VAPT — Network, Web & API
Manual, exploit-led testing that proves business impact instead of listing scanner output.
What is VAPT?Home / Services
// Capability mapThis is our full capability map — the complete practice we are building toward. Phase 01 domains are live and staffed today; the rest are sequenced behind them. We'll always tell you plainly which is which.
Three services, delivered by senior engineers. These are where our team's depth is strongest and where Indian businesses have the most urgent, unmet need.
Manual, exploit-led testing that proves business impact instead of listing scanner output.
What is VAPT?Cloud configuration and identity review, plus security built into your delivery pipeline.
See scopeKnow what personal data you hold, where it flows, and which gaps carry penalty exposure.
What is DPDP?Filter by the market each domain serves. Tags mark commercial fit, government fit, newly emerging demand, and the credential-building work that opens doors to regulated sectors.
Adversary-simulation testing across every layer of your estate — the practice everything else at Cybergil is built on.
The frameworks auditors, boards and enterprise customers ask for — implemented so they hold up under scrutiny.
India's data protection regime is now operational. We turn the statute into a concrete engineering and process programme.
Continuous defence for teams without a 24×7 security function of their own.
Our core technical edge. Most breaches today are misconfigurations, not exotic exploits — we find them.
Security that moves at the speed of your release cycle, embedded where developers already work.
Identity is the new perimeter. We make sure the right people — and only the right people — get in.
When something has already gone wrong, the first six hours decide the outcome — legally and technically.
Manufacturing, energy and utilities run on systems that were never designed to be online. Now they are.
The fundamentals, done properly. Unglamorous work that stops the majority of real attacks.
Your people are tested by attackers every day. We make sure they're prepared for it.
Where the threat landscape is heading. We invest here so our clients aren't caught flat-footed.
Senior counsel for the decisions that shape your security programme for years.
Public sector security carries its own standards, procurement rules and reporting duties.
Straight answer on capacity: domains outside Phase 01 are on our roadmap and we scope them case by case. If we don't yet have the depth to deliver something to our own standard, we'll say so and point you somewhere better rather than learning on your budget.
A defined assessment with a fixed scope, timeline and price. Best for a specific audit, a compliance deadline, or a customer security questionnaire you need to clear.
An agreed block of security hours each month — testing, advisory and on-call support. Best for teams shipping continuously who need security to keep pace.
We act as your security function: strategy, vendor management, audits and board reporting. Best for companies too small for a full in-house team but too exposed to go without.
Most clients aren't, at first. Tell us what you're running and what's worrying you — we'll map it to the right service and be honest about priority order.