Security testing and DPDP Act readiness for companies that hold Indian users' data.
CyberCombat.ai runs offensive security engagements and builds the compliance backbone Indian data fiduciaries need under the Digital Personal Data Protection Act, 2023 — from VAPT to breach-notification playbooks, delivered by a team that has sat across the table from the Data Protection Board.
No spam, no sales deck bombardment — a 30-minute call with the engineer who'd actually run your engagement.
BUILT FOR INDIAN DATA FIDUCIARIES IN
Offensive security and regulatory readiness, under one roof
Most Indian security vendors do one or the other — pentesting shops that don't understand the DPDP Act, or law firms that can't touch your infrastructure. We do both, with the same team end to end.
VAPT — Web, Mobile, API & Cloud
Manual-led penetration testing against OWASP Top 10, OWASP ASVS and MASVS baselines, mapped to real exploitability rather than scanner noise.
- Web & mobile app pentesting (Android/iOS)
- API & microservice security review
- AWS / GCP / Azure cloud configuration audit
- Retest included in every engagement
DPDP Act Compliance Advisory
Gap assessments and remediation roadmaps against the Digital Personal Data Protection Act, 2023 — built for how your product actually collects and processes data.
- Data mapping & Data Principal rights readiness
- Consent architecture & notice review
- Significant Data Fiduciary (SDF) obligation review
- DPO-as-a-Service retainer
Managed Detection & Response
A right-sized SOC for teams that can't justify a 24x7 in-house function yet — log ingestion, triage and escalation on call.
- SIEM setup on your existing stack
- 24x7 alert triage with defined SLAs
- Monthly threat & posture reporting
Incident Response & Breach Readiness
Retainer-based IR so the first hour after a breach isn't spent looking for a phone number — plus the DPDP-aligned notification playbook to go with it.
- Forensics, containment & root-cause analysis
- Data Protection Board & CERT-In notification support
- Tabletop breach simulations
Red Team & Adversary Simulation
Goal-oriented engagements that test people, process and detection — not just whether a box has an unpatched CVE.
- Phishing & social engineering simulations
- Physical & badge-access testing
- Purple-team detection tuning
Security Audits & ISO 27001 Readiness
Structured audits for teams heading into an enterprise sales cycle, a funding round, or their first ISO 27001 / SOC 2 certification.
- ISO 27001:2022 gap assessment
- Vendor & third-party risk review
- Policy & SOP documentation
DPDP compliance isn't a policy PDF. It's an engineering problem.
The DPDP Act gives every Indian "Data Principal" enforceable rights over their personal data, and puts binding obligations on every "Data Fiduciary" that collects it — with penalties running up to ₹250 crore per instance for failure to implement reasonable security safeguards. Most of those obligations live in your codebase, not your legal drawer.
Consent has to be verifiable, not implied
Consent must be free, specific, informed and revocable via clear affirmative action — pre-ticked boxes and buried checkboxes in your onboarding flow are exactly what we look for in an audit.
Breach notification is time-bound
A personal data breach must be reported to the Data Protection Board of India and to affected Data Principals, without delay — which means your detection and escalation pipeline has to be fast enough to make that deadline real.
Significant Data Fiduciaries carry extra weight
If the Central Government notifies you as an SDF based on data volume or sensitivity, you'll need a resident Data Protection Officer, an independent data auditor and periodic Data Protection Impact Assessments.
Children's data needs verifiable parental consent
Processing data of users under 18 requires verifiable parental consent, and bars behavioural tracking or targeted advertising directed at children outright.
Data Principal rights need real infrastructure
Access, correction, erasure and grievance redressal requests need a working intake and fulfilment process — not a mailbox nobody checks.
60-second DPDP exposure check
Answer three questions. This is a directional read, not legal advice — we'll go deeper on the call.
Five stages, one point of contact throughout
No handoffs between a "sales engineer" and the person doing the work — the analyst on your scoping call is the one testing your systems.
Scope & threat model
We map your assets, data flows and prior incidents to build a scope that reflects real risk, not a generic checklist. Includes a lightweight DPDP applicability read.
Testing & assessment
Manual-led testing against your applications, infra and, where relevant, your people — supplemented by tooling, never replaced by it.
DPDP gap analysis
Findings are cross-mapped to consent, breach-notification and Data Principal-rights obligations so legal and engineering are reading the same document.
Remediation & retest
Fix guidance written for your stack, office hours with engineers while you patch, and a full retest included in scope — not billed separately.
Continuous monitoring
For retainer clients: ongoing MDR, quarterly re-testing cadence and DPO-as-a-Service support as your product and data footprint evolve.
Built for how Indian regulation and infrastructure actually intersect
CERT-In empanelled auditors
Reports formatted the way regulators and enterprise procurement teams expect to see them.
Security and DPDP under one contract
No coordination tax between a pentest vendor and a separate compliance consultant.
Senior-led, fixed fee
Every engagement is scoped and led by someone with 6+ years in offensive security — quoted upfront, no surprise change orders.
India-based delivery & data residency
Findings, PII and test artefacts stay on infrastructure located in India throughout the engagement.
A few problems we've actually solved
Anonymised at client request — sector and outcome details are accurate.
Consent flow rebuilt ahead of an RBI-linked audit
A Mumbai-based digital lending NBFC needed its loan-origination consent flow rebuilt to capture purpose-specific, revocable consent before a co-lending partner's compliance review.
Critical API flaw found before a hospital-chain rollout
A diagnostics platform's patient-report API was found to leak reports across account boundaries via a predictable object ID — fixed and retested inside one sprint, before go-live with a hospital chain.
Breach playbook built after a near-miss
Following a third-party logistics vendor's data exposure, we built the client's first formal breach-notification playbook and ran a tabletop exercise with leadership and engineering.
From the people who sat through the retest
"They found things our previous vendor's automated scan missed entirely — and explained the DPDP angle in terms our product team could actually act on."
"The gap assessment gave us a prioritised list instead of a 90-page report nobody reads. We closed the top risks in three weeks."
"Our board wanted proof of a real breach-response process, not a policy document. The tabletop session with CyberCombat gave us exactly that."
Pricing that scales with your stage, not our margins
Indicative starting price for a well-scoped engagement. Every quote is fixed-fee once scope is confirmed on the call.
DPDP Gap Assessment
For teams that need to know where they stand before building a roadmap.
- Data flow & consent mapping
- SDF applicability review
- Prioritised remediation roadmap
- Leadership readout session
VAPT + DPDP Bundle
The pairing most Series A–C companies actually need before a funding diligence cycle.
- Full web / mobile / API pentest
- DPDP gap assessment & roadmap
- Breach notification playbook draft
- Retest & compliance-ready report
Managed Security Retainer
For teams that want ongoing coverage, not a once-a-year fire drill.
- MDR / SOC coverage
- DPO-as-a-Service
- Quarterly retesting cadence
- Incident response on retainer
FAQ
Yes — the Act applies to any entity, digital or otherwise, that determines the purpose and means of processing personal data of individuals in India, including data collected offline and later digitised. If you have a customer database, an HR system, or a website with a contact form, it applies to you.
We implement, not just advise. A law firm can tell you what a compliant consent notice should say; we rebuild the consent flow, test whether it actually captures what it claims to, and pentest the systems that store the data behind it.
It's the cheapest time to do it. Retrofitting consent and data-retention logic after your data model is locked in and your user base has grown costs far more than designing for it from the start. Most early-stage clients start with the Gap Assessment tier.
No — the DPDP Act applies extraterritorially to any entity processing personal data of individuals in India in connection with offering goods or services to them, regardless of where the company is incorporated. We work with several overseas clients on exactly this basis.
We issue a signed attestation report suitable for enterprise procurement and investor diligence, but there is no single government-issued "DPDP certificate" as of today. Where relevant, we also help you prepare for ISO 27001 or SOC 2, which pair well with DPDP evidence requests.
Retainer clients get a guaranteed response within 4 hours. For non-retainer engagements, our average time to first analyst contact has been under 72 hours, subject to team availability — call the incident line directly for anything in progress.
Tell us what you're building. We'll tell you where the risk actually is.
Every enquiry gets a reply from a human on the team within one business day — usually the analyst who'd run your engagement.
Got it.
Thanks — a member of the team will reply within one business day. For anything urgent, use the incident line above.
Send another enquiry