VAPT
VAPT · Fintech
14 Critical Vulnerabilities Found in a Fintech Payment Platform Before Launch
Client: Fintech Startup, Delhi · Duration: 5 days · Scope: Web App + API
A Delhi-based fintech startup was preparing for investor demo day. They engaged us for a VAPT 2 weeks before the event. We found 14 critical and high-severity vulnerabilities including an IDOR that exposed all customer bank account details, a broken authentication endpoint that allowed account takeover, and an API key hardcoded in frontend JavaScript.
The team patched all critical findings within a week. The demo went successfully and the investors specifically asked about their security posture — the client had our VAPT report ready.
Outcome
14 critical vulnerabilities patched before launch. Client secured Series A funding 3 months later.
OSINT Investigation
OSINT · Fraud Investigation
Investment Scammer Identified from WhatsApp Number Alone
Client: Individual, Mumbai · Duration: 4 days · Amount lost: ₹4.2L
A Mumbai professional was defrauded of ₹4.2 lakhs through a fake stock trading app on WhatsApp. The client had only a phone number and a fake name. Using OSINT techniques, we traced the phone number to a linked email address, which connected to social media profiles, an e-commerce seller account, and eventually a real address in Jaipur with photos matching the fraudster's other fake profiles.
The intelligence report was submitted to the cyber police. The case resulted in an FIR and the suspect was traced.
Outcome
Full identity profile of fraudster delivered. FIR filed. Investigation ongoing with cyber police.
Account Recovery
Instagram Recovery · Creator
Creator Account with 280K Followers Recovered After 3-Month Disable
Client: Fashion Creator, Delhi · Duration: 9 days · Followers: 280,000
A Delhi-based fashion creator's account with 280,000 followers was disabled after a coordinated mass-reporting attack by a competitor. Previous self-submitted appeals over 3 months had been rejected. We prepared a comprehensive appeal documenting the attack pattern, the creator's identity verification, business impact, and past Meta policy compliance history.
The account was reinstated on day 9. We also implemented security hardening to prevent repeat attacks.
Outcome
Account reinstated in 9 days after 3 months of failed self-appeals. 280K followers restored.
Software Security
Software + Security · Healthcare
Hospital Management System Built and Security-Audited in 8 Weeks
Client: 50-bed Hospital, Delhi NCR · Duration: 8 weeks · Tech: ASP.NET Core + React
A private hospital needed a custom HMS to replace their paper-based system. They wanted patient records, billing, OPD scheduling, pharmacy, and staff management. We built and deployed the full system in 8 weeks. Before handover, our security team ran a VAPT on the application — finding and fixing 3 medium-severity vulnerabilities including insecure direct object references and missing session invalidation on logout.
The hospital has been running on our system for 18 months with zero security incidents.
Outcome
Full HMS deployed in 8 weeks. 3 security issues fixed before go-live. 18 months of stable operation.
Digital Forensics
Digital Forensics · Corporate
Employee Data Theft Proven with Forensic Evidence — Legal Case Won
Client: IT Services Company, Noida · Duration: 7 days · Case: Employment Dispute
A Noida IT company suspected a departing employee had stolen a client list and source code before resignation. The company's lawyers needed admissible digital evidence. We imaged the employee's work laptop, recovered deleted files including email drafts with attachments sent to personal accounts, USB transfer logs, and screenshots of the client database viewed hours before resignation.
The evidence report was accepted by the civil court. The company won the case and secured an injunction preventing the former employee from sharing the stolen data.
Outcome
Forensic evidence accepted by civil court. Company won injunction. Former employee restrained from data use.