Track record

The organisations our team has helped secure.

HEBTECH Cyber Securities Services (OPC) Private Limited is a cyber security company registered with the Ministry of Corporate Affairs, Government of India. Our researchers have been finding and reporting vulnerabilities since 2020 — more than 1,200 to date — for organisations ranging from global technology platforms to Indian financial services.

1,200+Vulnerabilities reportedAcross public, private and direct disclosure
2020Working sinceSix years of continuous research
80+OrganisationsReports received and resolved
IndiaRegistered companyCIN U62099UP2024OPC198886

Where we have worked

Organisations our team has reported vulnerabilities to.

Through public bug bounty programmes, coordinated disclosure programmes and organisations’ own security channels. Every finding was reproduced, triaged and confirmed by the receiving organisation’s security team.

GoogleDisclosure programme
Meta / FacebookDisclosure programme
OktaBugcrowd
CloudflareHackerOne
GitHubHackerOne
ShopifyHackerOne
SpotifyHackerOne
SemrushHackerOne
MetaMaskHackerOne
CrowdStrikeHackerOne
ServiceNowHackerOne
DynatraceHackerOne
CourseraHackerOne
RazorpayHackerOne
CircleHackerOne
MatomoHackerOne
OmiseHackerOne
AutomatticHackerOne
TrendyolHackerOne
SuperhumanHackerOne
Telegram WalletHackerOne
Veterans UnitedHackerOne
MirantisHackerOne
HackerOneHackerOne
What this list is. These organisations operate vulnerability disclosure or bug bounty programmes and have received and resolved security reports from our researchers. It is a record of security research, not a client list, an endorsement or an affiliation — all names remain the trademarks of their respective owners. Our commercial clients are never named. Client identities are disclosed only with written consent, and references are provided the same way.

Public sample

One profile, open for anyone to check.

Most of our work is private. A portion is public, and where it is, you can verify it yourself rather than take our word for it.

7.00Signal · 99th pctShare of reports accepted as valid
20.63Impact · 74th pctAverage severity of findings
227Findings on this profileValidated by the receiving organisation
#6Cloudflare programme rank732 reputation on that programme alone

Figures published by HackerOne on the public profile hackerone.com/imtheking, one of our researchers. Signal and Impact are computed by HackerOne, not self-reported. The 1,200+ figure above covers our whole team across every channel, of which this profile is one part.

Recent disclosed work

The kind of issue we find.

Publicly disclosed and resolved. These are the flaws automated scanning does not reach — access control, session handling and request forgery inside real business logic.

Mirantis

Clickjacking on the account page leading to critical account actions

Resolved · bounty awarded

Veterans United

IDOR — saved-search manipulation via a user-controlled identifier

Resolved

Veterans United

IDOR — unauthorised edit of another user’s contact preferences

Resolved

Veterans United

Session not expired after logout

Resolved

Veterans United

CSRF — listing saved without the user’s consent

Resolved

Findings from commercial engagements are never published. These were disclosed by the receiving programme under coordinated disclosure.

In their words

What the organisations we tested said.

Published verbatim by the programmes themselves on our public research profile.

“This researcher is top notch! They have found many great findings and recently a very challenging to discover but severe finding. Would highly recommend working with them especially on authentication/authorization issues. They really know how find more nuanced vulnerabilities.”
Veterans UnitedDisclosure programme
“I had a great experience working with this hacker. Their skills and professionalism exceeded my expectations. They were prompt, efficient, and kept me informed throughout the process. I highly recommend their services to anyone in need of their expertise.”
BucksenseDisclosure programme
“Well written report, quick response times, and retesting.”
Veterans UnitedDisclosure programme

What this means for you

The same testing, scoped to your application.

Manual-led, not scanner-led

A 99th-percentile signal score means findings are reproduced and verified before they are submitted. You receive issues that are real, not a queue of false positives to triage yourself.

Depth in access control

The bulk of our disclosed work is broken access control, IDOR and business-logic abuse — the class of flaw that leaks other customers’ data and that automated tooling consistently misses.

A registered counterparty

HEBTECH is an incorporated Indian company, not an individual contractor. You contract with a registered entity, under an NDA and written authorisation, with a CIN you can verify on the MCA public register.

Tell us what needs testing.

Send the scope and objective. You receive a written response with an approach, a timeline and a fixed quotation — no obligation, no automated sales sequence.

Request an engagement →