OSCP · CEH · CISSP certified · Mumbai, India

Evidence over assurances.

TCP Infosec is a boutique offensive security practice. We show you the exploit path, the blast radius, and the fix, every finding proven by hand, never by scanner.

Why it matters who tests you

A scanner finds what it was told to look for. We find what your business logic allows.

The market is filling with automated platforms selling volume of findings. Our engagements are run hands-on-keyboard by senior testers who chain low-severity issues into the outcome that actually matters to your board.

01
Senior testers only
Every engagement is led by a tester with 15+ years in the field. No juniors learning on your estate.
02
Manual exploitation
Scanners are a starting point, not the deliverable. Findings are proven with working proof-of-concept.
03
Free retest included
Once you have remediated, we verify the fix and reissue the report at no additional cost.
04
Named accountability
You know who tested you, and you can call them. Debriefs are run by the tester, not an account manager.
Proof of work

Judge us on the report, not the pitch.

Sample deliverable

Redacted web & API pentest report

42 pages. Executive summary, risk ratings, full exploit chains with proof-of-concept, and developer-ready remediation. This is exactly what you receive.

-Executive summary written for a board audience
-CVSS-rated findings with business impact
-Full exploit chains and reproduction steps
-Developer-ready remediation guidance
Download sample report
Selected engagements, anonymised
FINTECH · WEB + API4 WEEKS
Auth bypass chained to full account takeover
Three criticals. A weak password-reset token combined with an IDOR in the account API allowed takeover of any user, including admin. Remediated and retested inside two weeks.
PHARMACEUTICALS · INTERNAL NETWORK3 WEEKS
Domain admin from a single unpatched print server
Lateral movement from one legacy host to full domain compromise. Delivered a prioritised hardening roadmap alongside the findings.
SAAS · CLOUD REVIEW2 WEEKS
Public storage bucket exposing customer documents
Misconfigured IAM policy and an over-permissive bucket. Found in day two, disclosed same day, fixed before the report was issued.
What we do

Three disciplines, one standard of proof.

Methodology

Rigour you can audit, step by step.

Every engagement is mapped to recognised frameworks, so results are consistent, reproducible, and defensible to your auditor.

01
Scoping
Targets, rules of engagement, and success criteria agreed in writing before anything starts.
02
Reconnaissance
Attack surface mapped across network, application, and cloud layers.
03
Exploitation
Manual, hands-on-keyboard testing. Findings chained to demonstrate real business impact.
04
Reporting
Prioritised findings, proof-of-concept, and remediation your engineers can action.
05
Retest
We verify your fixes and reissue a clean report, included in the engagement fee.
FRAMEWORKS
OWASP WSTG & ASVS · OWASP API Top 10 · OWASP MASVS · PTES · NIST SP 800-115
CREDENTIALS
OSCP · CEH · CISSP · CRTP, held by the testers who run your engagement
CONFIDENTIALITY
Mutual NDA before scoping. Findings encrypted at rest and deleted on request post-engagement.
RETEST POLICY
One full remediation retest included within 90 days of report delivery, at no extra cost.
The team

You will know exactly who is testing you.

No offshore bench, no rotating juniors. The people below run your engagement personally.

Full team & credentials →
Add name
Founder & Principal Consultant
OSCP · CISSP
Add name
Lead Penetration Tester
OSCP · CRTP
Add name
Cloud Security Consultant
CEH · AWS SCS
Add name
Training Lead
CEH · CISSP
15+
Years of cyber security experience
6K+
Employees trained
200+
Successful security engagements
Trusted by
ByteCon
Emcure Pharmaceuticals
CoCon Cyber Security Conference
nullcon
Scope an engagement

Four questions and we can quote you.

You'll get a scoped proposal with price and timeline within one business day, reviewed by the tester who would run it, not a sales desk.

info@tcpinfosec.com+91 96636 50665
Mumbai, India · NDA on request
03 · Driver
We reply from a named tester's address. Your details are never shared or resold.