VAPT for Cloud-Native Software

Find what attackers would actually find. Before they do.

HAZERCLOUD is a VAPT company. We run vulnerability assessment and penetration testing across your network, web applications, APIs and AWS cloud, then give you findings your engineers can act on, clear guidance on the fix, and a free retest once you have made the changes. Mobile app and source code depth is available through our application security assessment. OWASP-aligned throughout.

CEHCertified testers
OWASPASVS & API Top 10
AWSNative review
FreeRetest after fixes
HAZERCLOUD · VAPTCEH-Certified

What you actually receive.

FindingsCVSS scored
EvidenceReproducible
SummaryExecutive-ready
MappingCompliance-tagged
RetestFree, 30 days
Readout60-min call
MethodologyOWASP ASVS
StandardsAPI Top 10
What We Test

Three testing surfaces, one engagement.

Modern applications break across three layers: the web app itself, the APIs underneath it, and the cloud infrastructure they run on. We test all three, because attackers don't respect those boundaries either. When one layer needs more depth than an umbrella engagement gives it, we scope it separately: a cloud application security assessment for mobile testing and source code review, or a cloud security audit for the AWS environment itself.

Web applications

OWASP ASVS Level 2 testing of the application surface attackers actually probe.

  • Authentication and session management flaws
  • Authorization and access control bypass
  • Injection (SQL, NoSQL, command, template)
  • Cross-site scripting (reflected, stored, DOM-based)
  • Server-side request forgery, deserialization
  • Business logic flaws and workflow abuse
  • File upload, path traversal, redirect exploits

APIs (REST & GraphQL)

OWASP API Security Top 10 testing for the layer that powers your apps and integrations.

  • Broken object-level authorization (BOLA)
  • Broken function-level authorization
  • Broken authentication, JWT and OAuth flaws
  • Excessive data exposure and mass assignment
  • Rate limiting and resource exhaustion abuse
  • GraphQL introspection, batching, depth attacks
  • Webhook validation and inter-service trust

AWS infrastructure

Cloud-native review of the AWS account, IAM posture, and exposed services. Most VAPT firms don't do this.

  • IAM policy review, privilege escalation paths
  • S3 bucket exposure, KMS key policy review
  • VPC, security group, and network ACL analysis
  • Public service exposure (RDS, ElastiCache, ECS)
  • CloudTrail, GuardDuty, Config posture
  • Secrets management and credential exposure
  • Lambda permissions, API Gateway authorizers
Methodology

Six phases. Same approach every time.

A repeatable process based on OWASP Testing Guide and PTES (Penetration Testing Execution Standard). Predictable for procurement, defensible to auditors.

01

Scope

Free 30-minute scoping call to understand your application, threat model, and constraints. Written rules of engagement, NDA in place before any testing begins.

02

Recon

Passive and active reconnaissance: technology fingerprinting, attack surface mapping, credentialed and uncredentialed enumeration. We map what an attacker would map.

03

Assess

Automated scanning baseline (Burp Suite Pro, Nuclei, AWS-native tools) followed by manual validation. Every finding is verified before it lands in the report.

04

Exploit

Manual exploitation attempts within the agreed scope. Business logic flaws, chained attacks, post-exploitation paths. Proof of impact, not just proof of presence.

05

Report

Technical findings report with CVSS v3.1 scores, evidence, reproduction steps, and remediation guidance. Plus an executive summary for leadership and audit readiness.

06

Retest

Free retest on critical and high findings within 30 days of report delivery. We re-verify your fixes worked, update the report, mark items as remediated.

What You Receive

Deliverables, spelled out.

No surprises at the end of the engagement. Procurement and audit teams know exactly what they are buying.

Document 01

Technical findings report

The detailed report. Each finding includes:

  • CVSS v3.1 score and severity rating
  • Affected endpoints, parameters, components
  • Step-by-step reproduction instructions
  • Evidence (screenshots, request/response captures)
  • Remediation guidance with code-level recommendations
  • Compliance framework mapping for each finding
Document 02

Executive summary

The leadership-facing brief. One page covering:

  • Scope, methodology, and timeframe
  • Severity counts (critical / high / medium / low)
  • Top three risk themes in plain language
  • Overall risk posture and prioritized recommendations
  • Suitable for board updates and audit evidence packs
Document 03

Retest report

After remediation, we re-verify. The retest report shows:

  • Status of each critical and high finding (fixed / partial / not fixed)
  • Re-verification evidence for closed items
  • Updated risk posture
  • Helpful for SOC 2 and audit evidence trails
  • Free within 30 days of original report
Honest Note On Attestation Letters

We do the technical testing and produce the technical findings report. We do not issue formal SOC 2 or PCI DSS attestation letters, those come from your auditor (a CPA firm for SOC 2) or your QSA (for PCI DSS). Our reports are designed to slot directly into their evidence requirements, so the audit team has what they need without having to chase you for it.

Compliance Mapping

Findings mapped to your auditor's checklist.

Every finding in the report is tagged with the compliance frameworks it touches. Your audit team gets the evidence pre-sorted, region by region.

Engagement Options

Four ways to engage. Pricing on request.

Scope drives price. We do not publish flat tiers because a 5-page brochure site and a multi-tenant SaaS API both legitimately need testing, but the work is not comparable. The scoping call is free.

Single application

One web app, its APIs, and the AWS account it runs in. Two to four weeks. The most common shape for SOC 2 readiness.

Best for · First-time VAPT, audit prep

Multiple applications

Several apps, shared infrastructure, common authentication. Tested as a system. Discount applied vs. running them as separate engagements.

Best for · Scale-ups with a portfolio

Continuous program

Quarterly or twice-yearly retests as your application evolves. Built-in re-verification after every release that touches authentication, payments, or data exports.

Best for · Ongoing audit cycles

Compliance-driven

Scope and timing aligned to a specific framework window: SOC 2 Type II observation period, PCI DSS annual, SAMA submission, APRA CPS 234.

Best for · Regulated workloads

Book Free Scoping Call

Scoping calls are conducted by a CEH-certified tester, not a salesperson.

Standards

What you can expect from every VAPT engagement.

01

CEH-certified testers, no offshoring

Every engagement is led by a CEH-certified tester on the HAZERCLOUD team. We do not subcontract VAPT to third-party firms. Whoever scopes your work is the same person who tests it and writes the report.

02

Manual validation on every finding

Automated scanners produce false positives. Every finding in your report has been manually verified by a tester. If we report it, it is exploitable.

03

Free retest within 30 days

One retest of all critical and high findings is included. Most VAPT firms charge separately for retest. We do not, because re-verification is the only thing that proves remediation worked.

04

NDA before scoping, written rules of engagement

NDA in place before we see any architecture or credentials. Written rules of engagement signed before any testing starts. Testing windows agreed in advance, no surprises for your operations team.

Choosing a Vendor

How to choose a VAPT company.

Whether you shortlist us or not, these are the five things worth checking on any VAPT vendor before you sign. All five are answerable before a contract, and none of them require taking a sales pitch at face value.

01

Tester certifications, held in-house

Ask which certifications the people doing the testing actually hold, and whether the work is subcontracted onward. Our security team holds CEH, and the tester who scopes your engagement is the one who runs it. If a firm cannot tell you who tests, that is your answer.

02

The vendor's own security posture

A firm handling your vulnerabilities should be able to show it manages its own. Ask whether they hold a recognised information security certification and how they store your findings. Treat it as one neutral checklist item, not the headline reason to choose anyone.

03

Report quality, shown not promised

Ask for a sample findings structure before you buy. A good report rates each finding by severity, includes reproduction steps, and separates the fix that ships this week from the one that needs a design change. A wall of scanner output is not a report.

04

A written retest policy

Find out whether retesting after you fix the findings is included or billed separately, and within what window. Re-verification is the only thing that proves remediation worked, so a vendor that charges extra for it is charging you to finish the job.

05

Independence and honest scope

A testing engagement should stay independent of whoever fixes the findings. Ask whether they will tell you when a lighter piece of work would do, or when your requirement genuinely needs a partner they are not. Willingness to say no is a good sign.

Where We Deliver

A VAPT company you can reach, wherever you are.

Testing is delivered remotely, so location is about coverage and time zone rather than a local office. These are the markets we work in most.

IN

India

Headquartered in Kerala, we deliver VAPT to teams across India, including Bangalore, remotely. Same working day, and pricing that suits Indian scale-ups rather than a metro agency rate. See our pages for AWS partner in Kerala and AWS partner in India.

GCC

GCC and the Gulf

We work with clients across the Gulf on a near-identical working day, covering Bahrain, the UAE and Saudi Arabia from India with the compliance context those engagements need. See AWS partner in Bahrain and AWS consulting in Dubai.

WW

Global remote

Beyond India and the Gulf we deliver VAPT remotely worldwide, scheduling testing windows and readout calls around your time zone. The methodology and the report are the same wherever you happen to be.

Where VAPT Fits

VAPT, and its two neighbours.

Three services solve three different problems. VAPT is the umbrella; the other two go deeper on one layer each. Here is which is which, so you buy the one that answers your actual question.

ENV

Environment level

How your AWS account is configured: IAM, network exposure, encryption, logging. A misconfiguration, not an exploit. That is a cloud security audit, and fixing what it finds is AWS security hardening.

APP

Application layer

The software you wrote: web and mobile apps, APIs, and source code review, taken deeper than an umbrella test goes on any single app. That is a cloud application security assessment.

ALL

VAPT, the umbrella

One engagement across network, web, API and cloud that proves what an attacker could actually reach. Start here for breadth, then go to the other two when one layer needs depth.

Common Questions

Questions buyers ask before we engage.

If you have not procured VAPT before, these are the things to ask any vendor, not just us.

What credentials do your testers actually hold?+

CEH (Certified Ethical Hacker) certification. We are honest that this is a foundational credential rather than CREST or OSCP. The methodology we apply is OWASP ASVS Level 2, OWASP API Security Top 10, and PTES, which are the same standards that more senior testers work to. If your procurement specifically requires CREST or OSCP-led engagements, we will tell you up front and recommend a referral partner.

Do you issue formal attestation letters for SOC 2 or PCI DSS?+

No. Attestation letters come from your auditor (a CPA firm for SOC 2) or your QSA (for PCI DSS). We produce the technical findings report and evidence pack that those auditors need to see. Our report is structured to slot directly into their workflow, with each finding tagged to the relevant control. Most clients appreciate this honesty up front.

How do you scope an engagement and price it?+

The scoping call is free and runs about 30 minutes. We ask about your application surface (number of authenticated and unauthenticated endpoints), authentication model, integrations and APIs, AWS account complexity, and the compliance framework driving the engagement. From there we send a fixed-price quote with a written rules-of-engagement document. No open-ended hourly billing.

Will the testing affect our production environment?+

We strongly prefer to test against a staging environment that mirrors production. If production is the only realistic target, we agree testing windows in advance, throttle automated tooling, and exclude destructive payloads (no deletes, no mass writes). Your operations team gets the test source IPs ahead of time so any alerts can be triaged correctly.

Can you test before we are ready for an audit, or only when an auditor is asking?+

Both. The most useful time for a VAPT is six to eight weeks before your audit window opens, because that gives you time to remediate, retest, and present clean evidence. But we also work with teams who simply want to know what their security posture looks like, with no compliance trigger. The methodology is the same.

What happens after we receive the report?+

We schedule a 60-minute readout call with your engineering and security leads to walk through every critical and high finding. After remediation, you tell us when to retest (within 30 days for the free retest window). We re-verify, update the report status, and issue the retest document for your audit evidence pack.

What does a VAPT engagement cost?+

There is no flat price, because a single web application and a multi-account AWS estate with a dozen APIs are not the same job. What you get is a fixed, written quote before anything starts, so there is no open-ended hourly meter. It comes out of a free 30 minute scoping call where we look at your application surface, APIs, cloud complexity and what is driving the work. If a lighter piece of work would answer your actual question, we will say so rather than push a full program. We do not publish invented numbers here, because a price that ignored your scope would be worthless to you.

How long does a VAPT engagement take?+

It depends on scope, and we would rather scope it honestly than quote a number that does not survive contact with your environment. As a rough guide from our own delivery, a single web application or API is usually in the region of one to two weeks from kickoff to report, and a larger multi-application or multi-account program runs longer, because most of the time goes into understanding what is actually deployed. Retesting after you fix the findings is quick by comparison. The timeline goes in writing alongside the fixed quote.

Do you provide retesting after fixes?+

Yes. Retesting is included, free, within 30 days of the original report. Once your team has remediated, you tell us when you are ready and we re-verify each critical and high finding, mark it fixed, partial or not fixed, and issue a retest document you can put in your audit evidence pack. Proving a finding is actually closed matters more than proving it existed, so we treat the retest as part of the engagement rather than an add-on.

Is HAZERCLOUD itself certified?+

HAZERCLOUD holds ISO 27001:2022 and ISO 9001:2015 certification, so the company you are trusting with sensitive findings is audited against a recognised information security standard itself. To be clear about what we are not: we are not a CERT-In empanelled testing body, and we will not claim to be. If your requirement specifically mandates CERT-In empanelment, tell us at the scoping call and we will say so plainly and point you to a suitable partner.

Ready to find what attackers would find?

Book a free 30-minute scoping call.

CEH-certified tester on the line, not a salesperson. We will scope, price, and explain the methodology. Whether you engage us or not, you will leave with a clear sense of what good VAPT looks like for your application.

CEH-certified testers · OWASP ASVS & API Top 10 · AWS-native review · Free retest within 30 days

30 min Free Consultation →