root64Offensive Security. Cyber Resilience. Trusted Expertise.
02 / Choose your engagement

Which engagement answers your question?

The three are sold interchangeably and are not interchangeable. This is the honest version.

Comparison of VAPT, penetration testing and red teaming
Attribute VAPT Penetration testing Red teaming
The question What is exposed across the estate? Can this system be broken into? Would we notice, and how fast?
Goal Coverage Depth Stealth
Who knows Your whole team Your whole team One or two trusted agents only
Typical duration One to three weeks One to two weeks per target Three to eight weeks
Main output Scored finding register Attack paths and proof of impact Timeline, detection gaps, response timings
Good first engagement Yes, for a wide estate Yes, for most organisations No — needs monitoring in place first

Scroll the table sideways to compare →

03 / Attack surface

What we test

One connected view of the systems, identities and human decisions an attacker can chain together.

Connected attack surface / live map
01

Web applications

Authentication, access control between roles, injection, business logic and the admin surface people forget is internet-facing.

02

APIs and cloud

REST and GraphQL authorisation, token handling, IAM boundaries, public exposure and whether your logging would have caught us.

03

Mobile applications

Android and iOS — local storage, certificate handling, hardcoded secrets and the backend behind the app.

04

Networks and Active Directory

Assumed-breach positioning: credential exposure, privilege escalation and lateral movement to domain control.

05

People and process

Phishing, pretexting and social engineering, and whether a report actually reaches someone who acts on it.

06

Training and awareness

Board briefings, employee sessions, phishing programmes, secure development training and tabletop exercises.

04 / Evidence you can act on

What lands on your desk

Identical deliverable set regardless of which engagement you commission.

01

Executive summary

Written for a reader who will not open the technical section. Risk position, the two or three things that matter, and what happens next.

02

Finding register

Severity, CVSS vector, affected asset, evidence and reproduction steps precise enough for your engineer to work from.

03

Same-day critical escalation

Anything critical reaches you the day it is found, with enough detail to act on immediately.

04

Prioritised remediation plan

Ordered by risk and effort, with the fixes that close several findings at once called out.

05

Retest and closure register

Findings verified as fixed and recorded, not marked closed on your word.

06

Letter of attestation

Confirms scope and dates for customers and auditors without disclosing the findings.

05 / Our approach

How we work

Four commitments that are in the contract, not just on the website.

Scope in writing, always
Targets, windows, stop conditions and a named authoriser are agreed before anything is touched. No engagement starts on a verbal go-ahead.
Manual validation over finding counts
A long report is easy to produce and hard to act on. Findings we could not reproduce are marked unconfirmed rather than left in to pad a number.
Critical findings go out the same day
You are told when we find it, not when the document is formatted.
Retest is part of the engagement
A finding is not closed because you say it is fixed. It is closed because we checked.
Sectors

Sectors we work across

Testing methodology is common. What differs is the regulatory pressure, the threat profile and what counts as a crown jewel.

  • Financial services and NBFCs
  • Fintech and payments
  • SaaS and technology
  • Healthcare
  • Manufacturing
  • Hospitality
  • Logistics
  • Education
  • Public sector

Training and awareness

Most incidents start with a person, not a zero-day. We run board briefings, employee awareness sessions, phishing simulations, secure development training and incident tabletop exercises.

See training formats

Amit Dubey — speaker and trainer

Amit speaks on cyber crime, digital fraud and the human side of security at conferences, leadership offsites and corporate training days.

Topics, formats and availability

Your next move

Tell us what you are protecting

A scoping call, an indicative timeline and a written proposal before anyone asks you for a budget.

Contact us