Cybergil is an India-first cybersecurity practice built around offensive testing,
cloud & DevSecOps engineering, and the compliance reality Indian businesses now
face under the DPDP Act. We find what your scanners miss — and we tell you
exactly how to fix it.
Web & API VAPTCloud SecurityDevSecOpsDPDP ReadinessRed TeamingISO 27001Incident ResponseOT / ICS SecurityIAMThreat IntelligenceSOC as a ServiceSecurity TrainingWeb & API VAPTCloud SecurityDevSecOpsDPDP ReadinessRed TeamingISO 27001Incident ResponseOT / ICS SecurityIAMThreat IntelligenceSOC as a ServiceSecurity Training
// The compliance clock is running
India changed the rules. Most companies aren't ready.
The Digital Personal Data Protection Rules were notified in November 2025, and the
phased compliance window closes in May 2027. Add CERT-In's six-hour incident
reporting mandate and sector rules from the RBI and SEBI — and security stopped
being optional paperwork.
₹0 crMax DPDP penalty for weak safeguards
0 hrsCERT-In incident reporting window
May 2027Full DPDP enforcement deadline
0Security domains we operate across
The gap most teams miss: DPDP penalties are tied to whether you
implemented "reasonable security safeguards" — a technical question, not a legal one.
A policy document alone won't defend you. Evidence of testing and controls will.
// Phase 01 — active engagements
What we're delivering right now
We'd rather be excellent at three things than average at fourteen. These are the
services our team delivers today, with senior engineers on every engagement.
VAPT — Network, Web & API
Manual, exploit-driven testing that goes past automated scan noise. We chain
findings the way an attacker would and prove real business impact.
External & internal network penetration testing
Web application testing aligned to OWASP WSTG
REST/GraphQL API and authorisation-logic testing
Developer-ready reports with reproduction steps
Cloud Security & DevSecOps
Our core engineering edge. We review how your cloud is actually built —
identity, network, data — then wire security into the pipeline so fixes stick.
Every engagement follows the same disciplined path, built on the frameworks
your regulators and auditors already recognise — OWASP WSTG, PTES,
NIST SP 800-115, and CERT-In's audit expectations.
Free retest included. Once you've remediated, we verify the
fixes and reissue the report. A finding isn't closed until it's proven closed.
01
Scope & Rules of Engagement
We agree targets, testing windows, escalation paths and legal authorisation in writing before a single packet moves.
02
Reconnaissance & Mapping
Asset discovery and attack-surface mapping — including the shadow IT and forgotten subdomains nobody put on the list.
03
Exploitation & Chaining
Manual validation of every finding. We chain low-severity issues into the high-impact paths a real attacker would take.
04
Reporting & Walkthrough
Two reports: an executive view of business risk, and a technical one your developers can act on line by line.
05
Remediation Support & Retest
We stay available while you fix, then retest and certify closure. Evidence you can hand to an auditor.
// Why Cybergil
Built by engineers, not by a report template.
/ 01
Senior engineers on every test
No junior hand-offs. The person who scopes your engagement is the person who tests it and briefs your team afterwards.
/ 02
Cloud-native by default
Most Indian security vendors still test like it's 2015. Our edge is modern cloud, containers and CI/CD — where your risk actually lives now.
/ 03
Compliance translated into engineering
We turn DPDP and CERT-In obligations into specific technical controls and tickets — not a 90-page PDF nobody reads.
/ 04
Zero false-positive reporting
Every finding is manually verified and reproducible. If we can't demonstrate it, it doesn't go in the report as a vulnerability.
/ 05
Two-city presence
Registered in Bengaluru and Gurugram — on-site when an engagement needs hands in the room, remote when it doesn't.
/ 06
Fixed scope, fixed price
You get a defined deliverable and a defined cost before we start. No mid-engagement scope inflation.
// Let's talk
Find out what an attacker already knows.
Tell us what you're running and what's keeping you up at night. We'll come back
with a scoped, fixed-price proposal — and an honest view of whether you need us yet.