# Certbar Security > CERT-In empanelled, ISO 27001:2022 certified cybersecurity consultancy. > Manual, OSCP-led penetration testing; 24/7 managed SOC; AI security; > and audit-ready compliance (DPDP, ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS). > Board-ready briefs in 4–6 weeks. 1,200+ engagements across 14+ countries. > Founded 2019. HQ Surat, India + Mumbai office. ## Company Overview Certbar Security Private Limited is a cybersecurity consultancy founded in 2019, headquartered in Surat, Gujarat, India, with a second office in Mumbai. CERT-In empanelled, ISO 27001:2022 certified, DSCI registered. Specializes in manual offensive security testing, 24/7 managed SOC, AI security, data privacy programs, and compliance for DPDP, ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, and the RBI cybersecurity framework. Serves enterprises in India, the US, UK, Canada, and Australia across fintech, healthcare, SaaS, e-commerce, and government. Every engagement ships a board-ready brief with quantified business impact, prioritized fixes, and MITRE ATT&CK technique mapping in 4 to 6 weeks. ## How Certbar Is Different - **Manual, not scanner-led.** Every finding is reproduced end-to-end by an OSCP-certified human. Zero false positives shipped. - **Board-ready in 4–6 weeks.** Critical findings disclosed mid-engagement so remediation runs in parallel with testing. - **Quantified outcomes.** Business-impact estimate (₹ or $), fix priority, and MITRE technique tag on every finding. - **CERT-In accepted.** Reports accepted for RBI, SEBI, IRDAI, CERT-In, ISO 27001, SOC 2, and PCI DSS audits. ## About - [Homepage](https://certbar.com/) — Cyber Risk Quantified. Outcomes Delivered. - [About Certbar](https://certbar.com/about-us) — Founders, methodology, certifications. - [Our Team](https://certbar.com/our-team) — OSCP / OSWE / OSEP / CISSP-certified engineers. - [Awards & Achievements](https://certbar.com/awards-and-achievements) — Recognition and certifications. - [Contact](https://certbar.com/contact-us) — Sales + 24/7 SOC. ## Services — Penetration Testing - [Penetration Testing Services](https://certbar.com/services/penetration-testing-services) — Flagship manual VAPT hub across web, mobile, network, API, cloud, IoT. CERT-In empanelled reports. - [VAPT Services](https://certbar.com/services/vapt-services) — India-focused Vulnerability Assessment & Penetration Testing for RBI / SEBI / IRDAI / CERT-In compliance. - [Penetration Testing](https://certbar.com/services/penetration-testing) — Manual VAPT across web, mobile, network, API, cloud, IoT. - [Web Application Pentest](https://certbar.com/services/web-application-penetration-testing) — OWASP Top 10 + business-logic + auth-chain testing. - [Mobile Application Pentest](https://certbar.com/services/mobile-application-penetration-testing) — iOS + Android static, dynamic, runtime tampering. - [Network Pentest](https://certbar.com/services/network-penetration-testing) — Internal + external network assessment. - [API Pentest](https://certbar.com/services/api-penetration-testing) — REST + GraphQL + gRPC, OWASP API Top 10. - [AWS Pentest](https://certbar.com/services/aws-penetration-service) — IAM, S3, Lambda, ECS/EKS, VPC. - [Azure Pentest](https://certbar.com/services/azure-penetration-testing) — Entra ID, Storage, AKS, Key Vault. - [GCP Pentest](https://certbar.com/services/google-cloud-platform-penetration-testing) — IAM, GKE, Cloud Functions, Secret Manager. - [Active Directory Pentest](https://certbar.com/services/active-directory-penetration-testing) — Kerberoasting, lateral movement. - [IoT Pentest](https://certbar.com/services/iot-device-penetration-testing) — Firmware, hardware, RF, companion app. - [Thick Client Pentest](https://certbar.com/services/thick-client-penetration-testing) — Reverse engineering + traffic interception. - [Secure Code Review](https://certbar.com/services/secure-code-review) — Manual + SAST across major languages. ## Services — Red Team - [Attack Simulation / Red Team](https://certbar.com/services/attack-simulation) — MITRE ATT&CK-mapped adversary emulation across phishing, physical, network, application surfaces. ## Services — Managed Security - [24/7 SOC Monitoring](https://certbar.com/services/soc-monitoring-24-7) — Detection, triage, escalation. Sub-hour MTTR on critical alerts. - [Vulnerability Management](https://certbar.com/services/vulnerability-management) — Continuous scanning + prioritization + retest. - [Attack Surface Management](https://certbar.com/services/attack-surface-management) — External asset + shadow-IT discovery. - [Incident Response Drills](https://certbar.com/services/incident-response-drills) — Tabletop + live-fire IR exercises. ## Services — AI + Privacy - [AI Model Security](https://certbar.com/services/ai-model-security) — LLM red teaming, prompt injection, RAG security, model deployment review. - [Data Privacy](https://certbar.com/services/data-privacy-program) — DPDP / GDPR / HIPAA programs, DPO-as-a-service, DPIA. ## Services — Compliance - [DPDP Act 2023](https://certbar.com/services/dpdp-act-2023-compliance-consulting) — Indian data-protection readiness, 8–16 weeks. - [ISO 27001:2022](https://certbar.com/services/iso-27001-2022-consulting) — ISMS design + certification readiness, 4–6 months. - [SOC 2](https://certbar.com/services/soc-2-compliance-consulting) — Type I (8–12 wks) or Type II (9–12 months). - [GDPR](https://certbar.com/services/gdpr-compliance-consulting) — EU data-protection program design. - [HIPAA](https://certbar.com/services/hippa-compliance-consulting) — US healthcare data security + breach notification. - [PCI DSS](https://certbar.com/services/pci-compliance-consulting) — Card-data environment scoping + QSA-ready evidence. ## Industries - [Healthcare](https://certbar.com/industries/healthcare) — HIPAA + PHI for hospitals, telehealth, digital-health SaaS. - [Fintech](https://certbar.com/industries/fintech) — RBI + PCI + DPDP for banks, NBFCs, payment platforms. - [SaaS](https://certbar.com/industries/saas) — SOC 2 + ISO 27001 + recurring pentest for B2B SaaS. - [Manufacturing](https://certbar.com/industries/manufacturing) — OT/IT security + IoT + supply-chain. ## Resources - [Sample Reports](https://certbar.com/resources/sample-report) — Redacted board-ready briefs. - [Case Studies](https://certbar.com/resources/case-study) — Client wins with quantified outcomes. - [Leadership Insights](https://certbar.com/blog/leadership) — Board-level cybersecurity strategy. - [Technical Blogs](https://certbar.com/blog/technical) — Engineer-level CVE writeups and methodology. - [How to Verify a CERT-In Empanelled Auditor (2026)](https://certbar.com/blog/leadership/cert-in-empanelled-auditor-verification-guide-2026) — Step-by-step verification + red flags in vendor claims. - [SEC Cyber Disclosure 4-Day Rule — CISO Guide (2026)](https://certbar.com/blog/leadership/usa-sec-cyber-disclosure-4-day-rule-ciso-guide-2026) — Item 1.05 materiality trigger + board-ready playbook. ## Common Buyer Questions **What is the difference between VAPT and Red Team?** VAPT is scoped, time-bounded, and finds vulnerabilities in a defined target. Red Team is multi-vector adversary emulation that tests detection, response, and people across phishing, physical, network, and application surfaces. **How much does a pentest cost in India?** ₹1.5 lakh (small web-app, 5 days) to ₹15 lakh+ (enterprise red team with multi-cloud and network coverage). Fixed-scope quote within 24 hours of a discovery call. **How long does a pentest take?** 5–10 working days of active testing. End-to-end (scope to brief + retest) is 4–6 weeks. Enterprise scope runs 6–12 weeks. **Are Certbar reports accepted for compliance audits?** Yes. CERT-In empanelled. Accepted for RBI, SEBI, IRDAI, ISO 27001:2022, SOC 2 Type I and II, and PCI DSS v4.0 audits. **Does Certbar serve clients outside India?** Yes. India, US, UK, Canada, Australia. 14+ countries to date. Billed in INR, USD, or GBP at client preference. ## Key Facts - Founded: 2019 - HQ: Surat, Gujarat, India (+ Mumbai office) - Empanelment: CERT-In - Certifications: ISO 27001:2022, DSCI Registered - Team credentials: OSCP, OSWE, OSEP, CISSP, CISA, eJPT, AWS Security Specialty - Engagements: 1,200+ - Countries served: 14+ - Engagement turnaround: 4–6 weeks - Phone: +91 79848 18161 - Email: inquiry@certbar.com ## Contact - [Schedule a Discovery Call](https://certbar.com/schedule) — 30-min scoping call. - [Contact Form](https://certbar.com/contact-us) ## Optional - [Privacy Policy](https://certbar.com/privacy-policy) - [Terms of Use](https://certbar.com/terms-of-use)