(P) Penetration Testing

Real exploitation across your full attack surface.

Manual, hands-on-keyboard testing by senior operators. Every finding is proven with a working exploit, rated for business impact, and retested free once you have fixed it.

Scopes we test

Six assessment types, each with a defined method.

Web Application

2–4 WEEKS

Authenticated and unauthenticated testing of your application, its business logic, and its trust boundaries.

Tested for
·Broken access control & IDOR
·Authentication & session flaws
·Injection and SSRF
·Business-logic abuse
OWASP WSTG · OWASP ASVS L2

API

1–3 WEEKS

REST, GraphQL, and internal service APIs, including the endpoints your documentation forgot.

Tested for
·Object & property-level authorisation
·Mass assignment
·Rate-limit & resource abuse
·Token and JWT handling
OWASP API SECURITY TOP 10

Mobile Application

2–3 WEEKS

Android and iOS binaries reverse-engineered, plus the backend they talk to.

Tested for
·Insecure local storage
·Certificate pinning bypass
·Broken authentication
·Runtime tampering & hooking
OWASP MASVS · MASTG

Cloud Environment

2–3 WEEKS

AWS, Azure, and GCP configuration and identity review with targeted exploitation of what we find.

Tested for
·Over-permissive IAM & privilege escalation
·Public storage exposure
·Network segmentation gaps
·Secrets in code and metadata
CIS BENCHMARKS · CSA CCM

Internal & External Network

2–4 WEEKS

Perimeter and internal assessment, including lateral movement and privilege escalation to domain admin.

Tested for
·Unpatched and legacy services
·Active Directory attack paths
·Credential reuse & relay attacks
·Segmentation and egress controls
PTES · NIST SP 800-115

Human Risk & Phishing

2–3 WEEKS

Measured social engineering campaigns that produce a baseline you can improve against, not a blame list.

Tested for
·Credential-harvest phishing
·Pretext calling & vishing
·Payload delivery & EDR response
·Reporting-rate measurement
MITRE ATT&CK INITIAL ACCESS
How an engagement runs

Five phases, agreed in writing before we touch anything.

Mapped to PTES and NIST SP 800-115 so results are consistent, reproducible, and defensible to your auditor.

01
Scoping
WEEK 0
A short technical call to agree targets, rules of engagement, testing windows, escalation contacts, and success criteria. Mutual NDA signed before anything is shared.
You receive
Signed scope document, rules of engagement, fixed price and dates
02
Reconnaissance
DAYS 1–3
Attack surface mapped across network, application, and cloud layers, including assets you may not know are exposed. Nothing destructive.
You receive
Asset inventory and prioritised target list
03
Exploitation
CORE OF ENGAGEMENT
Manual, hands-on-keyboard testing. Low-severity issues are chained to demonstrate the outcome that actually matters. Criticals are disclosed to you the same day we find them, not held for the report.
You receive
Same-day critical disclosure, running findings log
04
Reporting & debrief
WEEK AFTER TESTING
Two documents (an executive summary and a technical report), followed by a live walkthrough with your engineers and, separately, your leadership.
You receive
Executive report, technical report, live debrief
05
Retest
WITHIN 90 DAYS
Once you have remediated, we verify each fix and reissue a clean report you can hand to a customer or auditor. Included in the engagement fee.
You receive
Verified remediation report and attestation letter
Deliverables

Two reports, because two audiences read them.

Your board needs risk and remediation cost. Your engineers need reproduction steps and a fix. We write both, and we walk both teams through it live.

See a redacted sample →
Executive summary
Risk posture, business impact, and remediation cost framing, written for a board audience.
Technical report
Every finding with CVSS rating, affected assets, and full reproduction steps.
Exploit chains
Proof-of-concept showing how issues combine into real compromise, not isolated CVE lists.
Remediation guidance
Specific, developer-ready fixes, not "apply vendor patches".
Live debrief
Separate walkthroughs for engineering and leadership, run by the tester.
Attestation letter
A shareable summary for customers, auditors, and due-diligence requests.
Commercials & assurances

No surprises in procurement.

PRICING MODEL
Fixed price per engagement, quoted from scope. No day-rate creep, no per-finding charges.
TYPICAL RANGE
A single web application starts in the low five figures (INR lakhs); full attack surface reviews scale from there. Quoted in writing before you commit.
LEAD TIME
Scoping call within 2 business days. Testing typically starts within 2–3 weeks of signature.
RETEST
One full remediation retest included within 90 days, at no extra cost.
CONFIDENTIALITY
Mutual NDA before scoping. Findings encrypted at rest, and deleted on request after the retest.
WHO TESTS YOU
Named senior testers holding OSCP, CEH, CISSP, and CRTP. You get their contact details, not a ticket queue.
Common questions

Asked by every security lead we meet.

How is this different from an automated scanning platform?
A scanner reports what it was configured to look for. It cannot reason about your business logic: that a support agent can view any customer record, or that a discount code can be replayed. Automation is our starting point; the engagement is manual exploitation by senior testers, which is where the findings that matter come from.
Will testing take our systems down?
No. Destructive testing and denial-of-service are explicitly out of scope unless you ask for them in writing. Testing windows, rate limits, and escalation contacts are all agreed during scoping, and we prefer a staging environment that mirrors production where one exists.
We need this for a compliance audit. Will your report satisfy it?
Yes. Engagements are mapped to OWASP, PTES, and NIST SP 800-115, and the deliverable includes an attestation letter suitable for SOC 2, ISO 27001, PCI DSS, and customer due-diligence requests.
What happens if you find something critical mid-engagement?
You hear about it that day, through the escalation contact agreed at scoping, with enough detail to start mitigating immediately. We do not hold criticals back to make the final report more impressive.
Do you subcontract or offshore the testing?
Never. Your engagement is run by the named TCP Infosec testers on your scope document, from Mumbai. If that changes for any reason, you are told before testing starts.

Ready to find out what an attacker would find first?

Four questions and we can quote you, reviewed by the tester who would run it.

Scope an engagement