹18,999

Duration

10 working days

SOC 2 Evidence Groundwork

Technical controls and automated evidence collection for a SOC 2 Type II audit, operating before your observation window opens.

Control gap assessment against the Trust Services Criteria in scope

Fixed fee · GST incl.

₹44,999

Duration

30 working days

GST included

₹29,999

Next step

Have a system that needs building, fixing or securing?