Application security testing · India
HEBTECH is a registered Indian cyber security company. We test the web and mobile applications your business depends on — manually, against a written scope — and hand back findings your engineers can act on the same week.
Illustrative report extract. Real findings are shared only with the client.
Incorporated with the MCA · CIN U62099UP2024OPC198886
1,200+ vulnerabilities reported to date
Scope agreed and signed before any testing
Formal verification within 30 days of the report
Track record
Our researchers have been reporting vulnerabilities since 2020 — more than 1,200 to date — through public bug bounty programmes, coordinated disclosure and organisations’ own security channels.
Organisations that have received and resolved reports from our team include Google, Meta, Okta, Cloudflare, GitHub, Shopify, Spotify, Semrush, CrowdStrike, ServiceNow, MetaMask, Coursera and Razorpay. A record of security research, not a client list — our commercial clients are never named.
What we do
Five services, each scoped and quoted on its own. Take one, or run them together as a programme.
Authenticated and unauthenticated assessment weighted toward what scanners miss.
For an application about to go live. Threat model, configuration review, fix verification.
Continuous discovery of what your organisation exposes, not just what it documents.
Android testing combining static package review with runtime instrumentation.
Engineering support while fixes land, then formal verification and a closure summary.
Triage and validation for issues reported to you by outside researchers.
What you receive
Common questions
It depends entirely on scope — a single application with two user roles is very different from a platform with a dozen services. After a short scoping conversation you receive a written timeline and a fixed quotation before anything begins.
Where you want us to, yes — under written authorisation, within an agreed window, and with destructive testing excluded unless you explicitly ask for it. Many clients prefer a staging environment with production-like data.
Scope (domains, applications, environments), test accounts for each user role, a named technical contact, and signed authorisation to test. An NDA is available on request and can be in place before scoping.
No. Client identities are never disclosed. References are only ever provided with explicit written consent from the client concerned.
Findings are delivered encrypted. Engagement data is purged on closure. Nothing is retained beyond the report and the closure summary unless you ask us to keep it.
Yes — remediation support is a service in its own right. We work directly with your developers while fixes land, then verify each one formally.
Send the scope and objective. You receive a written response with an approach, a timeline and a fixed quotation — no obligation, no automated sales sequence.