Blog

DPDP compliance and offensive security, explained.

Practical guidance from the team that runs the engagements — no filler, no vendor-speak.

DPDPCompliance

DPDP Rules 2025 Are Notified: Your New Compliance Timeline

The DPDP Rules were notified on November 13, 2025, turning the 2023 Act into an enforceable timeline. Here's what changed and what's due when.

17 Aug 2026 · 6 min read
VAPTCERT-In

CERT-In Empanelment Explained: What to Actually Check Before You Hire a VAPT Vendor

"CERT-In empanelled" gets used loosely in vendor pitches. Here's what the term actually means, which categories exist, and how to verify a claim in under five minutes.

12 Aug 2026 · 6 min read
VAPTFintech

RBI & SEBI Cybersecurity Rules: What VAPT Indian Fintechs Actually Need

Payment aggregators, NBFCs, and SEBI-regulated entities each face different testing obligations. Here's what applies to your fintech and how often it's due.

6 Aug 2026 · 7 min read
Breach ProtectionAccount Security

Credential Stuffing Is the #1 Breach Vector — Here's What Actually Stops It

Billions of stolen credentials are tested against business logins every month. Strong passwords alone don't help when the password was never yours to begin with.

1 Aug 2026 · 5 min read
VAPTFor Founders

How to Read a VAPT Report: A Guide for Non-Technical Founders

CVSS scores, severity bands, reproduction steps — a plain-English walkthrough of what a pentest report actually says, and the red flags that mean it's a weak one.

29 Jul 2026 · 8 min read
VAPTMethodology

Why Automated Scanners Aren't Enough for a Real Penetration Test

Scanners are good at what they're good at. Business logic abuse, chained exploits, and auth flaws aren't on that list — here's why manual testing still matters.

21 Jul 2026 · 6 min read
DPDPCompliance

DPDP Act, 2023: A Practical Compliance Checklist for Indian Businesses

Ten concrete things to check on your own site and processes before an auditor — or a data principal's complaint — finds them first.

14 Jul 2026 · 7 min read