Delivered service

Find it before somebody else does.

Scoped vulnerability assessment and penetration testing across web, mobile, API, cloud and network, delivered by the FlickerBytes security team - with a report written to be fixed, not filed.

Scoped per engagementRemediation-focused reportingRetest included
The problem

A clean scan is not a tested system.

Automated scanning finds known signatures. It does not chain three low-severity findings into an account takeover, and it does not test the logic your developers wrote last quarter.

  • Scanners miss business logic. Authorisation flaws, broken access control and privilege escalation rarely show up in an automated report.
  • Reports get filed, not fixed. A 200-page tool export with no prioritisation and no reproduction steps does not change your security posture.
  • Auditors and customers want evidence. ISO 27001, SOC 2 and enterprise procurement increasingly expect independent testing, dated and scoped.
  • Fixes go unverified. A remediation nobody retested is a remediation you are hoping worked.
Capabilities

What an engagement covers.

Scope is agreed in writing before testing starts. We test what you authorise us to test, and nothing else.

Web application testing

Authenticated and unauthenticated testing for injection, access control, session handling and business-logic flaws.

Mobile application testing

Android and iOS testing covering storage, transport, platform misuse and the APIs behind the app.

API testing

Authorisation, rate limiting, object-level access and data exposure across your API surface.

Cloud configuration review

Identity, network exposure, storage permissions and logging against cloud hardening baselines.

Network testing

External and internal network testing for exposed services, weak configuration and lateral movement.

Retest and sign-off

Once you have remediated, we retest the findings and issue an updated report you can hand to an auditor.

How it works

How an engagement runs.

1
Step one

Scope and authorise

We agree targets, depth, timing and rules of engagement in writing, with named contacts on both sides.

2
Step two

Test

Manual testing supported by tooling, with anything critical reported to you immediately rather than held for the report.

3
Step three

Report

Findings prioritised by real business impact, each with reproduction steps and a concrete fix.

4
Step four

Retest and close

After your fixes, we verify and reissue, so the engagement ends with evidence rather than a to-do list.

Outcomes

What you receive.

A report your engineers can act on and your auditors accept, plus verification that the fixes held.

  • Findings ranked by exploitability and business impact
  • Reproduction steps for every finding
  • Specific remediation guidance, not generic advice
  • Immediate notification of critical findings
  • A retest and an updated report after remediation
  • An executive summary you can share with a customer or board
Frameworks

Independent testing evidence for the frameworks that ask for it.

Frameworks are what Niyam helps you operationalise. They are not separate products.

ISO 27001:2022SOC 2CERT-In 2022RBI ITGRC 2023SEBI CSCRFNIST CSF 2.0
Pricing

Quoted per engagement.

VAPT is a delivered service, not a plan feature. Pricing depends on scope, depth and the number of targets, so we quote after a short scoping conversation. There is no self-serve price and no free tier.

FAQ

Questions about VAPT.

No. It is a separate, scoped service delivered by our security team. Niyam plans cover the platform; testing is quoted per engagement.

It depends entirely on scope. A single web application is a different engagement from a cloud estate plus internal network. We give you a duration with the quote.

We agree this during scoping. Testing can run against staging, or against production under agreed constraints and timing. Rules of engagement are written down before we start.

Yes. Retest is part of the engagement, and you get an updated report reflecting the verified state.

No. We require written authorisation from the asset owner for every target in scope.

Get an assessment scoped.

Tell us what you run and we will come back with scope, duration and a quote.