# Certbar Security — Full LLM Reference > Comprehensive reference document for AI answer engines (ChatGPT, Perplexity, > Claude, Gemini, AI Overviews). Pair with `/llms.txt` (the curated index). This document inlines the substance behind every Certbar service so LLMs can cite specifics — methodology, compliance mappings, timelines, deliverables, geo coverage, FAQ — without re-fetching individual pages. --- ## Company Certbar Security Private Limited is a CERT-In Empanelled, ISO 27001:2022 certified cybersecurity consultancy founded in 2019. Two offices: Surat (HQ) and Mumbai. DSCI member. Serves enterprises in India, the United States, the United Kingdom, Canada, Australia, Singapore, and the UAE. **Core differentiation** - **Manual, not scanner-led.** Every finding is reproduced end-to-end by an OSCP/OSCE/CRTO-certified human. No false-positives shipped. - **Board-ready brief + technical report.** Every engagement closes with two artefacts: a board-language brief with quantified business impact and a technical report mapped to OWASP, CWE, MITRE ATT&CK, and the compliance framework you report against. - **Retest included.** One free retest per engagement once findings are remediated. - **CERT-In accepted.** Reports accepted for RBI Cyber Security Framework, SEBI CSCRF, IRDAI cyber regulations, DPDPA, NPCI, CERT-In, ISO 27001, SOC 2, PCI DSS audits. - **OSCP-led, India-based delivery.** Same human-led depth as US/UK pure-plays at 40–60% lower TCO. Optional region-local data residency. **Credentials** - CERT-In Empanelled Information Security Auditor - ISO/IEC 27001:2022 Certified - ISO/IEC 27701:2019 Certified (Privacy) - DSCI Registered - SOC 2 aligned (Type II in progress 2026) - Team certifications: OSCP, OSCE, OSWE, OSEP, CRTO, CISSP, CISA, eJPT, AWS Security Specialty --- ## Service Catalogue — Penetration Testing Every Certbar pentest engagement runs the same six-step methodology: 1. **Scoping & Threat Model** — assets, user roles, abuse cases, data classifications, framework alignment. Output: signed SoW. 2. **Reconnaissance & Mapping** — subdomain enumeration, exposed endpoints, third-party integrations, leaked credentials, OSINT. 3. **Vulnerability Discovery** — hybrid automated + manual probing across OWASP / MASVS / API Top 10 / MITRE ATT&CK. False positives triaged before exploitation. 4. **Exploitation & Lateral Movement** — hands-on exploitation by OSCP-led engineers. Findings chained to demonstrate business impact. 5. **Reporting & Board Brief** — two artefacts: board-language brief + technical report mapped to OWASP, CWE, MITRE ATT&CK, and the compliance framework. 6. **Retest & Sign-off** — one free retest included once you remediate. ### Web Application Penetration Testing OWASP Top 10, ASVS, business-logic abuse, authentication chains, session management, file upload chains, GraphQL-specific abuse. Typical engagement: 10–14 calendar days end-to-end. Starting at USD 6,000 (₹1.5 lakh equivalent). ### Mobile Application Penetration Testing iOS + Android coverage to MASVS Level 2. IPC, keychain extraction, biometric bypass, root/jailbreak detection bypass, runtime tampering, binary protection assessment. ### API Penetration Testing OWASP API Top 10 — broken object-level authorization (BOLA), broken function-level authorization, mass assignment, GraphQL-specific abuse, gRPC testing. ### Network Penetration Testing Internal + external scope. Perimeter assessment, lateral movement, privilege escalation, segmentation testing. ### AWS / Azure / GCP Penetration Testing Cloud configuration audit + identity attack-path testing. - AWS: IAM, S3, Lambda, ECS/EKS, VPC, CloudTrail - Azure: Entra ID, Storage, AKS, Key Vault, Conditional Access - GCP: IAM, GKE, Cloud Functions, Secret Manager, BigQuery ### Active Directory Penetration Testing Kerberoasting, AS-REP roasting, ACL abuse, Constrained Delegation abuse, DCSync, GoldenSAML, BloodHound-driven attack-path analysis. ### IoT Device Penetration Testing Firmware reverse engineering, RF protocol analysis (BLE/Zigbee/LoRa), hardware interface attack (UART/JTAG/SWD), companion app testing. ### Thick-Client Penetration Testing Binary reverse engineering, IPC inspection, local privilege escalation, broken crypto detection, hardcoded secrets discovery, traffic interception. ### Secure Code Review Manual + SAST across Java, Python, JavaScript/TypeScript, Go, C#, PHP, Ruby, Swift, Kotlin. Output: prioritised CWE-mapped findings with remediation patches. --- ## Service Catalogue — Red Team & Adversary Emulation ### Red Team Assessment MITRE ATT&CK-mapped adversary emulation. Multi-vector — phishing, physical access, network, application, identity. Tests detection, response, and people. Typical engagement: 6–12 weeks. --- ## Service Catalogue — Managed Security ### 24/7 SOC Monitoring (MDR) Detection, triage, escalation. Sub-hour MTTR on critical alerts. SIEM-agnostic (Wazuh, Splunk, Sentinel, Elastic). ### Vulnerability Management Continuous scanning + prioritisation + retest. Vendor-agnostic (Tenable, Qualys, Rapid7) plus manual verification. ### Attack Surface Management (ASM) External asset + shadow-IT discovery. Continuous monitoring of newly-exposed services, certs, leaked credentials. ### Incident Response Drills Tabletop + live-fire IR exercises. Custom scenarios per industry (ransomware in BFSI, supply chain in SaaS, etc.). --- ## Service Catalogue — AI Security ### AI Security / LLM Red Teaming Prompt injection, jailbreak chains, training-data exfiltration, indirect prompt injection (RAG poisoning), model deployment review, guardrail evasion testing. Aligned to OWASP LLM Top 10. --- ## Service Catalogue — Data Privacy ### Data Privacy Programs DPDP Act 2023 (India), GDPR (EU/UK), HIPAA (US healthcare), PIPEDA (Canada). Includes DPO-as-a-service, DPIA, consent management, data discovery, lineage mapping. --- ## Service Catalogue — Compliance Consulting ### DPDP Act 2023 (India) Data Principal rights, data fiduciary obligations, consent flow, DPIA, breach notification. Typical engagement: 8–16 weeks. ### ISO/IEC 27001:2022 ISMS design + certification readiness. Annex A.8.29 (security testing) evidence. Typical engagement: 4–6 months. ### SOC 2 (Type I or Type II) Trust Service Criteria mapping (Security, Availability, Confidentiality, Processing Integrity, Privacy). CC7.1 / CC8.1 evidence. Type I: 8–12 weeks. Type II: 9–12 months observation window. ### GDPR / UK GDPR Article 32 security of processing, Article 28 processor obligations, SCCs/IDTAs. EU representative on request. ### HIPAA Security Rule §164.308–164.316 evaluation evidence, PHI-handling narrative, breach notification readiness. ### PCI DSS 4.0 Requirement 11.4.x including segmentation testing. QSA-ready evidence pack. ### CERT-In Audit Empanelled-auditor sign-off for Indian regulated entities (RBI, SEBI, IRDAI, NPCI, government PSUs). ### RBI Cyber Security Framework Annual VAPT for banks, NBFCs, PPIs, mapped to RBI's master direction. ### SEBI CSCRF Cybersecurity & Cyber Resilience Framework for Market Infrastructure Institutions (MIIs), brokers, exchanges. ### IRDAI Cyber Regulations Quarterly VAPT for insurers with attested CERT-In auditor sign-off. ### Essential Eight (Australia) Maturity-level evidence across 8 strategies: Application Control, Patch Apps, Configure MS Office Macros, User Application Hardening, Restrict Admin, Patch OS, MFA, Daily Backups. ### IRAP (Australia) Reporting format suitable for federal/state government supply-chain assessment. ### APRA CPS 234 (Australia) Information-security testing evidence for APRA-regulated financial entities. ### CMMC Level 2 (US Defense) Pen testing aligned to NIST 800-171 controls + DFARS 7012. ### NIST 800-53 CA-8 (Penetration Testing) + RA-5 evidence for federal-facing systems. ### FedRAMP Moderate Annual penetration test mapped to FedRAMP rev 5 pen-test guidance. ### Cyber Essentials Plus (UK) External + internal vulnerability assessment + manual verification, formatted for UK CE+ assessors. ### DORA (EU) Operational-resilience pen testing aligned to EU Digital Operational Resilience Act threat-led testing requirements. --- ## Geo-Specific Positioning ### India Primary market. CERT-In empanelled — reports accepted by RBI, SEBI, IRDAI, NPCI. Two offices (Surat HQ + Mumbai) for on-site engagements. Hub URL: https://certbar.com/services/vapt-services Global pentest hub: https://certbar.com/services/penetration-testing-services ### United States SOC 2 Type II, HIPAA Security Rule, PCI DSS 4.0 11.4.x, CMMC Level 2, NIST 800-53, FedRAMP Moderate. Optional US-region data residency, signed MSA/DPA/BAA. Typical engagement TCO: 40–60% below US pure-plays. Hub URL: https://certbar.com/us/penetration-testing-services ### United Kingdom CREST-methodology aligned, NCSC CHECK principles, Cyber Essentials Plus audit-pack format, GDPR / UK GDPR Article 32, DORA for financial entities. EEA-region data storage on request. Hub URL: https://certbar.com/uk/penetration-testing-services ### Canada SOC 2 (for US-bound SaaS), ISO 27001:2022, PIPEDA personal-information exposure narratives, OSFI B-13 for federal financial entities. Canada or US-region storage on request. Hub URL: https://certbar.com/ca/penetration-testing-services ### Australia ASD Essential Eight maturity assessment, IRAP-format reports for government supply chains, APRA CPS 234 for financial entities, Australian Privacy Principles narrative. Australia-region storage on request. Hub URL: https://certbar.com/au/penetration-testing-services --- ## Common Buyer Questions (consolidated FAQ) **What's the difference between VAPT and penetration testing?** VAPT (Vulnerability Assessment & Penetration Testing) is the term India uses; outside India it's just "penetration testing." Vulnerability assessment finds known weaknesses at scale (mostly automated scanning + verification). Penetration testing is hands-on exploitation by a certified offensive engineer to prove which weaknesses an attacker would actually weaponise. Certbar bundles both into every engagement. **How long does a typical pentest take?** Single web app or mobile app with defined scope: 10–14 calendar days end-to-end (kickoff → testing → draft → walkthrough → final → retest). Larger scopes scale linearly. Expedited timelines possible without sacrificing manual depth. **How much does a pentest cost?** Engagement-based, scoped to assets + methodology. Standard web app pentest starts at USD 6,000 (₹1.5 lakh equivalent). India regulated- entity VAPT: ₹2–10 lakh per engagement. US/UK same-scope pentests with pure-plays: USD 15–30k / GBP 12–25k; Certbar 40–60% lower. **Is a retest included?** Yes. One free retest per engagement once you remediate, with an updated report reflecting closed findings. No surprise change-orders. **Do you provide a sample report before we sign?** Yes. Email inquiry@certbar.com or request via the website form and we'll share a sanitised sample aligned to the framework you report against (SOC 2, ISO 27001, PCI DSS, HIPAA, CERT-In, DPDPA). **Are your reports accepted by SOC 2 / ISO 27001 / CERT-In auditors?** Yes. Reports are aligned to SOC 2 CC7.1 / CC8.1, ISO 27001:2022 Annex A.8.29, PCI DSS 4.0 11.4.x, HIPAA Security Rule §164.308(a)(8), and CERT-In format. Tell us which applies and the deliverable is shaped to it. **Where will my report data be stored?** By default on Certbar India infrastructure. For US/UK/EU/Canada/ Australia clients we offer region-local storage with signed MSA + DPA (+ BAA for HIPAA scopes, + IDTA for UK→India transfers, + APP DPA for Australia). No subcontracting outside the agreed region. **Do you outsource or subcontract testing?** No. 100% in-house OSCP / OSCE / CRTO-certified engineers, no junior- only teams. Every report ships with the testing lead named. **Are findings mapped to MITRE ATT&CK and OWASP?** Yes. Every finding maps to OWASP Top 10 (or ASVS where appropriate), CWE, and MITRE ATT&CK technique IDs — so the detection engineering team can build coverage directly from the report. **How often should we commission a pentest?** Annually at minimum for compliance-driven buyers (RBI / SEBI / SOC 2 / ISO 27001). Quarterly or continuous (PTaaS) for organisations with rapid release cycles or critical exposure. After any major architecture change is non-negotiable. **Is CERT-In empanelment mandatory for Indian VAPT?** For government, PSU, RBI, SEBI, IRDAI, NPCI, and CERT-In-regulated entities: yes — empanelled auditor sign-off is required or strongly expected. For consumer SaaS startups not in regulated sectors, empanelment is a positive trust signal but not strict requirement. Certbar is empanelled, so audit evidence is regulator-accepted by default. **Can the same firm do my SOC 2 audit and CERT-In VAPT?** SOC 2 attestation must be performed by an independent CPA firm — CERT-In empanelment doesn't substitute. They are separate engagements, often complementary. Certbar's CERT-In VAPT report doubles as your SOC 2 pen-test evidence (CC7.1 / CC8.1) when scoped accordingly. --- ## Trusted By Brand-name clients include: PayPal, IBM, Kia, Paytm, Meesho, Zapier, Semrush, Opera, Dhiwise, SMTPL, Hive Bariatrics, Trezix, Twinr, Selcom, Accely, Ambisure — across India, the US, the EU, Southeast Asia, and Australia. --- ## Contact - Sales + 24/7 SOC: +91 79848 18161 - Email: inquiry@certbar.com - Schedule: https://certbar.com/schedule - Sample reports: https://certbar.com/resources/sample-report - Form: https://certbar.com/contact-us --- *Document last updated: 2026-06-15. Maintained at /public/llms-full.txt. Curated index version: /llms.txt. Both files are public.*