Penetration testing

Web, API and Android penetration test. Fixed scope, fixed price.

For teams that need a third-party test: evidence for SOC 2 or ISO 27001, a customer's security review, or a launch. The price is on this page, and the scope is agreed in writing before a single request reaches your systems.

Three fixed boxes

One app

₹75,000 $1,000 outside India

  • One web application and its API
  • Up to 2 user roles
  • One environment

More roles, or mobile

₹1,10,000 $1,400 outside India

  • Everything in One app
  • Plus up to 2 more roles, or your Android app

Web, API and Android

₹1,50,000 $1,800 outside India

  • The web application, its API and your Android app
  • Up to 4 user roles
  • One environment

Source code review is available on its own or alongside a test, and is quoted once we have seen the repository.

What you get

  • Every finding with the request and response that prove it.
  • A severity for each, and a fix your developers can act on without a call.
  • A short summary for whoever signs off.
  • A signed letter with the dates, the scope and the retest result, which an auditor can file.
  • One retest of the reported findings within 30 days of the report.

How it runs

  1. Testing starts within 10 business days of signature.
  2. Five business days of testing.
  3. The report three business days later.
  4. The retest whenever your fixes are ready, within 30 days.

How we test

By hand, with authorization testing at the core: one account reaching another account's data, and a role reaching an action it should not. The tooling is our own platform, Crossfyre, and nothing goes in the report that we have not reproduced.

We test Android apps that resist interception, including certificate-pinned builds and Flutter apps.

Who tests

The Clickswave Labs security testing team, led by Dikshant Chandel (LinkedIn). His published work includes, in Gitea: CVE-2026-104633, sole reporter; CVE-2026-104626, Critical, one of three credited reporters. Advisories published by OpenProject and SiYuan. A remote code execution reported to a Government of India entity and acknowledged by NCIIPC, which helped prevent the exposure of about 190 GB of data. The full record, including what is still with maintainers, is at crossfyre.io/disclosures.

For PCI DSS

PCI SSC's penetration testing guidance (an information supplement from September 2017, not the standard itself) says that "penetration testing is essentially a manual endeavor" and that "simply running an automated tool does not satisfy the penetration testing requirement." We are organizationally independent of the systems we test.

Terms

  • 50% on signing, before any testing, and 50% when the report is delivered.
  • Written authorization from the owner of every asset before any traffic, with the test window, our source addresses and an emergency contact.
  • A mutual NDA on request.
  • Clients in India pay by bank transfer against an invoice. Clients outside India pay by wire transfer in USD.

Not included

  • CERT-In empanelled audit certificates. We are not empanelled, so we cannot issue them.
  • iOS apps.
  • Social engineering.
  • Denial-of-service testing.

Ask for a test

Email [email protected] with four lines: the URL, the number of user roles, the environment, and your deadline. The scope and the start date come back in writing.

Clickswave Labs Private Limited, CIN U62090GJ2024PTC157553, Gujarat, India.