Authorised Penetration Testing for Your Website and Apps
A penetration test is a planned, permitted check where security experts try to find real weaknesses in your own systems before criminals do. You get a clear report and help to fix what we find.
What are penetration testing services and what do you get from them?
Penetration testing services are planned, permitted security tests of systems you own, such as a website, web app or API. Testers act like a real attacker within an agreed scope to see which weaknesses can actually be used. You get a written report with each finding, its risk level, proof and clear fix steps, plus a retest after you fix.
Key takeaways
- We only test systems you own or have written permission to test.
- Scope, dates and rules are agreed in writing before any test.
- Tests are planned to avoid harm to live data and customers.
- You get a report for managers and a detailed one for developers.
- Fixes are retested so you know the gap is really closed.
- A pen test goes deeper than a scan, but is not needed for every business.
What is a penetration test?
A penetration test is an authorised security test where experts try, in a controlled way, to find and confirm weaknesses in your own systems. Our penetration testing services are fully defensive: the goal is to help you fix problems, never to cause damage.
Many people in India call this VAPT, which stands for Vulnerability Assessment and Penetration Testing. The two are often bought together. A vulnerability assessment finds and lists possible weaknesses. A pen test goes further and confirms which ones are real and serious.
Penetration test vs vulnerability assessment: which do you need?
Most small businesses should start with a vulnerability assessment. A penetration test is right when the system is important, handles sensitive data, or a client or rule asks for one.
| Vulnerability assessment | Penetration test | |
|---|---|---|
| Main question | What weaknesses might exist? | Which weaknesses can really be used, and how bad is it? |
| Method | Scans plus manual review | Manual expert testing within agreed rules |
| Depth | Wide | Deep on the agreed scope |
| Time | Shorter | Longer, based on scope |
| Good for | Regular checks, small sites | Apps with logins, payments, patient or customer data, client or audit requests |
| Output | List of issues and fixes | Confirmed findings with proof, risk rating and fix steps |
If you are not sure, start with a security audit. We will tell you honestly if a pen test is worth it for you yet.
What can we test?
We test web-facing systems that your business owns or controls. The scope is written down so both sides know exactly what is in and what is out.
Websites
Business sites, WordPress, WooCommerce and other CMS platforms.
Web applications
Customer portals, booking systems, CRMs and dashboards. See web application security.
APIs
APIs used by your mobile app or partners. See API security.
Cloud setup
Settings and access in your cloud hosting, with the cloud provider's rules followed. See cloud security.
What is usually out of scope
- Systems owned by someone else, such as a shared host, payment gateway or third-party SaaS, unless they give written permission
- Tests that may cause downtime, such as heavy load tests, unless agreed and planned
- Social engineering of staff, unless clearly agreed in writing by management
- Physical access to offices
How our penetration testing process works
Every test follows the same safe path: agree, plan, test, report, fix and retest. You stay informed at each step.
- 1
Free scoping call
We learn what the system does, who uses it and why you want a test. We suggest a scope and type of test.
- 2
Written permission and rules
You sign an authorisation that lists the systems, dates, test windows, contacts and any limits. We confirm you own the systems or have the owner's consent.
- 3
Safe test setup
Where possible we test a staging copy. On live systems we agree quiet hours, avoid destructive actions and have a contact to stop testing at any time.
- 4
Testing
Our team checks the agreed areas such as login, user roles, data access, input handling and configuration, using recognised testing guides.
- 5
Urgent alerts
If we find a critical issue during the test, we tell you at once instead of waiting for the report.
- 6
Report and walkthrough
You get the report and a call to explain each finding to your team.
- 7
Fix support and retest
Your developers fix the issues, or we help. Then we retest and update the report.
We do not publish or share your findings. Reports are sent only to the contacts you name.
What is included in a penetration test report?
A good report is useful to both managers and developers. It explains each risk in simple words and gives exact fix steps.
| Report part | Who it is for | What it contains |
|---|---|---|
| Summary | Owners and managers | Overall risk, top issues and what to fix first, in plain language |
| Scope and method | Auditors and clients | What was tested, when, and which test guides were used |
| Findings list | Developers | Each issue, where it is, risk level and evidence |
| Fix steps | Developers | Clear instructions and good practice to close each issue |
| Retest results | Everyone | Status of each finding after your fixes |
Risk levels are usually Critical, High, Medium, Low and Info. We explain why each issue got its level, so you can plan your work and budget.
How long does a penetration test take?
A small website test may take a few working days. A larger web app or API with many user roles can take one to a few weeks, plus time for the report.
- Number of pages, features and user roles
- Number of APIs and endpoints
- Testing on staging or only on live systems with limited windows
- Whether you want black box (no information) or grey box (test accounts given) testing
- How quickly test accounts and access are provided
- Time for your team to fix before the retest
Grey box testing, where you give us test logins, is usually better value for small teams. It lets us spend time on real risks instead of guessing.
Who needs penetration testing?
You need a pen test if your app holds sensitive data, takes payments, or a client, partner or rule asks for proof of security testing.
- SaaS products and portals where customers log in
- Clinics and health apps with patient data (see clinic patient data security)
- Ecommerce stores with custom checkout or customer accounts
- Fintech, lending or insurance apps
- Businesses asked by an enterprise client for a security test report
- Apps before a major launch or after a big code change
A brochure website with no logins usually does not need a full pen test. Regular updates, a firewall and a website security checklist give more value for the money.
How to choose a penetration testing company
Choose a provider who insists on written permission, explains the scope clearly and gives a sample report before you buy.
- Do they ask for written authorisation and confirm you own the systems?
- Do they explain what is in and out of scope in writing?
- Can they show a sample report with names removed?
- Do they include a retest after fixes?
- How do they protect your data and the report?
- Will they explain findings to your developers on a call?
Cost depends on the scope, number of user roles and APIs, testing on live or staging and the retest needs. You get a clear quote after a free scoping call. SI Cyber is powered by Shivah Web Tech with 11+ years of experience. Contact us to start.
Related Pages
Vulnerability Assessment
Find known weaknesses in your sites and servers before bots do.
Security Audit
A clear report of your security gaps and how to fix them.
Web App Security
Secure code, logins and data in custom web applications.
API Security
Protect the APIs that connect your apps, stores and tools.
Frequently Asked Questions
What is the difference between VAPT and penetration testing?
VAPT means Vulnerability Assessment and Penetration Testing. The vulnerability assessment part finds and lists possible weaknesses using scans and review. The penetration testing part goes deeper and confirms which weaknesses can really be used and how serious they are. Many Indian clients and auditors ask for both together. Small sites often start with the assessment and add pen testing later.
Is penetration testing legal?
Yes, when the owner of the system gives clear written permission and the test stays within the agreed scope. Testing someone else's website or app without permission is illegal. That is why we always sign an authorisation with you before testing and only test systems you own or are allowed to test, such as your own website, app, API or cloud account.
Can a penetration test break my website?
A planned test is designed to avoid harm. We prefer to test a staging copy, agree quiet test hours for live systems, avoid destructive actions and keep a contact who can stop the test at any time. You should still have a fresh backup before testing. Heavy load testing is never done unless you agree to it separately.
How much does a penetration test cost in India?
Cost depends on the size of the scope, the number of user roles, pages and APIs, whether testing is on live or staging, and whether a retest is needed. A small website costs much less than a large app with many features. We give a free scoping call, then a clear written quote that lists exactly what will be tested.
How often should I do a penetration test?
Many businesses test once a year and again after big changes, such as a new login system, payment flow or major release. Some clients and industry rules ask for a set schedule. Between pen tests, regular vulnerability scans and updates help catch new issues. The right timing depends on how often your app changes and how sensitive your data is.
What do I need to give you before a penetration test?
We need written authorisation, the list of systems in scope, a technical contact, preferred test dates and hours, and test accounts for each user role if it is a grey box test. Tell us about any fragile parts of the system. If your hosting or cloud provider has testing rules, we follow them and help you check them.
Do you test mobile apps?
We focus on the web side that mobile apps use, such as the APIs and servers behind the app, which is where many serious issues are found. Testing of the app installed on the phone can be discussed during scoping. We will tell you clearly if a request is outside what we do, so you can plan correctly.
Will you help us fix the issues you find?
Yes. The report gives clear fix steps for each finding, and we hold a walkthrough call with your developers. If you want, our team can help with the fixes as a separate task. After fixes, we retest the findings and update the report so you have proof that the issues are closed.
Talk to our team today
Call or WhatsApp +91 85808 92163. We reply fast, Monday to Friday.