Home / About Us

// Who we are

A security firm built the way we wished one existed.

Cybergil was founded on a simple frustration: too much of the Indian security market sells automated scans dressed up as expertise, and compliance documents that would not survive contact with a real attacker. We built the alternative.

// Our story

Why we started

Indian businesses are digitising faster than almost anywhere on earth. Payments, healthcare records, logistics, government services — all of it moved online in barely a decade. Security did not keep pace.

Then two things changed at once. Attackers began treating Indian companies as serious targets rather than collateral damage. And the law caught up: the DPDP Act and CERT-In's directions turned security from a discretionary spend into a statutory obligation with real financial consequences.

Cybergil exists for that moment. We are engineers first — people who have built and broken cloud infrastructure, CI/CD pipelines and production applications — and we bring that perspective to security work that too often gets handed to people who have only ever read about the systems they are assessing.

/ At a glance
Registered offices

Bengaluru, Karnataka & Gurugram, Haryana

Practice areas

14 domains mapped; 3 live in Phase 01

Core focus

Offensive security, cloud & DevSecOps, data protection

Who we serve

Commercial enterprises, startups and public sector

Response time

Proposals within one business day

/ Mission

What we're here to do

Make genuine, expert-led security accessible to Indian organisations of every size — not just the ones who can afford a Big Four retainer. Every engagement should leave a client measurably harder to attack than when we arrived, with evidence they can show a regulator, a board, or a customer.

/ Vision

Where we're going

To become the security partner Indian companies name first — a full-spectrum practice across all fourteen domains, trusted equally by fast-moving startups and by government departments, and known for saying the difficult thing rather than the profitable one.

// How we operate

Six principles we don't negotiate on

These aren't poster values. They're the specific commitments we make on every engagement, and you can hold us to each one.

PRINCIPLE 01

Evidence over assertion

If we report a vulnerability, we can demonstrate it. Every finding comes with reproduction steps and proof. We don't pad reports with theoretical risk to justify the invoice.

PRINCIPLE 02

Say the uncomfortable thing

If your architecture is the problem, we'll say so. If you don't need the service you asked for, we'll tell you — even when it costs us the sale. Advice you can't trust is worthless.

PRINCIPLE 03

Engineers, not report writers

Everyone on an engagement has built systems, not just assessed them. That's why our recommendations are implementable rather than generic best-practice boilerplate.

PRINCIPLE 04

Absolute confidentiality

What we find stays between us. NDA before scoping, encrypted handling of all findings, and we never name a client or reuse your data as a case study without written permission.

PRINCIPLE 05

Transparent scope and price

You know the deliverable, the timeline and the cost before we begin. If scope genuinely needs to change mid-engagement, we discuss it before doing the work, not after.

PRINCIPLE 06

We finish what we start

Handing over a report isn't the end of the engagement. We stay available through remediation and retest at no extra cost, because an unfixed finding helped nobody.

// Where we are

Two cities, deliberately chosen

India's security demand is concentrated in two corridors, and we set up in both from day one rather than serving one remotely and pretending otherwise.

Bengaluru

India's product and cloud engineering capital. Our base for application security, cloud architecture review and DevSecOps work — close to the startups and SaaS companies shipping fastest and carrying the most cloud-native risk.

Karnataka, India · Full address to be added

Gurugram

The NCR hub for financial services, insurance, large enterprise and proximity to central government. Our base for GRC, DPDP advisory and regulated-sector engagements where being in the room still matters.

Haryana, India · Full address to be added

// Roadmap

Where we are, honestly

We'd rather show you the real build plan than imply we're something we aren't yet.

  1. 01

    Phase 01 — Months 0 to 6 Active now

    Deliver three services at depth: VAPT across network, web and API; cloud security and DevSecOps; and DPDP readiness and gap assessment. Build the reporting quality and client references everything else depends on.

  2. 02

    Phase 02 — Recurring revenue

    Extend into managed services and retainers — continuous vulnerability management, attack surface monitoring and vCISO engagements — so clients get ongoing coverage instead of annual snapshots.

  3. 03

    Phase 03 — Credentials & regulated sectors

    Pursue the empanelments and certifications that unlock government and BFSI work, and build out GRC, incident response and identity practices alongside them.

  4. 04

    Phase 04 — Full-spectrum practice

    Complete the fourteen-domain map, including OT/ICS, training and the emerging-technology practice covering AI security, supply chain and post-quantum readiness.

A note on credentials: we don't display certifications, empanelments or client logos we haven't earned. When we hold them, they'll appear here with verifiable registration details. Until then, judge us on a scoping call and a sample report.

// Work with us

Start with a conversation, not a contract.

Tell us about your environment. We'll tell you honestly whether we're the right fit and what we'd prioritise first.