Frequently asked questions
Answers to common questions about VAPT and penetration testing scope, timelines, cost drivers, confidentiality, reporting, remediation and retesting.
Scope and engagement
4 questionsWhat is the difference between VAPT, a penetration test and red teaming?
VAPT is breadth — what is exposed across the estate, validated by hand. A penetration test is depth — can a tester actually break into this specific system. Red teaming asks a different question entirely: if someone got in, would your team notice, and how fast would they act.
We have never tested anything. Where do we start?
A grey box penetration test of the application that would hurt most if it were breached. It gives the most useful information per rupee at the start, and it tells you whether a wider assessment is worth commissioning.
Can you test a system hosted by our vendor?
Only with the vendor's written authorisation, in addition to yours. Most cloud providers also have their own testing policy. We help you obtain both before scoping.
Do you test systems we do not own?
No. Written authorisation from an empowered signatory covering every asset in scope is a hard prerequisite. There is no exception to this.
Cost and timeline
3 questionsWhat drives the cost?
Tester days. The number of applications, the number of distinct user roles, whether internal network coverage is included, and how much we are told up front. A white box test costs less per unit of coverage than a black box test on the same target.
How long does an engagement take?
A single web application is typically a working week including reporting. Larger estates and red team exercises run for several weeks. You get an indicative timeline in the proposal before you commit to anything.
Is the retest charged separately?
No. A retest of the findings from the original scope is part of the engagement. Testing new functionality built after the report is a new engagement.
Reports and results
4 questionsWho is the report written for?
Both audiences, deliberately. An executive summary a non-technical reader can act on, and a technical register with reproduction steps and evidence your engineers can work from.
What happens if you find something critical?
You are told the same day, with enough detail to act immediately. It does not wait for the final document.
Can we share the report with a customer or auditor?
Yes. We also issue a letter of attestation confirming the engagement, its scope and its dates without disclosing the technical findings — usually the better document to share externally.
What if you find nothing serious?
The report says so. A quiet result on a well-built system is a legitimate outcome, and we will not manufacture severity to justify an invoice.
Confidentiality and conduct
3 questionsHow is our data protected during testing?
Least-privilege access for the shortest workable window, encrypted storage and transfer, access limited to the assigned testers, and destruction on the schedule set in the contract. Where a finding involves sensitive data, we evidence that access was possible rather than extracting the data.
Will you use us as a case study?
Only with your written consent. By default, published engagement summaries are anonymised and name no client.
Could testing take our systems down?
The rules of engagement exclude destructive testing by default and define explicit stop conditions. Any check that carries risk is agreed in advance and run in a window you choose.
Training and speaking
3 questionsCan training be delivered in Hindi?
Yes. Awareness sessions are delivered in Hindi, English or a mix, depending on the audience.
Do you run training on site?
On site or remote. Full-day formats work better in person; keynotes and leadership briefings work either way.
How do we check speaker availability?
Send the date, city, audience size and session length over WhatsApp or email and you will get an answer on availability and format.
ROOT64 / VERIFIED