RedForge / Pricing

Fixed scope, fixed price.

You know what an engagement costs before it starts, and the number does not move because we found more than we expected. Start with the free attack-surface report if you want to see what you already expose before spending anything.

Engagement Price Time Best for
Attack-surface report Free 2 days Seeing what you already expose, before you spend anything
External assessment ₹30,000 5 days Early-stage products, or a first look at your exposure
Web & API assessment ₹65,000 8 days Anyone holding customer accounts and personal data
Web, API & mobile ₹1,10,000 12 days Products with an Android or iOS build
DPDP readiness assessment ₹85,000 10 days Evidence for §8(4) safeguards ahead of 13 May 2027
ISO 27001 / SOC 2 technical readiness ₹70,000 8 days The technical evidence your auditor will ask you for
Pipeline retainer ₹20,000/qtr ongoing Teams shipping weekly who want every push checked
Assurance retainer ₹30,000/qtr ongoing Anyone who has to re-prove security to a customer each quarter
Pipeline + Assurance ₹40,000/qtr ongoing Both, at a fifth off buying them separately

Prices in Indian rupees, exclusive of applicable taxes. Larger or multi-application scopes are quoted individually — we tell you before you commit rather than after. These sit inside the band published in Indian VAPT price guides for 2026, which put a basic application test around ₹25,000–30,000 and a comprehensive manual one at ₹50,000–75,000.

The free tier

The attack-surface report costs nothing because it never touches you.

Our first engine reads only public sources. It is the same reconnaissance an attacker does before they pick a target, and because none of it reaches your systems, we can run it before there is a contract, an authorization letter, or a conversation about price.

What it reads

Public DNS, certificate transparency logs, archived copies of your site, search-engine exposure, public code repositories, and the SaaS tenants registered to your domain. All of it is already published.

What it usually finds

Subdomains nobody remembers owning, staging environments answering on the public internet, expired or mis-issued certificates, and credentials or internal documents committed to a repository years ago.

What you get

A written report of the surface, with each item's public source so you can confirm it yourself, and the coverage table saying what we reached and what we did not.

What it is not

It is not a penetration test. Passive reconnaissance can tell you what is exposed; it cannot tell you whether the login on that staging box can be bypassed. Answering that is the paid work, and we will say so rather than let a free report read as a clean bill of health.

In every engagement

What the price includes.

The same deliverables regardless of which tier you buy. The difference between tiers is scope, not thoroughness.

The full technical report

Every finding with the reproducible request that proves it and the fix, plus the coverage table stating what each module actually reached — including anything it did not.

Letter of attestation

One page, signed, forwardable to your customer. Scope, method, testing window, findings by severity and retest status. This is usually what unblocks a deal.

A free retest

Once you have patched, we re-run the engagement so the attestation reflects the fixed state rather than the day we started. Included, not an add-on.

Control mapping and SARIF

Findings mapped to ISO/IEC 27001:2022, SOC 2 and DPDP 2023, plus SARIF so they land in your GitHub Security tab and close themselves when they stop reproducing.

Control mapping is not an accredited audit. If you need an ISO 27001 certificate or a SOC 2 report for a customer or an investor, you need an accredited auditor. What we provide is the evidence that auditor will ask you for — and we will tell you plainly where the line is rather than let you assume it covers more than it does.

Staying tested

Two retainers, because two different people buy them.

An engineering lead wants every push checked. A founder wants something they can send a customer. They are different jobs, so they are priced separately — and cheaper together.

Pipeline — ₹20,000/quarter

RedForge runs inside your CI as a container. Scans on push and on a schedule, findings go to your GitHub Security tab, and the build fails only on findings we actually proved.

Passive by default — read only, no writes or state changes, because a CI job runs unattended against staging that often shares a database with production · automated triage only · access is a per-client token we can revoke

Assurance — ₹30,000/quarter

One full re-scan per quarter at the scope of your original engagement, a diff against last quarter so you can see what moved, and a fresh signed attestation letter.

Same scope as the engagement it follows — new applications or new surface are quoted separately · includes human review of what the scan found

What the Pipeline tier does not include. A person reading your findings. At ₹20,000 a quarter it is automation: proven findings land in your Security tab with the evidence attached, and unproven leads sit alongside them marked as unproven. If you want someone to work through them with your engineers, that is the Assurance tier. We would rather say this now than have you discover it in month two.

Both retainers bill quarterly. Paid annually, Pipeline + Assurance is ₹1,36,000 rather than ₹1,60,000. Continuous scanning runs on a standing written authorisation covering the period, not a per-engagement one — and where your application runs on a vendor’s infrastructure, the party who can authorise testing is usually them rather than you. We check that before the first scan, not after.

Not sure which tier fits?

Send us your scope — number of applications, tech stack, whether there is a mobile build, and any compliance deadline you are working to. We will tell you which one you need, including if the answer is the free one.

Send us your scope