One app
₹75,000 $1,000 outside India
- One web application and its API
- Up to 2 user roles
- One environment
For teams that need a third-party test: evidence for SOC 2 or ISO 27001, a customer's security review, or a launch. The price is on this page, and the scope is agreed in writing before a single request reaches your systems.
₹75,000 $1,000 outside India
₹1,10,000 $1,400 outside India
₹1,50,000 $1,800 outside India
Source code review is available on its own or alongside a test, and is quoted once we have seen the repository.
By hand, with authorization testing at the core: one account reaching another account's data, and a role reaching an action it should not. The tooling is our own platform, Crossfyre, and nothing goes in the report that we have not reproduced.
We test Android apps that resist interception, including certificate-pinned builds and Flutter apps.
The Clickswave Labs security testing team, led by Dikshant Chandel (LinkedIn). His published work includes, in Gitea: CVE-2026-104633, sole reporter; CVE-2026-104626, Critical, one of three credited reporters. Advisories published by OpenProject and SiYuan. A remote code execution reported to a Government of India entity and acknowledged by NCIIPC, which helped prevent the exposure of about 190 GB of data. The full record, including what is still with maintainers, is at crossfyre.io/disclosures.
PCI SSC's penetration testing guidance (an information supplement from September 2017, not the standard itself) says that "penetration testing is essentially a manual endeavor" and that "simply running an automated tool does not satisfy the penetration testing requirement." We are organizationally independent of the systems we test.
Email [email protected] with four lines: the URL, the number of user roles, the environment, and your deadline. The scope and the start date come back in writing.
Clickswave Labs Private Limited, CIN U62090GJ2024PTC157553, Gujarat, India.