Application security testing · India

Find the flaws in your application before an attacker does.

HEBTECH is a registered Indian cyber security company. We test the web and mobile applications your business depends on — manually, against a written scope — and hand back findings your engineers can act on the same week.

BROKEN-ACCESS-CONTROLCritical
SSRF → METADATAHigh
SESSION-FIXATIONMedium
RETEST-VERIFIEDClosed

Illustrative report extract. Real findings are shared only with the client.

Registered Indian company

Incorporated with the MCA · CIN U62099UP2024OPC198886

Researching since 2020

1,200+ vulnerabilities reported to date

Written authorisation

Scope agreed and signed before any testing

Free retest

Formal verification within 30 days of the report

Track record

Whom we have secured.

Our researchers have been reporting vulnerabilities since 2020 — more than 1,200 to date — through public bug bounty programmes, coordinated disclosure and organisations’ own security channels.

1,200+Vulnerabilities reported
2020Working since
80+Organisations
IndiaRegistered company

Organisations that have received and resolved reports from our team include Google, Meta, Okta, Cloudflare, GitHub, Shopify, Spotify, Semrush, CrowdStrike, ServiceNow, MetaMask, Coursera and Razorpay. A record of security research, not a client list — our commercial clients are never named.

What we do

Security testing across the surfaces your customers actually touch.

Five services, each scoped and quoted on its own. Take one, or run them together as a programme.

Web application penetration testing

Authenticated and unauthenticated assessment weighted toward what scanners miss.

  • Broken access control & IDOR
  • Business-logic abuse
  • Injection, SSRF, auth flaws
Details →

Pre-launch security review

For an application about to go live. Threat model, configuration review, fix verification.

  • Deployment threat model
  • TLS, cloud & server config
  • Secrets and CI/CD hygiene
Details →

Attack-surface monitoring

Continuous discovery of what your organisation exposes, not just what it documents.

  • Subdomain & host discovery
  • JavaScript bundle analysis
  • Change alerting
Details →

Mobile application assessment

Android testing combining static package review with runtime instrumentation.

  • Transport security & pinning
  • Local & shared storage
  • Exported components, IPC
Details →

Remediation support & retest

Engineering support while fixes land, then formal verification and a closure summary.

  • Direct developer support
  • Formal retest
  • Summary for audit or customers
Details →

Vulnerability disclosure support

Triage and validation for issues reported to you by outside researchers.

  • Reproduction & severity rating
  • Impact assessment
  • Remediation guidance
Talk to us →

What you receive

A report your engineers can work from, not a scanner dump.

Reproduction stepsExact requests, accounts and preconditions for every finding
Business impactWhat an attacker gains, stated in your terms — not generic CVSS prose
Specific remediationThe fix for your stack, not a link to a generic guideline
Critical findings same dayP1 issues reported within 24 hours, ahead of the report
Formal retestEach fix verified within 30 days, at no extra cost
Closure summaryA document you can hand to auditors or enterprise customers

Common questions

Before you enquire

How long does an engagement take?

It depends entirely on scope — a single application with two user roles is very different from a platform with a dozen services. After a short scoping conversation you receive a written timeline and a fixed quotation before anything begins.

Do you test production systems?

Where you want us to, yes — under written authorisation, within an agreed window, and with destructive testing excluded unless you explicitly ask for it. Many clients prefer a staging environment with production-like data.

What do you need from us to start?

Scope (domains, applications, environments), test accounts for each user role, a named technical contact, and signed authorisation to test. An NDA is available on request and can be in place before scoping.

Will you name us as a client?

No. Client identities are never disclosed. References are only ever provided with explicit written consent from the client concerned.

What happens to our data afterwards?

Findings are delivered encrypted. Engagement data is purged on closure. Nothing is retained beyond the report and the closure summary unless you ask us to keep it.

Can you help us fix things, not just find them?

Yes — remediation support is a service in its own right. We work directly with your developers while fixes land, then verify each one formally.

Tell us what needs testing.

Send the scope and objective. You receive a written response with an approach, a timeline and a fixed quotation — no obligation, no automated sales sequence.

Request an engagement →