About TCP Infosec LLP

A small firm, on purpose.

TCP Infosec was founded on a simple idea: security work should be verifiable. Not asserted in a slide deck, not inferred from a scanner's severity column, but demonstrated, with a working exploit and a fix your engineers can ship.

The name is the practice. Training, Consulting, Pentesting: three disciplines that reinforce each other. We teach from what we find in engagements, and we advise with the instincts of people who spend the rest of the week breaking things.

We have stayed deliberately small. Every engagement is run by a named senior tester, and you can call them. That is not a scaling strategy, it is the product.

How we work

Four commitments we will not trade away.

01
Manual before automated
Tooling gets us to the starting line. Every finding we report was reached and proven by a person.
02
Same-day critical disclosure
If we find something that could hurt you today, you hear about it today, not in the final report.
03
Named accountability
You get the tester, their credentials, and their contact details. No delivery pod, no offshore bench.
04
We sell no products
No vendor commissions, no resale. A recommendation is only ever a recommendation.
The team

The people who will actually be on your engagement.

Replace the placeholder names, photos, and links below with your real team: this section is the single strongest trust signal a boutique practice has.

Add name
Founder & Principal Consultant
OSCP · CISSP
One or two lines: years in the field, the sectors they know best, and something specific they are known for.
Add name
Lead Penetration Tester
OSCP · CRTP
One or two lines: specialisation, notable disclosures or CVEs, conference talks.
Add name
Cloud Security Consultant
CEH · AWS SCS
One or two lines: cloud platforms, compliance frameworks, the kind of estate they work on.
Add name
Training Lead
CEH · CISSP
One or two lines: courses owned, number of cohorts delivered, teaching background.
Credentials & standards

Certified, and mapped to frameworks your auditor recognises.

Certifications are table stakes, not a differentiator, but procurement asks, so here they are alongside the methodologies we test against.

OSCP
CEH
CISSP
CRTP
OWASP WSTG & ASVSWEB APPLICATION TESTING
OWASP API Security Top 10API TESTING
OWASP MASVS & MASTGMOBILE TESTING
PTESENGAGEMENT METHODOLOGY
NIST SP 800-115TECHNICAL ASSESSMENT
CIS BenchmarksCLOUD & HOST CONFIGURATION
MITRE ATT&CKADVERSARY SIMULATION
In the community

We teach where practitioners gather.

Our team trains and speaks at community conferences across India. Add the talk titles and years: public work is verifiable in a way a capability statement is not.

ByteCon
Emcure Pharmaceuticals
CoCon Cyber Security Conference
nullcon

Talk to the people who would do the work.

Mumbai, India · +91 96636 50665