HAZERCLOUD is a VAPT company. We run vulnerability assessment and penetration testing across your network, web applications, APIs and AWS cloud, then give you findings your engineers can act on, clear guidance on the fix, and a free retest once you have made the changes. Mobile app and source code depth is available through our application security assessment. OWASP-aligned throughout.
What you actually receive.
Modern applications break across three layers: the web app itself, the APIs underneath it, and the cloud infrastructure they run on. We test all three, because attackers don't respect those boundaries either. When one layer needs more depth than an umbrella engagement gives it, we scope it separately: a cloud application security assessment for mobile testing and source code review, or a cloud security audit for the AWS environment itself.
OWASP ASVS Level 2 testing of the application surface attackers actually probe.
OWASP API Security Top 10 testing for the layer that powers your apps and integrations.
Cloud-native review of the AWS account, IAM posture, and exposed services. Most VAPT firms don't do this.
A repeatable process based on OWASP Testing Guide and PTES (Penetration Testing Execution Standard). Predictable for procurement, defensible to auditors.
Free 30-minute scoping call to understand your application, threat model, and constraints. Written rules of engagement, NDA in place before any testing begins.
Passive and active reconnaissance: technology fingerprinting, attack surface mapping, credentialed and uncredentialed enumeration. We map what an attacker would map.
Automated scanning baseline (Burp Suite Pro, Nuclei, AWS-native tools) followed by manual validation. Every finding is verified before it lands in the report.
Manual exploitation attempts within the agreed scope. Business logic flaws, chained attacks, post-exploitation paths. Proof of impact, not just proof of presence.
Technical findings report with CVSS v3.1 scores, evidence, reproduction steps, and remediation guidance. Plus an executive summary for leadership and audit readiness.
Free retest on critical and high findings within 30 days of report delivery. We re-verify your fixes worked, update the report, mark items as remediated.
No surprises at the end of the engagement. Procurement and audit teams know exactly what they are buying.
The detailed report. Each finding includes:
The leadership-facing brief. One page covering:
After remediation, we re-verify. The retest report shows:
We do the technical testing and produce the technical findings report. We do not issue formal SOC 2 or PCI DSS attestation letters, those come from your auditor (a CPA firm for SOC 2) or your QSA (for PCI DSS). Our reports are designed to slot directly into their evidence requirements, so the audit team has what they need without having to chase you for it.
Every finding in the report is tagged with the compliance frameworks it touches. Your audit team gets the evidence pre-sorted, region by region.
Scope drives price. We do not publish flat tiers because a 5-page brochure site and a multi-tenant SaaS API both legitimately need testing, but the work is not comparable. The scoping call is free.
One web app, its APIs, and the AWS account it runs in. Two to four weeks. The most common shape for SOC 2 readiness.
Best for · First-time VAPT, audit prep
Several apps, shared infrastructure, common authentication. Tested as a system. Discount applied vs. running them as separate engagements.
Best for · Scale-ups with a portfolio
Quarterly or twice-yearly retests as your application evolves. Built-in re-verification after every release that touches authentication, payments, or data exports.
Best for · Ongoing audit cycles
Scope and timing aligned to a specific framework window: SOC 2 Type II observation period, PCI DSS annual, SAMA submission, APRA CPS 234.
Best for · Regulated workloads
Scoping calls are conducted by a CEH-certified tester, not a salesperson.
Every engagement is led by a CEH-certified tester on the HAZERCLOUD team. We do not subcontract VAPT to third-party firms. Whoever scopes your work is the same person who tests it and writes the report.
Automated scanners produce false positives. Every finding in your report has been manually verified by a tester. If we report it, it is exploitable.
One retest of all critical and high findings is included. Most VAPT firms charge separately for retest. We do not, because re-verification is the only thing that proves remediation worked.
NDA in place before we see any architecture or credentials. Written rules of engagement signed before any testing starts. Testing windows agreed in advance, no surprises for your operations team.
Whether you shortlist us or not, these are the five things worth checking on any VAPT vendor before you sign. All five are answerable before a contract, and none of them require taking a sales pitch at face value.
Ask which certifications the people doing the testing actually hold, and whether the work is subcontracted onward. Our security team holds CEH, and the tester who scopes your engagement is the one who runs it. If a firm cannot tell you who tests, that is your answer.
A firm handling your vulnerabilities should be able to show it manages its own. Ask whether they hold a recognised information security certification and how they store your findings. Treat it as one neutral checklist item, not the headline reason to choose anyone.
Ask for a sample findings structure before you buy. A good report rates each finding by severity, includes reproduction steps, and separates the fix that ships this week from the one that needs a design change. A wall of scanner output is not a report.
Find out whether retesting after you fix the findings is included or billed separately, and within what window. Re-verification is the only thing that proves remediation worked, so a vendor that charges extra for it is charging you to finish the job.
A testing engagement should stay independent of whoever fixes the findings. Ask whether they will tell you when a lighter piece of work would do, or when your requirement genuinely needs a partner they are not. Willingness to say no is a good sign.
Testing is delivered remotely, so location is about coverage and time zone rather than a local office. These are the markets we work in most.
Headquartered in Kerala, we deliver VAPT to teams across India, including Bangalore, remotely. Same working day, and pricing that suits Indian scale-ups rather than a metro agency rate. See our pages for AWS partner in Kerala and AWS partner in India.
We work with clients across the Gulf on a near-identical working day, covering Bahrain, the UAE and Saudi Arabia from India with the compliance context those engagements need. See AWS partner in Bahrain and AWS consulting in Dubai.
Beyond India and the Gulf we deliver VAPT remotely worldwide, scheduling testing windows and readout calls around your time zone. The methodology and the report are the same wherever you happen to be.
Three services solve three different problems. VAPT is the umbrella; the other two go deeper on one layer each. Here is which is which, so you buy the one that answers your actual question.
How your AWS account is configured: IAM, network exposure, encryption, logging. A misconfiguration, not an exploit. That is a cloud security audit, and fixing what it finds is AWS security hardening.
The software you wrote: web and mobile apps, APIs, and source code review, taken deeper than an umbrella test goes on any single app. That is a cloud application security assessment.
One engagement across network, web, API and cloud that proves what an attacker could actually reach. Start here for breadth, then go to the other two when one layer needs depth.
If you have not procured VAPT before, these are the things to ask any vendor, not just us.
CEH (Certified Ethical Hacker) certification. We are honest that this is a foundational credential rather than CREST or OSCP. The methodology we apply is OWASP ASVS Level 2, OWASP API Security Top 10, and PTES, which are the same standards that more senior testers work to. If your procurement specifically requires CREST or OSCP-led engagements, we will tell you up front and recommend a referral partner.
No. Attestation letters come from your auditor (a CPA firm for SOC 2) or your QSA (for PCI DSS). We produce the technical findings report and evidence pack that those auditors need to see. Our report is structured to slot directly into their workflow, with each finding tagged to the relevant control. Most clients appreciate this honesty up front.
The scoping call is free and runs about 30 minutes. We ask about your application surface (number of authenticated and unauthenticated endpoints), authentication model, integrations and APIs, AWS account complexity, and the compliance framework driving the engagement. From there we send a fixed-price quote with a written rules-of-engagement document. No open-ended hourly billing.
We strongly prefer to test against a staging environment that mirrors production. If production is the only realistic target, we agree testing windows in advance, throttle automated tooling, and exclude destructive payloads (no deletes, no mass writes). Your operations team gets the test source IPs ahead of time so any alerts can be triaged correctly.
Both. The most useful time for a VAPT is six to eight weeks before your audit window opens, because that gives you time to remediate, retest, and present clean evidence. But we also work with teams who simply want to know what their security posture looks like, with no compliance trigger. The methodology is the same.
We schedule a 60-minute readout call with your engineering and security leads to walk through every critical and high finding. After remediation, you tell us when to retest (within 30 days for the free retest window). We re-verify, update the report status, and issue the retest document for your audit evidence pack.
There is no flat price, because a single web application and a multi-account AWS estate with a dozen APIs are not the same job. What you get is a fixed, written quote before anything starts, so there is no open-ended hourly meter. It comes out of a free 30 minute scoping call where we look at your application surface, APIs, cloud complexity and what is driving the work. If a lighter piece of work would answer your actual question, we will say so rather than push a full program. We do not publish invented numbers here, because a price that ignored your scope would be worthless to you.
It depends on scope, and we would rather scope it honestly than quote a number that does not survive contact with your environment. As a rough guide from our own delivery, a single web application or API is usually in the region of one to two weeks from kickoff to report, and a larger multi-application or multi-account program runs longer, because most of the time goes into understanding what is actually deployed. Retesting after you fix the findings is quick by comparison. The timeline goes in writing alongside the fixed quote.
Yes. Retesting is included, free, within 30 days of the original report. Once your team has remediated, you tell us when you are ready and we re-verify each critical and high finding, mark it fixed, partial or not fixed, and issue a retest document you can put in your audit evidence pack. Proving a finding is actually closed matters more than proving it existed, so we treat the retest as part of the engagement rather than an add-on.
HAZERCLOUD holds ISO 27001:2022 and ISO 9001:2015 certification, so the company you are trusting with sensitive findings is audited against a recognised information security standard itself. To be clear about what we are not: we are not a CERT-In empanelled testing body, and we will not claim to be. If your requirement specifically mandates CERT-In empanelment, tell us at the scoping call and we will say so plainly and point you to a suitable partner.
CEH-certified tester on the line, not a salesperson. We will scope, price, and explain the methodology. Whether you engage us or not, you will leave with a clear sense of what good VAPT looks like for your application.
★CEH-certified testers · OWASP ASVS & API Top 10 · AWS-native review · Free retest within 30 days