You have an audit coming up.
ISO 27001, SOC 2 Type II, PCI-DSS, HIPAA, RBI cyber security framework — your auditor has asked for a network VAPT report and you need it in weeks, not months.
Attackers won’t wait. Neither should you. Identify and fix real network vulnerabilities before they cost you.
Most network pentest vendors hand you a 60-page PDF that's 80% automated scanner output. Your developers can't act on it. Your auditor sees through it. Your enterprise client asks follow-up questions you can't answer.
We do it differently. Every EyeQ Dot Net network penetration test is a manual, attacker-mindset engagement run by certified pen testers with real bug bounty and red team backgrounds. We chain low-severity findings into high-impact exploits the way an actual attacker would. We record proof-of-concept videos. We prioritize every finding using CVSS v3.1 scoring so your dev team knows exactly what to fix first. And we retest your fixes for free.
If you've been quoted ₹8 lakh+ by a Big-4 firm and told to wait six weeks for a report there is a better option.
We built this service for the moments where security stops being a checkbox and starts blocking your business. If a single trigger below matches your situation, the rest of the page answers what you're trying to figure out.
ISO 27001, SOC 2 Type II, PCI-DSS, HIPAA, RBI cyber security framework — your auditor has asked for a network VAPT report and you need it in weeks, not months.
Your deal is sitting in procurement. Their security team wants a recent third-party network penetration test report. Every day of delay risks the contract.
The findings weren't fixed properly. Remediation guidance was vague. You need a vendor who will help you actually pass this time — not just hand over another report.
A new product, a new data center, a cloud migration, a new client integration. You want it tested before it goes live and starts holding production data.
Something looked wrong in your logs. A former employee left. A phishing email got through. You need an honest external assessment of what's exposed.
30-person SaaS startup. 200-person fintech. Growing healthcare platform. You don't need a CISO yet — you need a partner who runs the test and walks your devs through fixes.
A complete, end-to-end engagement covering everything inside and outside your perimeter. No upsells. No scope-creep surprises mid-engagement.
We attack your internet-facing infrastructure the way a remote attacker would — public IPs, exposed services, VPN gateways, mail servers, web-facing APIs, DNS, and any forgotten subdomains. We hunt for misconfigurations, default credentials, exposed admin panels, and known CVEs that haven't been patched.
Once we're inside (or simulating an insider, a compromised laptop, or a phished employee), we test how far an attacker can move. Lateral movement, privilege escalation, Active Directory abuse, Kerberoasting, weak SMB shares, internal segmentation gaps. This is where most reports stop and ours begins.
Dedicated review of your perimeter and internal network devices. Misconfigured ACLs, weak management protocols, default SNMP strings, outdated firmware, missing segmentation between VLANs, and IPSec/SSL VPN weaknesses.
Patch levels, exposed services, weak local accounts, missing hardening on Windows, Linux, and hypervisors. We don't just list the CVEs — we show which ones are actually exploitable in your environment.
Most engagements use grey-box because that's what auditors and enterprise clients want to see.
We start with nothing but your scope. Closest to a real external attacker. Best for testing perimeter security and external posture.
You give us limited credentials or network access. Most realistic for compliance audits. Balances depth with time.
Full credentials and architecture documentation. Maximum coverage. Best for high-stakes environments and pre-launch testing.
This is the single most asked question on every discovery call. Here's the honest answer.
| Scope | Timeline |
|---|---|
| Small network — under 10 to 30 IPs, single environment | 5 business days |
| Mid-sized — 50–250 IPs, internal + external | 7–10 business days |
| Enterprise — 250+ IPs, multi-site, AD-heavy | 30–50 business days |
| Emergency / pre-audit rush | 3–5 business days* |
* Subject to team availability. Usually possible with 24–48 hour notice.
Every network is different, so we don't list rigid tiers. Here is the actual range you should expect, so the conversation starts somewhere real.
Under 30 IPs · single environment · external + internal coverage.
50–250 IPs · internal + external · firewall, VPN, AD coverage.
250+ IPs · multi-site · typically 25–35% lower than Big-4 quotes for comparable scope.
Your auditor doesn't want a generic report, they want evidence mapped to specific controls. Every EyeQ Dot Net engagement includes a control-by-control mapping table you can hand directly to your audit team.
We test the controls in Annex A.8 (Asset Management), A.13 (Communications Security), and A.12.6 (Technical Vulnerability Management) — the ones your auditor will actually ask about.
Aligned with AICPA Trust Services Criteria, focused on the Security (CC6.x) and Availability principles. Designed to satisfy your SOC 2 auditor's pentest evidence requirement on the first attempt.
Segmentation testing between CDE and non-CDE networks. External and internal testing. Remediation and retest within the PCI-DSS 12-month testing window.
For healthcare platforms handling PHI. Covers technical safeguards under §164.312 and the Security Risk Analysis required under the HIPAA Security Rule.
For Indian financial institutions, NBFCs, payment aggregators, and insurance entities. Familiar with the specific testing requirements in each framework.
If you're chasing two or more certifications in parallel (common for SaaS), one engagement, one report, multiple control mappings. No need to pay for testing twice.
We get asked all the time how we compare. Here's the honest version, including where bigger names actually win.
| Capability | EyeQ Dot Net | Indusface | AppSecure | Big-4 |
|---|---|---|---|---|
| Turnaround time | 5–10 days | 2–4 weeks | 2–4 weeks | 4–8 weeks |
| Manual exploitation depth | Adversarial | Mixed | Manual | Mixed |
| Free retest after fixes | Included | Add-on | Sometimes | Add-on |
| PoC video for every finding | Standard | Upsell | Sometimes | Rare |
| Direct tester access | Yes | Account mgr | Limited | Account mgr |
| CVSS v3.1 prioritization | Standard | Yes | Yes | Yes |
| SMB / mid-market price fit | Yes | Mid+ | Mid+ | Enterprise |
| Bug bounty / red team team | Yes | Mixed | Yes | Mixed |
We'll tell you straight, if you're a Fortune 500 with a dedicated CISO office, a 12-month pentest calendar, and procurement that mandates Big-4 logos on every report, you should probably go with one of those firms. We're built for the 20–1,000 employee company that needs depth, speed, and value not a logo on the report. If that's not you, we're very likely a better fit. Send us your scope and we'll send you a quote within 24 hours.
Each industry brings its own compliance pressure, threat model, and reporting expectations. We've shaped the engagement template for each.
PCI-DSS-aligned testing. RBI Payment Aggregator audit support. CDE segmentation testing. Worked with payment gateways, neo-banks, and lending platforms across India.
No in-house security team yet. Enterprise customers asking for VAPT reports before they sign. Built for this exact scenario — fast turnaround, clean reports, attestation letter.
HIPAA-aware testing. PHI-handling environment scoping. Healthcare-specific threat modeling — ransomware, medical IoT, telehealth platforms. Pre-launch testing for new patient-facing apps.
RBI Cyber Security Framework alignment. Master Direction on IT Governance compliance. UCB framework testing. Familiar with SAR audits and data localization requirements.
PCI-DSS coverage, payment flow testing, third-party integration risk, and pre-Black-Friday infrastructure hardening. Stress testing under simulated attack conditions.
200–1,000 employees. Multiple cloud providers. Hybrid infrastructure. A real attack surface that needs more than a scanner — but doesn't need a Big-4 quote.
No mystery, no surprise invoices, no "let me get back to you" silence between phases.
We understand your scope, your driver (audit, client request, incident, pre-launch or Whitelable), and your timeline. No sales pitch! we either fit or we tell you we don't.
You get a affordable-price quote, a scope of work document, and a kickoff date. No mystery line items, no "discovery" phase that's secretly billable.
Sign SoW and NDA, agree testing windows, exchange technical contacts, confirm the testing approach (black/grey/white-box) and out-of-scope assets.
Our pen testers execute the engagement. You get daily progress updates. Critical findings are reported immediately, not held for the final report.
Executive summary, technical report, PoC videos, and a remediation walkthrough call with your dev team. They leave the call knowing exactly what to fix and how.
Once your team applies fixes, we re-validate. You get a clean signed Letter of SAFE TO HOST for auditors and enterprise clients.
A lot of vendors call themselves a "VAPT provider" and deliver a Nessus scan with a cover page. That's not penetration testing! that's a vulnerability scan with extra steps. Here's what real manual testing looks like at EyeQ Dot Net.
A medium-severity information disclosure plus a low-severity weak credential plus an unpatched service equals domain admin. Scanners can't make that connection. Our testers do.
Where it's safe and within scope, we prove the vulnerability is real by exploiting it in a controlled way. You get video evidence, not theoretical risk ratings.
Our team has bug bounty submissions to Microsoft, Google, Meta, and various Indian fintechs. We've worked the other side of the firewall. We know what attackers actually try.
Every finding has: where it was found, how to reproduce it, what an attacker could do with it, the CVSS v3.1 score and vector string, and a developer-actionable fix.
We ask three questions: what's driving this, what's your scope, what's your timeline. By the end of the call you'll know if we're the right fit, what it'll cost, and how fast we can start.
The questions we get asked most by CTOs, CISOs, and security heads in their first call. Honest, direct answers — no hedging.