Home / About Us
// Who we areA security firm built the way we wished one existed.
Cybergil was founded on a simple frustration: too much of the Indian security market sells automated scans dressed up as expertise, and compliance documents that would not survive contact with a real attacker. We built the alternative.
Why we started
Indian businesses are digitising faster than almost anywhere on earth. Payments, healthcare records, logistics, government services — all of it moved online in barely a decade. Security did not keep pace.
Then two things changed at once. Attackers began treating Indian companies as serious targets rather than collateral damage. And the law caught up: the DPDP Act and CERT-In's directions turned security from a discretionary spend into a statutory obligation with real financial consequences.
Cybergil exists for that moment. We are engineers first — people who have built and broken cloud infrastructure, CI/CD pipelines and production applications — and we bring that perspective to security work that too often gets handed to people who have only ever read about the systems they are assessing.
Bengaluru, Karnataka & Gurugram, Haryana
14 domains mapped; 3 live in Phase 01
Offensive security, cloud & DevSecOps, data protection
Commercial enterprises, startups and public sector
Proposals within one business day
What we're here to do
Make genuine, expert-led security accessible to Indian organisations of every size — not just the ones who can afford a Big Four retainer. Every engagement should leave a client measurably harder to attack than when we arrived, with evidence they can show a regulator, a board, or a customer.
Where we're going
To become the security partner Indian companies name first — a full-spectrum practice across all fourteen domains, trusted equally by fast-moving startups and by government departments, and known for saying the difficult thing rather than the profitable one.
Six principles we don't negotiate on
These aren't poster values. They're the specific commitments we make on every engagement, and you can hold us to each one.
Evidence over assertion
If we report a vulnerability, we can demonstrate it. Every finding comes with reproduction steps and proof. We don't pad reports with theoretical risk to justify the invoice.
Say the uncomfortable thing
If your architecture is the problem, we'll say so. If you don't need the service you asked for, we'll tell you — even when it costs us the sale. Advice you can't trust is worthless.
Engineers, not report writers
Everyone on an engagement has built systems, not just assessed them. That's why our recommendations are implementable rather than generic best-practice boilerplate.
Absolute confidentiality
What we find stays between us. NDA before scoping, encrypted handling of all findings, and we never name a client or reuse your data as a case study without written permission.
Transparent scope and price
You know the deliverable, the timeline and the cost before we begin. If scope genuinely needs to change mid-engagement, we discuss it before doing the work, not after.
We finish what we start
Handing over a report isn't the end of the engagement. We stay available through remediation and retest at no extra cost, because an unfixed finding helped nobody.
Two cities, deliberately chosen
India's security demand is concentrated in two corridors, and we set up in both from day one rather than serving one remotely and pretending otherwise.
Bengaluru
India's product and cloud engineering capital. Our base for application security, cloud architecture review and DevSecOps work — close to the startups and SaaS companies shipping fastest and carrying the most cloud-native risk.
Karnataka, India · Full address to be added
Gurugram
The NCR hub for financial services, insurance, large enterprise and proximity to central government. Our base for GRC, DPDP advisory and regulated-sector engagements where being in the room still matters.
Haryana, India · Full address to be added
Where we are, honestly
We'd rather show you the real build plan than imply we're something we aren't yet.
-
01
Phase 01 — Months 0 to 6 Active now
Deliver three services at depth: VAPT across network, web and API; cloud security and DevSecOps; and DPDP readiness and gap assessment. Build the reporting quality and client references everything else depends on.
-
02
Phase 02 — Recurring revenue
Extend into managed services and retainers — continuous vulnerability management, attack surface monitoring and vCISO engagements — so clients get ongoing coverage instead of annual snapshots.
-
03
Phase 03 — Credentials & regulated sectors
Pursue the empanelments and certifications that unlock government and BFSI work, and build out GRC, incident response and identity practices alongside them.
-
04
Phase 04 — Full-spectrum practice
Complete the fourteen-domain map, including OT/ICS, training and the emerging-technology practice covering AI security, supply chain and post-quantum readiness.
A note on credentials: we don't display certifications, empanelments or client logos we haven't earned. When we hold them, they'll appear here with verifiable registration details. Until then, judge us on a scoping call and a sample report.
Start with a conversation, not a contract.
Tell us about your environment. We'll tell you honestly whether we're the right fit and what we'd prioritise first.