Available for Q3 2026 engagements

Compliance-ready
penetration testing

Clear reports. Fast turnaround. No jargon.
Designed to satisfy your auditor, client, or insurer — not just your security team.

Do you need a pentest for…

Book a scoping call →

Fixed-scope packages.
No surprises.

Every engagement includes a compliance-ready report, free retest of fixed findings, and a scoping call to tailor the test to your environment.

Web Application Pentest

Full-scope testing of your SaaS, web app, or admin panel. Covers OWASP Top 10, business logic flaws, auth bypass, and access control.

  • OWASP / PTES methodology
  • Authenticated & unauthenticated testing
  • Compliance-mapped findings (SOC 2, ISO 27001, PCI-DSS)
  • Free retest of all fixed findings
From $2,000 5–10 business days

API Security Assessment

REST, GraphQL, and SOAP API testing. Covers rate limiting, injection, auth, object-level auth, and mass assignment vulnerabilities.

  • OWASP API Top 10 coverage
  • Swagger / OpenAPI spec review included
  • Token and session management testing
  • Free retest of all fixed findings
From $1,500 3–7 business days

Cloud Configuration Review

AWS, GCP, or Azure security configuration audit. Covers IAM, S3/storage buckets, security groups, logging, and encryption settings.

  • CIS Benchmarks-based assessment
  • IAM & permission boundary review
  • Secrets & exposure scanning
  • Free retest of all fixed findings
From $1,800 5–8 business days

From scoping to retest —
clear at every step.

1

Scope

We define targets, timelines, and compliance requirements together. I review your architecture and tailor the engagement to your needs. NDA signed before any testing begins.

1–2 days
2

Test

Active testing using OWASP, PTES, and NIST-based methodology. You receive a daily status update so nothing is a surprise. No black boxes — you know what's happening.

3–14 days (per scope)
3

Report

You receive a compliance-ready report: executive summary, technical findings with CVSS scores, remediation steps, and an appendix with evidence. Written for auditors and engineers alike.

2–3 days after testing
4

Retest

After your team fixes the findings, I retest every one — free. You get an updated report confirming remediation. Then you're ready for your audit, client review, or insurer sign-off.

Free — included with every engagement

Vulnerabilities responsibly
disclosed to:

These companies were notified of security vulnerabilities through their public bug bounty programs or responsible disclosure channels. This reflects independent security research — not paid client engagements, endorsements, or ongoing contracts.

Redbus Swiggy Lenskart Paytm Grofers Krafton CarDekho CoinSwitch Bosch Houzz FreshMenu WithJoy BigBasket Kiwi SitiBroadband
500+
Vulnerabilities responsibly disclosed
300+
Bug bounty rewards received
100+
Data exposures identified & closed

Bug bounty recognition and paid pentesting engagements are different. The companies above were notified as part of independent security research. For paid client engagements (available after your first contract), see Client Testimonials — coming once I have real client relationships to reference.

Verified credentials.

EC-Council
Certified Ethical Hacker — CEH V13
Penetration Testing · Ethical Hacking · AI Security Modules
The SecOps Group
Certified Network Security Practitioner — CNSP
Network Security · Vulnerability Assessment
ISC2
Certified in Cybersecurity — CC
Security Principles · Risk Management · Incident Response

Built on industry standards.

OWASP

OWASP Top 10, API Top 10, and ASVS-aligned testing across all web and API engagements.

PTES

Penetration Testing Execution Standard — structured, repeatable, and defensible methodology.

NIST SP 800-115

Technical Guide to Information Security Testing and Assessment — planning, execution, and reporting.

CIS Benchmarks

Cloud and infrastructure reviews benchmarked against CIS controls for AWS, GCP, and Azure.

Common questions
answered honestly.

How long does a pentest take?

Most web application pentests are completed in 5–10 business days. API assessments typically take 3–7 days. Network and cloud reviews run 5–14 days depending on scope. You'll have a firm timeline after the scoping call — no moving targets.

What does the report include?

Every report includes: an executive summary for non-technical stakeholders, detailed findings with CVSS scores and business impact, step-by-step remediation guidance, and an appendix with evidence (screenshots, request/response data). If you need the report formatted for a specific compliance framework (SOC 2, ISO 27001, PCI-DSS), that's included.

What happens after the report is delivered?

You fix the findings. I retest everything — free. You get an updated report confirming remediation. If your auditor has follow-up questions, I'm available to respond directly. The goal is to get you through your audit or review, not just hand over a PDF.

Do you sign an NDA?

Yes — always, before any technical discussion or testing begins. I'm happy to work with your standard NDA or provide one. Your data, architecture, and findings remain confidential.

What's the pricing structure?

I use fixed-scope pricing — the price we agree on during scoping is the price you pay. No hourly surprises, no scope creep without your approval. Typical ranges are shown in the Services section. Exact pricing depends on scope, authenticated vs. unauthenticated testing, and number of targets.

Do you work with startups or smaller companies?

Yes. If you're a startup that needs a pentest because a client or investor requires it, I understand budget constraints. Let's discuss it on the scoping call — I'd rather work with you at a rate that makes sense than have you skip a pentest entirely.

Do you do on-site testing?

Most engagements are done remotely. Web apps, APIs, and cloud config reviews are tested over a VPN or against your production/staging environment. We'll agree on the exact approach during scoping.

Who actually does the testing?

Me — Nitish Kumar Shah. I'm the one who scopes, tests, writes the report, and handles the retest. No junior staff, no subcontractors. You get direct access to the person doing the work.

Book a scoping call.

No commitment. No sales pitch. Just a 20-minute call to understand your requirements and see if we're a fit.