VAPT & penetration testing FAQs
60 questions answered. More on VAPT & penetration testing →
What's the difference between a vulnerability scan and a real penetration test?
A vulnerability scan flags what might be wrong; a penetration test shows what an attacker could actually do with it. Bitkosh's engineers chain small misconfigurations, business-logic flaws and human error the way a real adversary would, then hand you a prioritized, developer-ready remediation plan rather than a PDF of raw scanner output.
How often should we schedule a penetration test?
At least once a year, and again after any significant change to your infrastructure or application. Regulated or high-risk environments often move to a quarterly or continuous testing cadence instead of relying on a single annual snapshot to catch new exposure as systems change.
Is it worth paying for manual testing instead of just running a scanner?
A scanner tells you what might be wrong; it cannot tell you what an attacker could actually chain together. Bitkosh's engineers use automated tools for breadth, then add manual testing to uncover business-logic flaws, chained exploits and misconfigurations that scanners miss, so the report reflects real exploitable risk rather than a raw alert list.
Do you retest our systems after we fix the findings?
Yes. One retest cycle is included with every VAPT engagement so our engineers can confirm each finding was properly remediated before you close it out. A finding is only marked closed once an engineer has verified the fix, not simply because a ticket was updated internally.
How much does a web application VAPT cost?
Standard-scope Web Application VAPT starts at ₹45,000, covering manual and automated testing of a single application along with an evidence-led report and one retest round. It is a flat starting rate for a standard scope; engagements with a larger attack surface are scoped and quoted separately.
What does mobile app penetration testing cost per platform?
Mobile App VAPT starts at ₹55,000 per platform, covering either iOS or Android with static and dynamic analysis mapped to the OWASP MASVS standard. Testing both platforms for the same app is scoped and priced per platform rather than bundled into a single flat rate.
How much do you charge for API security testing?
API Security Testing starts at ₹40,000 for standard-scope REST or GraphQL endpoint testing. It is priced as a flat starting rate, in line with Bitkosh's other productized VAPT rates, and covers the endpoints exposed by your API rather than the surrounding infrastructure.
Can you test both iOS and Android versions of our app?
Yes, mobile app testing covers both iOS and Android through static and dynamic analysis, checking for insecure data storage, API abuse and resistance to reverse engineering. Each platform is scoped and priced separately, since the codebases and attack surfaces of iOS and Android apps differ.
Do you test cloud environments like AWS or Azure?
Yes, cloud penetration testing covers AWS, Azure, GCP and Cloudflare, focused on misconfigurations, IAM privilege escalation paths and storage exposure. Bitkosh's engineers look for the kind of cloud-specific mistakes, such as an overly permissive role or an exposed storage bucket, that generic scanners often miss.
Can you assess the security of our IoT or SCADA devices?
Yes, Bitkosh performs specialized testing for IoT devices and SCADA or OT environments, along with hardware security and penetration testing. These are attack surfaces many firms are not equipped to assess, covering physical and protocol-level risks that standard web or network testing does not reach.
Is source code review included in your security testing?
Secure source code review is offered as part of Bitkosh's application security testing, alongside web, mobile, API and thick client testing. It examines your codebase directly for flaws that black-box testing alone may not surface, and is scoped as its own engagement rather than bundled into a standard web app VAPT.
Do we need separate thick client testing for our desktop app?
Yes, thick client security testing is scoped separately from web, mobile and API testing because installed desktop applications have a different attack surface than a browser-based app. Bitkosh offers it alongside secure source code review as part of application security testing, so a desktop client should be its own engagement.
What frameworks does your penetration testing follow?
Testing is mapped to the OWASP Top 10 and MITRE ATT&CK, with findings scored using CVSS so severity stays consistent and comparable across an engagement. This keeps results structured enough for a technical team to act on directly while leadership can verify progress against agreed criteria.
What do we actually receive at the end of an engagement?
You get a statement of work and scope register, technical findings with evidence and traceability, a risk-rated remediation or POA&M register, and an executive decision brief delivered through a structured close-out workshop. The package is built so technical teams can act and leadership can verify progress.
When should scoping happen relative to the actual testing?
Scoping happens first, before any testing begins. Bitkosh confirms authority to test, scope boundaries, data classification, stakeholders, critical assets and acceptance criteria as a baseline stage, so both sides agree on what is in scope and what success looks like before an engineer touches a system.
What happens if a critical vulnerability turns up mid-engagement?
Bitkosh's engineers work from an agreed, evidence-led plan that includes checkpoints and escalation paths, so a critical finding can be raised and acted on as soon as it is discovered rather than waiting for the final report. Every decision and action taken during the engagement is kept in an auditable record.
Is accessibility testing part of your security services?
Yes, Bitkosh offers WCAG 2.1 accessibility testing as part of its VAPT service line, checking that applications are usable for every visitor and not only secure against attackers. It is scoped and delivered alongside, rather than as a substitute for, the underlying security testing itself.
Who typically commissions a Bitkosh VAPT engagement?
Engagements are typically commissioned by CISOs and security leadership, IT and engineering teams, risk, compliance or procurement teams, and government or regulated program owners. The delivery process, from scoping through the close-out workshop, is structured so each of these stakeholders can act on the results directly.
Do you provide a report with proof-of-concept evidence?
Yes, every finding is reported as reproducible, with proof-of-concept evidence, a description of business impact and a prioritized remediation register your engineering team can act on. Findings are not simply listed; they include enough detail for a developer to reproduce and understand the issue before fixing it.
How do you confirm you're authorized to test our systems?
Before any testing begins, Bitkosh's scoping phase confirms authority to test along with scope boundaries, data classification, stakeholders, critical assets and acceptance criteria. This baseline step ensures everyone agrees on what is in scope, what is off-limits, and who can approve actions, so the engagement starts on a documented, mutually agreed footing rather than assumptions.
Do we get a formal scope document before testing begins?
Yes, every engagement produces a statement of work and scope register as part of the initial scoping phase. This document records the agreed boundaries, critical assets, data classification and acceptance criteria before testers start work, giving both sides a clear written reference for what was tested and what was excluded.
What happens in the close-out workshop after an engagement?
At the end of an engagement Bitkosh runs a structured close-out workshop alongside a leadership readout. It covers the technical evidence gathered, prioritized actions, and any residual-risk decisions your team needs to make, giving both technical staff and leadership a shared, verified understanding of where things stand before the engagement is formally closed.
Do you provide a POA&M or remediation tracking register?
Yes, findings are delivered as a risk-rated remediation register, often referred to as a POA&M (plan of action and milestones). It prioritizes issues by risk so your engineering team knows what to fix first, and it feeds directly into the close-out workshop and any later retest cycle.
How do you handle risks we choose not to fix immediately?
Not every finding gets remediated right away, so the close-out workshop includes residual-risk decisions where your team formally accepts or defers specific issues. This gives leadership a documented record of which risks were knowingly left open and why, rather than letting them quietly disappear after the report is delivered.
Is there an audit trail of what testers did during testing?
Yes, execution follows an agreed evidence-led plan with checkpoints, escalation paths and an auditable record of decisions and actions taken during testing. This traceability means you are not left with only a final report, you can see how testers got from scope to findings.
Can you test our internal network, not just internet-facing systems?
Yes, network testing covers internal as well as external networks, focusing on segmentation and lateral movement paths inside your environment. This shows what a compromised device or account could reach once past your perimeter, which purely external testing cannot reveal.
Is there a free consultation before we commit to an engagement?
Yes, Bitkosh offers a free 30-minute consultation with the engineering team before you commit to anything. It's meant to give you a clear, practical plan for what a VAPT engagement would look like for your systems, without any obligation to proceed.
What kind of cloud misconfigurations do you actually check for?
Cloud penetration testing across AWS, Azure, GCP and Cloudflare looks at misconfigurations, IAM privilege escalation paths and storage exposure. The goal is to find where identity and access settings or exposed storage could let an attacker escalate privileges or reach data that should not be public.
Do you test GraphQL APIs or only REST APIs?
Yes. API security testing covers both REST and GraphQL endpoints, checking for authorization flaws, rate-limit bypass and mass-assignment vulnerabilities regardless of which style your application uses. Testing is scoped to how your specific implementation handles authentication, authorization and input validation, not just a generic checklist of endpoint names.
Can testing show if our mobile app is easy to reverse engineer?
Yes, mobile app testing includes checking reverse-engineering resistance alongside static and dynamic analysis of iOS and Android builds. This tells you whether an attacker could decompile your app to extract secrets, bypass client-side checks or understand your API calls well enough to abuse them.
Do you check if our mobile app stores data insecurely?
Yes, insecure storage is one of the specific checks within mobile app testing, alongside API abuse and reverse-engineering resistance. Testers look at how the app handles data at rest on the device, whether that is credentials, tokens or sensitive user data, and whether it is exposed to other apps or a rooted device.
Do you test for authentication bypass and broken session handling?
Yes, web application testing gives full OWASP Top 10 coverage, which specifically includes authentication bypass and session handling flaws, tested manually rather than only through a scanner. This means testers check whether your login flow, tokens and session management can actually be broken, not just whether known software versions are outdated.
Can you test physical hardware devices as part of an engagement?
Yes, hardware security and penetration testing is offered alongside IoT and SCADA/OT testing, covering attack surfaces that most firms are not equipped to assess. This extends testing beyond software into the physical device layer itself, relevant for products built around embedded systems or connected hardware.
What does external network penetration testing actually check for?
External network VAPT looks at your internet-facing infrastructure for exposed services, misconfigurations and other weaknesses an attacker could reach without any internal access. It is tested manually and with automated tools together, following the same evidence-led approach used across other engagement types.
How fast can we get a VAPT proposal after contacting Bitkosh?
Bitkosh aims to turn around a scoped VAPT proposal within 48 hours of being contacted. This lets you get a concrete, priced plan quickly rather than waiting through a long back-and-forth before you even know what an engagement would look like or what it will cost.
Are vulnerabilities in our report ranked using CVSS scores?
Yes, findings are CVSS-scored with reproduction steps included, so you can see both the severity and exactly how each issue was found. This is paired with an executive summary for stakeholders who need the overall picture without reading through every technical detail in the full report.
Do you align testing with NIST and MITRE ATT&CK too?
Yes, engagements are mapped to OWASP Top 10 as well as NIST and MITRE ATT&CK, combining manual and automated testing methods. Rather than treating these as separate checklists, testers use them together to structure how vulnerabilities are found and how realistic attack paths get chained together.
Is remediation guidance written so developers can act on it?
Yes, findings come with developer-ready remediation guidance rather than just a PDF of scanner output. Each issue in the prioritized remediation register is meant to be actionable by your engineering team immediately, without needing a security specialist to translate it first before anyone can start fixing anything.
Does infrastructure testing cover more than just networking gear?
Yes, infrastructure and network testing includes network penetration testing plus broader enterprise and infrastructure security testing, alongside cloud penetration testing across AWS, Azure, GCP and Cloudflare. It is not limited to routers and firewalls, it extends to the wider infrastructure and cloud estate that supports your systems.
Do the same engineers who build systems also test them?
Yes. Every VAPT engagement is scoped, executed and reported by the same engineers who build secure systems for a living, not junior staff running a scanner. That practical build experience is what lets them recognize business-logic flaws, chained exploits and misconfigurations that a purely testing-focused team, or an automated tool, would miss during a standard assessment.
Do you work with government agencies or regulated industries?
Yes. Bitkosh's VAPT service is built for CISOs and security leadership, IT and engineering teams, risk, compliance and procurement teams, and government and regulated program owners. Engagements are structured with a formal scope register, evidence-led execution and an executive decision brief so both technical staff and program owners in regulated environments can act on the results.
Is VAPT pricing fixed, or do we always need a custom quote?
Standard-scope engagements run on flat, productized starting rates rather than a custom quote for every request. Web application, mobile and API testing each have a published starting price for standard scope, priced for the Odisha, India market rather than a global enterprise budget. Scope that goes beyond standard, such as a larger application or added environment, is quoted from that baseline.
Is the included retest round free, or is it billed as an extra?
The first retest round is included in the engagement, not billed as an add-on. Web Application VAPT, for example, bundles manual and automated testing plus one retest round into its starting price, and every engagement includes a retest cycle so an engineer confirms each finding was actually remediated before you close it out.
What does it mean when testers chain vulnerabilities together?
Chaining means combining several individually minor issues, such as a misconfiguration, a business-logic flaw and a piece of human error, into a single working attack path, the way a real adversary would. A scanner reports each weakness in isolation; Bitkosh's engineers test whether those weaknesses can be linked together to actually reach data or systems a single flaw alone would not expose.
Do you test for privilege escalation paths in our cloud IAM setup?
Yes. Cloud penetration testing covers AWS, Azure, GCP and Cloudflare environments, including IAM privilege escalation paths where a low-privilege identity or a misconfigured role and policy combination can be abused to gain higher access than intended. This is tested alongside other cloud misconfigurations and storage exposure issues as part of the same engagement.
Can testing catch API abuse issues specific to our mobile app?
Yes. Mobile App Testing covers iOS and Android through static and dynamic analysis, and API abuse is one of the specific areas assessed alongside insecure data storage and reverse-engineering resistance. This checks how the mobile client's calls to your backend can be manipulated or abused, not just how the app behaves on the device itself.
What is a mass-assignment vulnerability in API testing?
A mass-assignment vulnerability happens when an API accepts more fields in a request than it should, letting an attacker set values, such as a role or price field, that the application never intended to expose for editing. API Security Testing checks REST and GraphQL endpoints for this along with authorization flaws and rate-limit bypass issues.
Do you test whether our API's rate limiting can be bypassed?
Yes. API Security Testing checks REST and GraphQL endpoints for rate-limit bypass, alongside authorization flaws and mass-assignment vulnerabilities. This matters because rate limits are often relied on to slow down brute-force login attempts or scraping; if they can be bypassed, that protection stops working even though the limit still appears to be configured correctly.
Can an attacker move laterally once inside our network?
Yes. Network and Infrastructure testing looks at lateral movement paths as part of assessing your internal network, alongside segmentation and exposed services. The goal is to show what an attacker could reach next after gaining an initial foothold on one system, not just whether that first system can be compromised.
Do you test whether our network segmentation actually stops an attacker?
Yes. Segmentation is one of the specific things Network and Infrastructure testing checks, alongside lateral movement paths and exposed services. Segmentation is meant to contain a breach to one zone of your network; testing verifies whether that isolation actually holds or whether a compromised system in one segment can still reach systems in another.
Is mobile app testing mapped to the OWASP MASVS standard?
Yes. Mobile App VAPT is scoped and billed per platform, iOS or Android, and combines static and dynamic analysis mapped to OWASP MASVS, the mobile-focused counterpart to the OWASP Top 10 used for web application testing. Findings are reported against that standard so your team can see coverage in familiar terms.
What's the difference between static and dynamic mobile app analysis?
Static analysis examines the mobile app's code and packaged files without running it, looking for issues like insecure storage or exposed configuration. Dynamic analysis runs the app and observes its actual behavior, including how it calls backend APIs. Mobile App VAPT uses both together, mapped to OWASP MASVS, because each method catches issues the other can miss.
Do you test for SQL injection and similar injection flaws?
Yes. Web Application Testing gives full OWASP Top 10 coverage, which includes injection flaws such as SQL injection, tested manually alongside auth bypass, business-logic flaws and session handling issues. Manual testing matters here because exploitable injection points are often missed or misreported by automated scanners alone.
Does the report explain business impact, not just technical severity?
Yes. Every finding in Bitkosh's reports is reproducible and includes proof-of-concept evidence, business impact, and a place in a prioritized remediation register, not just a severity label. That business impact context is what lets your team weigh a finding against what it would actually mean for the organization, rather than reacting to a raw score alone.
Which people on our side need to join the scoping conversation?
Scoping confirms authority, scope boundaries, data classification, stakeholders, critical assets and acceptance criteria before testing begins, so the people who should join are whoever owns those areas: typically someone who can confirm authorization, the technical owner of the systems in scope, and whoever holds data classification and risk decisions for the assets being tested.
What does Enterprise and Infrastructure Security Testing actually cover?
Enterprise and Infrastructure Security Testing is one of three services under Infrastructure & Network Testing, alongside Network Penetration Testing and Cloud Penetration Testing across AWS, Azure, GCP and Cloudflare. It extends testing across your broader enterprise infrastructure rather than a single network segment or cloud account, using the same evidence-led scoping, execution and reporting process as every other engagement.
How are issues escalated to us while testing is underway?
Testing runs against an agreed, evidence-led plan that includes checkpoints and defined escalation paths, so if something needing immediate attention comes up mid-test, there is already an agreed route to raise it with your team rather than waiting for the final report. This is part of the same execution structure that also produces the leadership readout at the end.
How do you define acceptance criteria before testing starts?
Acceptance criteria are agreed during the scoping phase, before testing begins, alongside authority, scope boundaries, data classification, stakeholders and critical assets. They set out what a finding needs to look like to matter for this engagement and what counts as done for the assessment, so your team and Bitkosh's engineers work against the same definition from day one.
Do you test for broken authorization on individual API endpoints?
Yes. API Security Testing checks REST and GraphQL endpoints for authorization flaws, meaning cases where one authenticated user can access or modify data or actions belonging to another, not just whether login itself can be bypassed. This is assessed alongside rate-limit bypass and mass-assignment vulnerabilities as part of the same API engagement.
Does scoping identify which of our data and assets are critical?
Yes. The scoping step baselines data classification alongside stakeholders, critical assets and acceptance criteria before any testing begins. This tells testers which systems carry sensitive data and which ones would cause the most damage if compromised, so effort is focused where it matters and the scope register reflects real business risk, not just a list of IP addresses.