CERT-In empanelled · Bengaluru, India

Security testing and DPDP Act readiness for companies that hold Indian users' data.

CyberCombat.ai runs offensive security engagements and builds the compliance backbone Indian data fiduciaries need under the Digital Personal Data Protection Act, 2023 — from VAPT to breach-notification playbooks, delivered by a team that has sat across the table from the Data Protection Board.

No spam, no sales deck bombardment — a 30-minute call with the engineer who'd actually run your engagement.

120+VAPT & audit engagements delivered since 2021
<72 hrsaverage incident response mobilisation SLA
38data fiduciaries taken through DPDP gap closure
THREAT MONITOR 3 active engagements 0 unresolved criticals

BUILT FOR INDIAN DATA FIDUCIARIES IN

Fintech & NBFC Healthtech D2C & Marketplaces SaaS & B2B Platforms Insurtech EdTech
What we do

Offensive security and regulatory readiness, under one roof

Most Indian security vendors do one or the other — pentesting shops that don't understand the DPDP Act, or law firms that can't touch your infrastructure. We do both, with the same team end to end.

VAPT — Web, Mobile, API & Cloud

Manual-led penetration testing against OWASP Top 10, OWASP ASVS and MASVS baselines, mapped to real exploitability rather than scanner noise.

  • Web & mobile app pentesting (Android/iOS)
  • API & microservice security review
  • AWS / GCP / Azure cloud configuration audit
  • Retest included in every engagement

DPDP Act Compliance Advisory

Gap assessments and remediation roadmaps against the Digital Personal Data Protection Act, 2023 — built for how your product actually collects and processes data.

  • Data mapping & Data Principal rights readiness
  • Consent architecture & notice review
  • Significant Data Fiduciary (SDF) obligation review
  • DPO-as-a-Service retainer

Managed Detection & Response

A right-sized SOC for teams that can't justify a 24x7 in-house function yet — log ingestion, triage and escalation on call.

  • SIEM setup on your existing stack
  • 24x7 alert triage with defined SLAs
  • Monthly threat & posture reporting

Incident Response & Breach Readiness

Retainer-based IR so the first hour after a breach isn't spent looking for a phone number — plus the DPDP-aligned notification playbook to go with it.

  • Forensics, containment & root-cause analysis
  • Data Protection Board & CERT-In notification support
  • Tabletop breach simulations

Red Team & Adversary Simulation

Goal-oriented engagements that test people, process and detection — not just whether a box has an unpatched CVE.

  • Phishing & social engineering simulations
  • Physical & badge-access testing
  • Purple-team detection tuning

Security Audits & ISO 27001 Readiness

Structured audits for teams heading into an enterprise sales cycle, a funding round, or their first ISO 27001 / SOC 2 certification.

  • ISO 27001:2022 gap assessment
  • Vendor & third-party risk review
  • Policy & SOP documentation
Digital Personal Data Protection Act, 2023

DPDP compliance isn't a policy PDF. It's an engineering problem.

The DPDP Act gives every Indian "Data Principal" enforceable rights over their personal data, and puts binding obligations on every "Data Fiduciary" that collects it — with penalties running up to ₹250 crore per instance for failure to implement reasonable security safeguards. Most of those obligations live in your codebase, not your legal drawer.

01

Consent has to be verifiable, not implied

Consent must be free, specific, informed and revocable via clear affirmative action — pre-ticked boxes and buried checkboxes in your onboarding flow are exactly what we look for in an audit.

02

Breach notification is time-bound

A personal data breach must be reported to the Data Protection Board of India and to affected Data Principals, without delay — which means your detection and escalation pipeline has to be fast enough to make that deadline real.

03

Significant Data Fiduciaries carry extra weight

If the Central Government notifies you as an SDF based on data volume or sensitivity, you'll need a resident Data Protection Officer, an independent data auditor and periodic Data Protection Impact Assessments.

04

Children's data needs verifiable parental consent

Processing data of users under 18 requires verifiable parental consent, and bars behavioural tracking or targeted advertising directed at children outright.

05

Data Principal rights need real infrastructure

Access, correction, erasure and grievance redressal requests need a working intake and fulfilment process — not a mailbox nobody checks.

60-second DPDP exposure check

Answer three questions. This is a directional read, not legal advice — we'll go deeper on the call.

Answer the questions above to see your indicative exposure level.
Get a full gap assessment
How engagements run

Five stages, one point of contact throughout

No handoffs between a "sales engineer" and the person doing the work — the analyst on your scoping call is the one testing your systems.

01

Scope & threat model

We map your assets, data flows and prior incidents to build a scope that reflects real risk, not a generic checklist. Includes a lightweight DPDP applicability read.

02

Testing & assessment

Manual-led testing against your applications, infra and, where relevant, your people — supplemented by tooling, never replaced by it.

03

DPDP gap analysis

Findings are cross-mapped to consent, breach-notification and Data Principal-rights obligations so legal and engineering are reading the same document.

04

Remediation & retest

Fix guidance written for your stack, office hours with engineers while you patch, and a full retest included in scope — not billed separately.

05

Continuous monitoring

For retainer clients: ongoing MDR, quarterly re-testing cadence and DPO-as-a-Service support as your product and data footprint evolve.

Why teams pick us

Built for how Indian regulation and infrastructure actually intersect

CERT-In empanelled auditors

Reports formatted the way regulators and enterprise procurement teams expect to see them.

Security and DPDP under one contract

No coordination tax between a pentest vendor and a separate compliance consultant.

Senior-led, fixed fee

Every engagement is scoped and led by someone with 6+ years in offensive security — quoted upfront, no surprise change orders.

India-based delivery & data residency

Findings, PII and test artefacts stay on infrastructure located in India throughout the engagement.

0Findings closed on first retest, avg.
0Days average DPDP gap-closure sprint
0Repeat / retainer clients
0Critical findings caught pre-launch (2025)
Recent engagements

A few problems we've actually solved

Anonymised at client request — sector and outcome details are accurate.

NBFC · Lending

Consent flow rebuilt ahead of an RBI-linked audit

A Mumbai-based digital lending NBFC needed its loan-origination consent flow rebuilt to capture purpose-specific, revocable consent before a co-lending partner's compliance review.

18 daysGap to fix
4Consent flows redesigned
Healthtech · Diagnostics

Critical API flaw found before a hospital-chain rollout

A diagnostics platform's patient-report API was found to leak reports across account boundaries via a predictable object ID — fixed and retested inside one sprint, before go-live with a hospital chain.

1Critical (IDOR)
72 hrsTime to fix confirmed
D2C · E-commerce

Breach playbook built after a near-miss

Following a third-party logistics vendor's data exposure, we built the client's first formal breach-notification playbook and ran a tabletop exercise with leadership and engineering.

1Tabletop simulation run
12Vendors risk-reviewed
What clients say

From the people who sat through the retest

"They found things our previous vendor's automated scan missed entirely — and explained the DPDP angle in terms our product team could actually act on."

CT
CTOSeries B fintech, Bengaluru

"The gap assessment gave us a prioritised list instead of a 90-page report nobody reads. We closed the top risks in three weeks."

DP
Data Protection LeadHealthtech platform, Pune

"Our board wanted proof of a real breach-response process, not a policy document. The tabletop session with CyberCombat gave us exactly that."

HS
Head of SecurityD2C marketplace, Gurugram
Engagement models

Pricing that scales with your stage, not our margins

Indicative starting price for a well-scoped engagement. Every quote is fixed-fee once scope is confirmed on the call.

DPDP Gap Assessment

For teams that need to know where they stand before building a roadmap.

₹1.5L onwards
One-time · 2–3 week turnaround
  • Data flow & consent mapping
  • SDF applicability review
  • Prioritised remediation roadmap
  • Leadership readout session
Start here

Managed Security Retainer

For teams that want ongoing coverage, not a once-a-year fire drill.

₹1.25L / month onwards
Quarterly minimum commitment
  • MDR / SOC coverage
  • DPO-as-a-Service
  • Quarterly retesting cadence
  • Incident response on retainer
Talk to us
Questions we get often

FAQ

Does the DPDP Act apply to my company if we're not a "tech" company?

Yes — the Act applies to any entity, digital or otherwise, that determines the purpose and means of processing personal data of individuals in India, including data collected offline and later digitised. If you have a customer database, an HR system, or a website with a contact form, it applies to you.

How is CyberCombat different from a law firm's DPDP practice?

We implement, not just advise. A law firm can tell you what a compliant consent notice should say; we rebuild the consent flow, test whether it actually captures what it claims to, and pentest the systems that store the data behind it.

We're pre-revenue. Is it too early for a DPDP assessment?

It's the cheapest time to do it. Retrofitting consent and data-retention logic after your data model is locked in and your user base has grown costs far more than designing for it from the start. Most early-stage clients start with the Gap Assessment tier.

Do you only work with companies based in India?

No — the DPDP Act applies extraterritorially to any entity processing personal data of individuals in India in connection with offering goods or services to them, regardless of where the company is incorporated. We work with several overseas clients on exactly this basis.

What happens after the retest — are we "certified"?

We issue a signed attestation report suitable for enterprise procurement and investor diligence, but there is no single government-issued "DPDP certificate" as of today. Where relevant, we also help you prepare for ISO 27001 or SOC 2, which pair well with DPDP evidence requests.

How fast can you mobilise for an active incident?

Retainer clients get a guaranteed response within 4 hours. For non-retainer engagements, our average time to first analyst contact has been under 72 hours, subject to team availability — call the incident line directly for anything in progress.

Get in touch

Tell us what you're building. We'll tell you where the risk actually is.

Every enquiry gets a reply from a human on the team within one business day — usually the analyst who'd run your engagement.

hello@cybercombat.aiGeneral & new business enquiries
+91 80 4718 2266Incident response line · 24x7 for retainer clients
HSR Layout, Bengaluru, Karnataka 560102By appointment only
CERT-IN EMPANELLED ISO 27001:2022 DPDP ACT 2023 READY

Got it.

Thanks — a member of the team will reply within one business day. For anything urgent, use the incident line above.

Send another enquiry