Bengaluru & Gurugram

We break your systems
before someone else does.

Cybergil is an India-first cybersecurity practice built around offensive testing, cloud & DevSecOps engineering, and the compliance reality Indian businesses now face under the DPDP Act. We find what your scanners miss — and we tell you exactly how to fix it.

cybergil // live-recon
// The compliance clock is running

India changed the rules. Most companies aren't ready.

The Digital Personal Data Protection Rules were notified in November 2025, and the phased compliance window closes in May 2027. Add CERT-In's six-hour incident reporting mandate and sector rules from the RBI and SEBI — and security stopped being optional paperwork.

₹0 cr Max DPDP penalty for weak safeguards
0 hrs CERT-In incident reporting window
May 2027 Full DPDP enforcement deadline
0 Security domains we operate across

The gap most teams miss: DPDP penalties are tied to whether you implemented "reasonable security safeguards" — a technical question, not a legal one. A policy document alone won't defend you. Evidence of testing and controls will.

// Phase 01 — active engagements

What we're delivering right now

We'd rather be excellent at three things than average at fourteen. These are the services our team delivers today, with senior engineers on every engagement.

VAPT — Network, Web & API

Manual, exploit-driven testing that goes past automated scan noise. We chain findings the way an attacker would and prove real business impact.

  • External & internal network penetration testing
  • Web application testing aligned to OWASP WSTG
  • REST/GraphQL API and authorisation-logic testing
  • Developer-ready reports with reproduction steps

Cloud Security & DevSecOps

Our core engineering edge. We review how your cloud is actually built — identity, network, data — then wire security into the pipeline so fixes stick.

  • AWS / Azure / GCP configuration & IAM review
  • Kubernetes and container hardening
  • CI/CD pipeline security, SAST/DAST/SCA integration
  • Infrastructure-as-Code scanning and guardrails

DPDP Readiness & Gap Assessment

A practical route to compliance: find the personal data you hold, map how it flows, and close the gaps that carry real penalty exposure.

  • Personal data discovery & data-flow mapping
  • Gap assessment against DPDP Act & Rules
  • Consent, notice and data-principal rights workflows
  • Breach response readiness and remediation roadmap
// How we work

A method you can audit, not a black box.

Every engagement follows the same disciplined path, built on the frameworks your regulators and auditors already recognise — OWASP WSTG, PTES, NIST SP 800-115, and CERT-In's audit expectations.

Free retest included. Once you've remediated, we verify the fixes and reissue the report. A finding isn't closed until it's proven closed.

  1. 01

    Scope & Rules of Engagement

    We agree targets, testing windows, escalation paths and legal authorisation in writing before a single packet moves.

  2. 02

    Reconnaissance & Mapping

    Asset discovery and attack-surface mapping — including the shadow IT and forgotten subdomains nobody put on the list.

  3. 03

    Exploitation & Chaining

    Manual validation of every finding. We chain low-severity issues into the high-impact paths a real attacker would take.

  4. 04

    Reporting & Walkthrough

    Two reports: an executive view of business risk, and a technical one your developers can act on line by line.

  5. 05

    Remediation Support & Retest

    We stay available while you fix, then retest and certify closure. Evidence you can hand to an auditor.

// Why Cybergil

Built by engineers, not by a report template.

/ 01

Senior engineers on every test

No junior hand-offs. The person who scopes your engagement is the person who tests it and briefs your team afterwards.

/ 02

Cloud-native by default

Most Indian security vendors still test like it's 2015. Our edge is modern cloud, containers and CI/CD — where your risk actually lives now.

/ 03

Compliance translated into engineering

We turn DPDP and CERT-In obligations into specific technical controls and tickets — not a 90-page PDF nobody reads.

/ 04

Zero false-positive reporting

Every finding is manually verified and reproducible. If we can't demonstrate it, it doesn't go in the report as a vulnerability.

/ 05

Two-city presence

Registered in Bengaluru and Gurugram — on-site when an engagement needs hands in the room, remote when it doesn't.

/ 06

Fixed scope, fixed price

You get a defined deliverable and a defined cost before we start. No mid-engagement scope inflation.

// Let's talk

Find out what an attacker already knows.

Tell us what you're running and what's keeping you up at night. We'll come back with a scoped, fixed-price proposal — and an honest view of whether you need us yet.