Simple, Transparent Pricing

Founder-led pentest with retest and consulting hours. Fixed plan pricing with transparent per-scope add-on rates. No hidden costs.

6 pentests / month. Rathnakara (OSCP) leads every pentest engagement. Book ahead.

Penetration Testing

AI, Web, API, Android, iOS, Desktop, Cloud, IoT, Internal Network, and External Network. Pick the plan that fits your scope.

Startup Pentest Plan

For early-stage startups

INR 74,999 + taxes

~$790 / ~€680

1 Scope Included 1 scope = 1 application type, internal and external network included. The exact boundary of each type is published further down this page, in the scope counter. Add a second scope for INR 44,999 (max 2 on this plan, +5 business days delivery). Need 2+ scopes with compliance mapping? The Growth Plan is built for that.
Pick one: AI, web app, API, Android, iOS, desktop, cloud, IoT, internal network, or external network. One target, tested thoroughly.
Report in 5 Business Days 5 business days from kick-off to final report delivery. Business days are Monday to Friday; the weekend is our quality buffer, not counted against your timeline.
Kick-off to final report in one working week, so your investor deadline doesn't slip.
6 Hours of Founder-led Security Consulting 6 consulting hours included with the Startup Plan, usable within 6 months from pentest kickoff. Use during the engagement (remediation pairing, scope clarification) or anytime in the 6-month window (architecture review, threat modeling, compliance Q&A). Extra hours billed at INR 3,500/hr if needed.
Use anytime within 6 months from pentest kickoff. Architecture questions, remediation pairing, compliance prep, threat modeling. Both founders available.
1 Full Retest within One Month After you fix the vulnerabilities we found, we retest every finding to confirm fixes are effective. Scheduled within one month of v1.0 initial report. Completes in 1-3 business days on our side. Report v2.0 is issued at retest close.
Full retest scheduled within one month of the initial report. No extra charge. Your report closes "remediated", not "open".
OWASP Top 10 + PTES Methodology, Investor-Ready Report Industry-standard OWASP Top 10 + PTES (Penetration Testing Execution Standard) methodology. Authentication and access control are inside that baseline: OWASP Top 10:2025 lists them as A07 Authentication Failures and A01 Broken Access Control. Coverage starts here because this is where the lowest-hanging findings are, and there is little value in running advanced work against an application whose baseline has not been verified yet. The order is deliberate: the OWASP baseline first, then the work that needs an understanding of your application - business-logic abuse, chained exploits, privilege escalation and lateral movement - which the Growth Plan carries together as real-world attack simulation. Deliverable is a full technical report with reproduction steps, fix guidance, and risk ratings, plus a 2-page executive summary aligned with what SOC 2 / ISO 27001 auditors expect. OWASP WSTG v4.2 test-case coverage is Growth-only. This plan is OWASP Top 10:2025 executed under PTES, so findings carry their OWASP Top 10 category rather than a WSTG test-case reference.
Manual exploitation, authentication and access-control coverage. Technical report for engineering + 2-page executive summary for investors and enterprise clients.
+1 Scope at INR 44,999 (~$470 / ~€410) Adding the second scope adds 5 business days: 10 business days total for 2 scopes. For 3+ scopes or audit-grade evidence, see the Growth Plan.
Max 2 scopes on this plan. +5 business days to total delivery (10 business days for 2 scopes). Need 3+ scopes or compliance mapping? The Growth Plan is the better fit.

Best Suited For: A first pentest, or the first in a while. Known attack categories tested by hand, with a report investors and enterprise customers accept. Advanced work adds nothing until the baseline is clean.

Get a Startup Pentest Quote Understand scoping
Most Popular

Growth Pentest Plan

For scaling businesses

INR 1,79,999 + taxes

~$1,890 / ~€1,640

1 Scope + 1 Extra Scope Included Internal network counts as a scope too: one scope covers a single Active Directory domain, up to 256 live hosts and up to 3 segmentation boundaries. Larger estates or multi-forest environments are quoted as a custom proposal. 2 scopes total = 2 targets tested (1 base + 1 extra included in the Growth Plan price). E.g., web app + API, or Android app + iOS app. Each platform counts as a separate scope. Add more scopes for INR 74,999 each, and 5 business days each. On a tight deadline, ask us: we can often test several scopes at the same time and finish sooner. 5 or more scopes move to a custom scoping proposal.
Test your web app + API together, or any two targets. Most startups have at least two attack surfaces.
Report in 10 Business Days 10 business days from kick-off to final consolidated report (5 business days per scope). Business days are Monday to Friday; the weekend is our quality buffer, not counted. Parallel-or-sequential choice applies to additional scopes.
Deep enough to catch business logic flaws, fast enough for your deadline.
12 Hours of Founder-led Security Consulting 12 consulting hours included with the Growth Plan, usable within 12 months from pentest kickoff. 2× the Startup Plan allocation. Use during the pentest, the retest window, or anytime in the 12-month window. Extra hours billed at INR 3,500/hr if needed.
Use anytime within 12 months from pentest kickoff. Architecture review, compliance prep, threat modeling, remediation pairing, incident readiness. Both founders available.
1 Full Retest within One Month After you remediate the findings from v1.0, we retest every finding to verify fixes are effective. Scheduled within one month of the initial report. Completes in 1-3 business days on our side. Report v2.0 is issued at retest close.
Full retest scheduled within one month of the initial report. No extra charge. Your report closes "remediated", not "open".
OWASP WSTG v4.2 Test-Case Coverage, Investor-Ready Report OWASP Top 10 + PTES is the baseline on both plans, and the Growth Plan adds systematic coverage from the OWASP Web Security Testing Guide v4.2, the current release. The difference is category coverage versus test-case coverage: the Top 10 names ten categories of weakness, while WSTG sets out the individual tests that establish whether each one is present. In practice that means testing is driven by WSTG test cases, and a finding cites the test case it came from where one maps, so an auditor can see what was actually executed rather than which categories were considered. Findings that come from business-logic or configuration work carry their CWE and OWASP category instead, because no single WSTG case produced them. Growth also carries Real-world Attack Simulation (listed at the bottom of this card), and reports include full SOC 2 / ISO 27001 mapping per finding.
Growth-only. Systematic WSTG test cases on top of the OWASP Top 10 + PTES baseline. Manual exploitation, business logic, auth coverage. Control-mapped technical + executive report your auditor can use as evidence.
+1 Scope at INR 74,999 (~$790 / ~€680) The base 2 scopes take 10 business days, and each additional scope adds 5, so 3 scopes is 15 and 4 is 20. If your deadline is tighter than that, ask us: we can often test several scopes at the same time and finish sooner. That changes the schedule, not the price. Large estates (5+ scopes) get a custom scoping proposal. Each additional scope gets its own findings section and full compliance mapping.
No limit on scopes. Each scope is 5 business days, so 3 scopes is 15 and 4 is 20. On a tight deadline, ask us about testing several at once.
SOC 2 + ISO 27001 Compliance Mapping Compliance mapping ties each finding to SOC 2 Trust Services Criteria and ISO 27001 Annex A controls. Structured for SOC 2 Type 1, Type 2, and ISO 27001 internal + external audits.
Growth-only. Every finding mapped to SOC 2 Trust Services Criteria + ISO 27001 Annex A controls. Your auditor can use the report as direct evidence.
Letter of Attestation for Compliance Auditors Letter of Attestation is a standard deliverable on every Growth Pentest engagement. Signed by Rathnakara GN (OSCP) as Lead Penetration Tester. References the methodology used, the engagement window, and the ISO 27001:2022 Annex A controls that penetration testing supports as audit evidence (A.8.8 management of technical vulnerabilities + A.8.29 security testing in development and acceptance). Structured as first-piece-of-evidence for ISO 27001 audits and customer security questionnaires. Does not contain technical findings or vulnerability detail. Not a certification or accreditation of overall security posture.
Growth-only. One-page PDF signed by our Lead Penetration Tester (OSCP). References ISO 27001:2022 Annex A.8.8 + A.8.29 and the engagement window. Send it to auditors, enterprise customers, and procurement without re-cutting the report.
Real-world Attack Simulation Beyond OWASP Top 10 baseline. Includes chained exploits (one finding amplifying another), privilege escalation, lateral movement, and business logic flaws specific to your application (payment race conditions, IDOR in financial flows, tenant-isolation gaps). The OWASP baseline is pattern-based and can be tested against a defined checklist. Business logic cannot: a race condition in your billing flow is only a finding once we understand what the flow is supposed to do, who is allowed to do it, and where your tenant boundaries sit. That understanding is work that happens before the testing does, which is why this sits on the longer plan rather than the baseline.
Growth-only. Beyond OWASP/PTES baseline: chained exploits, privilege escalation, lateral movement, and business logic abuse specific to your application.

Best Suited For: An auditor, an enterprise security review or a compliance deadline needs SOC 2 or ISO 27001 evidence. Also the plan for more than two scopes, which the Startup Plan caps at.

Get a Growth Pentest Quote Understand scoping

Plan terms and prices on this page are effective from 28 August 2026 · USD and EUR figures are indicative, shown as at August 2026 · The INR price is the one that binds. International engagements are invoiced at the conversion rate on the date of your quote or invoice.

One scope is one thing we test, not one company. A web app, the API behind it and an Android build are three. Each needs a different kind of testing, which is why each is counted separately.

Tick what you want tested

One tick per target.

Nothing ticked yet. Most SaaS startups land on two: the web app and the API behind it.

Ticking two boxes does not always mean paying for two. If both fit inside one scope's work, we quote one. You pay for the effort the test actually takes, and where a surface turns out to be larger than one scope we say so before the SOW rather than after. The scoping call is free and carries no obligation.

There is exactly one point where the price can change. At access verification, after the NDA is signed and before any testing begins, we look at the estate read-only and confirm the work fits the scopes quoted. If it does, the price stands. If something turns out to need its own scope, we tell you then, in writing, and you can decline it. Nothing moves after that, and nothing moves once testing has started.

The same work is the same price, wherever you are. A team in Berlin or San Francisco pays what a team in Bengaluru pays for the same scope. We publish one INR figure and it is the one that binds; the USD and EUR amounts are that same number converted on the day of your quote.

Two of the same kind counts as two scopes, so say if you have more than one. This travels with your enquiry.

Compliance

Scoped per engagement. Talk to us for pricing.

Compliance as a Service

SOC 2 Type 2 & ISO 27001 internal audit prep: gap assessment, control mapping, and policy documentation. DPDP Act and CERT-In readiness for Indian operations. Pairs naturally with pentest evidence.

Scoped per engagement

Pricing FAQ

What is the difference between the Startup and Growth pentest plans?

The Startup plan covers 1 scope in 5 business days with a technical + executive report, 6 hours of founder-led consulting, and 1 free retest. The Growth plan covers 2 scopes in 10 business days and adds systematic OWASP WSTG v4.2 test-case coverage, SOC 2 + ISO 27001 compliance mapping, real-world attack simulation beyond OWASP Top 10, and 12 hours of consulting. Both plans include 1 free retest within one month. Choose Growth if you have a compliance deadline or an enterprise deal in the pipeline.

How long does the full engagement take, including retests?

Engagement duration (testing + v1.0 report) depends on plan and scope count: 5 business days for Startup (1 scope), 10 business days for Growth (2 scopes). Each additional scope adds 5 business days, so 3 scopes is 15 and 4 scopes is 20. If you need it sooner, ask us about testing several scopes at the same time. Business days are Monday to Friday; the weekend is our quality buffer and is not counted against the timeline. After v1.0 ships, the retest is scheduled when your team has finished the fixes. Earliest start: as soon as you are ready. Latest start: one month after v1.0 (this is the upper bound on when retest can begin, not a mandatory wait). Retest itself takes 1 to 3 business days, then v2.0 closes the engagement. Faster remediation on your side closes the engagement faster.

What is the difference between parallel and sequential testing?

Sequential is the default: one scope after another, 5 business days each. Startup is 5 business days for 1 scope and 10 for 2, with no parallel option. Growth is 10 business days for 2 scopes, 15 with one added scope, and 20 with two added scopes. Parallel applies from the 4th scope only, on request: we run the 3rd and 4th together, which brings a 4-scope engagement to 15 business days. It changes the schedule, never the price, and it is confirmed per engagement rather than guaranteed. At 3 scopes parallel changes nothing, so 15 business days is the honest number either way. If you are working to a tighter deadline, tell us and we will try to meet it, subject to our availability and the people we can put on it. Indian public holidays fall outside the business-day count. Large estates of 5 or more scopes get a custom scoping proposal.

Can I add more scopes after the engagement starts?

Yes, you can add scopes during scoping or after the engagement starts. Startup Plan caps at 2 scopes total (1 base + 1 additional at INR 44,999, with +5 business days = 10 business days total for 2 scopes). Growth Plan has no scope limit (each additional scope at INR 74,999); each scope adds 5 business days, so 3 scopes is 15 and 4 is 20, and you can ask us about testing several at the same time if you need it sooner. Large estates of 5+ scopes get a custom scoping proposal. Adding scopes during the engagement is possible but extends the timeline and requires a scope confirmation note in writing before testing begins on the new scope.

What counts as one scope?

One scope is one application surface tested as a complete unit. Examples: a web application is 1 scope, a REST API is 1 scope, an Android app is 1 scope, an iOS app is 1 scope. Web app + API = 2 scopes (separate surfaces, different attack vectors). iOS + Android = 2 scopes (separate platforms, separate code, separate runtime). A microservices backend with 3 distinct services may count as 1 scope or 3 scopes depending on whether they share authentication and architecture. We confirm scope count during scoping before final pricing. If you are unsure, send us your architecture and we will tell you what we would count as a single scope.

What is real-world attack simulation, and why does Growth include it?

Real-world attack simulation tests beyond the OWASP Top 10 baseline by simulating how a determined attacker would actually compromise your application. This includes chained exploits (using one finding to amplify another), privilege escalation (moving from a regular user to admin), and lateral movement (accessing systems outside the initial entry point). We also test business logic flaws specific to your application such as payment race conditions, IDOR in financial flows, and authorization gaps in tenant-isolated data. Growth Plan includes this because compliance buyers and enterprise customers expect their pentest to demonstrate not just OWASP coverage but that the application can withstand a focused attacker. Startup Plan covers OWASP Top 10 + PTES standard methodology, sufficient for buyers without active enterprise or audit pressure.

What does the SOC 2 + ISO 27001 compliance mapping include?

Each finding in the Growth Plan report is mapped to specific control requirements in two frameworks. SOC 2 mapping covers the Trust Services Criteria 2017, typically CC6.1 (logical access security), CC6.3 (role-based access), CC6.6 (protection against external threats), CC7.2 (monitoring), and CC8.1 (change management) for a typical web or API engagement. Separately from the per-finding mapping, the engagement itself is evidence for CC4.1, which calls for ongoing and/or separate evaluations: an external test by a party with no role in building or running the systems is the separate half of that criterion. ISO 27001 mapping covers Annex A controls from the 2022 revision, typically A.5.15 and A.8.3 (access control), A.8.20 to A.8.23 (network and communications security), A.8.25 to A.8.29 (secure development and testing), and A.8.15 (logging). The compliance evidence package is delivered as a separate section of the report and can be handed to your auditor as direct evidence of penetration testing, findings, and remediation. Useful for SOC 2 Type 1, SOC 2 Type 2, and ISO 27001 internal or external audits.

How many consulting hours are included with each pentest?

Startup Plan: 6 hours of founder-led security consulting. Growth Plan: 12 hours of founder-led security consulting. Use these hours during the engagement (scope clarification, remediation pairing) or anytime in the 6-month or 12-month consulting window (architecture review, compliance prep, threat modeling, incident readiness). Both founders are available. Hours do not roll over but typically get fully used.

How much does penetration testing cost in India?

Cybersecify offers penetration testing starting at INR 74,999 for a single scope (AI, web app, API, Android, iOS, desktop, cloud, IoT, internal network, or external network) with delivery in 5 business days. The Startup Plan includes 6 consulting hours and 1 free retest. The Growth Plan at INR 1,79,999 includes 2 scopes, 10 business days, SOC 2 + ISO 27001 compliance evidence, real-world attack simulation, 12 consulting hours, and 1 free retest. All prices exclude taxes.

Can I see a sample report before buying?

Yes. We publish a full redacted sample showing the exact structure, finding format, compliance mapping, and methodology you receive. You can view it online or download it as a PDF. View sample report →

Why do you ask for 50% upfront?

Nothing is invoiced until the scope is agreed in writing. Before a proforma invoice exists you have had a response to your inquiry, a formal quote, a mutual NDA signed by both parties, and a SOW signed by an authorised signatory on both sides setting out the exact scopes you picked, the timeline and the deliverables. You are approving a document you have read, not a description on a web page. The advance confirms the testing slot, which is capped at six pentests a month because both founders work every engagement. The remaining 50% falls due after the v1.0 report is delivered, so the findings are in your hands before we are paid in full. Both sides are exposed for half, and neither is asked to extend trust the other has not already matched.

Still have questions?

Book a 30-min call with Ashok. We'll talk through your scope, your timeline, and which plan actually fits. No sales pressure.