DebugSol

Buyer's guide · 2026

The pentest buyer's guide for Indian SaaS.

If you're buying a penetration test in India in 2026, expect to pay roughly ₹40,000 to ₹2.5 lakh for a human-led web-app test, get a report in 1–2 weeks, and insist on a certified human tester, a retest, and an attestation letter your customers will accept. This guide explains what you're actually buying, what fair prices look like from vendors' public pages, what auditors expect, how to scope the work, and the questions that separate a real test from a dressed-up scan.

Written for founders and engineering leads at startups and SaaS companies. No jargon, no fear-selling.

First, the basics

A pentest is not a scan.

A vulnerability scan is an automated tool that lists things that might be wrong — fast, broad, and full of false positives. A penetration test is a certified human who confirms what is actually exploitable, chains issues together the way an attacker would, and proves each finding with masked evidence. Scanners miss the bugs that matter most to SaaS: broken access control, authorisation flaws (IDOR), and business-logic abuse — because judging those needs a human who understands your app.

Sample finding — from a deliberately vulnerable practice app (OWASP Juice Shop)

Broken access control (IDOR) — High

A logged-in user could read another customer's shopping basket by changing the numeric id in the request GET /rest/basket/{id}. The server returned the other user's items without checking ownership. A scanner reports the endpoint exists; only a human testing as two different users discovers that one can read the other's data.

Fix: enforce an ownership check on every object lookup — the logged-in user's id must match the resource's owner. Note: this is a sample from a practice app, never real client data.

See a full redacted sample report →

What it costs

India price bands, in the open.

Most Indian vendors don't publish prices at all — you have to "contact sales." The figures below are the ones that are public, next to our own fixed prices. Published prices are deliberately our edge: you can budget before you talk to us.

ServiceTypical India market (public pages)DebugSol (fixed, public)
Light / external checkAstra Scanner plan ₹1,67,000/yr (continuous scan)Launch Check — ₹29,999 ($499), 5 days
Web app pentest (manual)₹40,000–2,50,000 per app (India range)Startup Pentest — ₹74,999 ($2,499), 7 days
Web + API + cloud (SaaS)Astra Enterprise ₹6,65,000/yr; infra ₹3,80,000–5,50,000SaaS Assurance — ₹1,99,999 ($8,999), 15 days
Compliance / retainerQuote-only at most vendorsFixed quote from a short scoping form

Market figures from vendors' public pages (Astra Security), as of October 2026; prices change — treat them as bands, not quotes. Sources: getastra.com VAPT pricing.

Compliance

What auditors actually expect.

No framework names "penetration testing" as a hard legal requirement — but in practice, auditors and enterprise customers ask for a recent human-led test as evidence that your controls work. Here's the commonly-expected picture for Indian SaaS:

These compliance points were checked against the primary Act, Rules and standards referenced above as of October 2026; frameworks and enforcement dates can change. Nothing here is legal advice.

Get it right

A scoping checklist.

Good scope is what makes a fixed price possible and the result useful. Before you sign, pin down:

  1. 01Roles: list every user role (admin, member, read-only, API client) — authorisation is tested as each one.
  2. 02Endpoints: the app's pages plus every API route, including internal and mobile-backend APIs.
  3. 03Environments: a stable staging mirror of production, with seed data and test accounts per role.
  4. 04Retest rounds: how many re-checks after you fix are included, and for how long.
  5. 05Who tests: a named, certified human tester — not only an automated scanner.
  6. 06Evidence: masked request/response proof per finding, and a retest certificate.
  7. 07Timeline: a fixed delivery date, and how critical findings are escalated mid-test.

Use our full SaaS security checklist →

Before you sign

Ten questions for any vendor.

  1. 01Is the price fixed and published, or quote-only? What changes it?
  2. 02Is a certified human testing, or is it mostly an automated scan?
  3. 03Which standards do you follow — OWASP WSTG, API Top 10, MASTG, PTES?
  4. 04Do you test authorisation as every role (IDOR, privilege escalation)?
  5. 05How many retests are included, and for how long after delivery?
  6. 06Will I get an attestation letter my customers and auditors accept?
  7. 07Can you map findings to SOC 2 / ISO 27001 / DPDP if I need it?
  8. 08How do you handle a critical finding found mid-engagement?
  9. 09Can I see a redacted sample report before I sign?
  10. 10What exactly is in scope, and what happens if scope grows?

Questions

FAQ

How long does a pentest take?+

For a typical SaaS web app and its API, a focused engagement runs about 5–15 business days depending on scope. Our fixed packages deliver in 5, 7 and 15 business days.

Pentest or vulnerability scan — which do auditors want?+

A scan is automated breadth; a pentest is a human confirming real, exploitable issues with proof. Auditors and enterprise buyers generally want evidence of a human-led test, not only a scanner report.

Will a pentest make us DPDP / SOC 2 / ISO 27001 compliant?+

No single test makes you compliant. A pentest is one commonly-expected piece of evidence that your security safeguards work; the rest is policy, process and controls.

Do you need production access?+

No. We test a staging mirror with seed data and per-role test accounts, so there is no risk to live customer data.

Start with a free exposure snapshot.

One domain, passive public checks, results on screen. No login.