INDIA / DESKTOP, THICK CLIENT & ELECTRON

Desktop application penetration testing in India

Scope-based VAPT for Electron apps and classic thick clients used by Indian SaaS, fintech and product teams. Validate renderer isolation, IPC, local privileges and update paths — with evidence and one remediation retest.

Electron trust boundaries

Renderer isolation, preload bridges and IPC handlers treated as privileged private APIs — not as “just another web page”.

Classic thick-client surfaces

Where relevant, assess traditional desktop clients for insecure local IPC, weak local auth and unsafe native integrations.

Evidence and retest

Validated impact with reproduction detail, remediation guidance and one remediation retest for in-scope fixes.

Desktop and thick-client VAPT for India-market products

Indian product companies increasingly ship companion desktop apps alongside web and mobile — Electron-based productivity tools, fintech operators’ consoles, security agents, and internal thick clients that talk to the same APIs customers already rely on. A useful desktop assessment looks past dependency CVE lists: it examines whether the UI process can reach privileged local capabilities it should not, whether secrets persist in clear storage, and whether update or deep-link channels can be abused.

PocForge provides human-led desktop application penetration testing for Windows, macOS and Linux scopes, with particular depth on Electron stacks. Indicative India pricing is published on our penetration testing cost guide. This India lander explains buyer context, typical scenarios and how desktop work sits next to broader VAPT services in India.

What this engagement covers

  • Electron renderer isolation, webPreferences, preload bridges and context boundaries
  • IPC / privileged handlers treated like authenticated private APIs (argument validation, path and URL controls)
  • Local storage of tokens, credentials, SQLite/IndexedDB artefacts, logs and keychain use
  • File, archive and plugin install paths — traversal, symlink and destination risks in scope
  • Deep links, custom protocols and navigation into privileged content
  • Update channel authenticity assumptions where explicitly in scope
  • Classic thick-client surfaces when the same product still ships native clients alongside Electron
  • Safe proof of impact and remediation retest

Exact techniques depend on platforms, build channels and whether you provide source, asar layout access or instrumentation. Methods are agreed in the rules of engagement before active testing.

Why Electron needs its own lens

Electron combines a Chromium renderer with powerful Node.js and native capabilities. When isolation fails — or when a preload bridge over-exposes filesystem, shell or process APIs — content that looks like a routine web bug can become local impact. That is a different risk model from a pure browser app, and scanner-only programmes rarely model it well.

Our methodology companion is the Electron security deep dive on renderer-to-Node trust boundaries. The service page describes how we map privilege across UI, preload, IPC, storage and updates, then validate evidence-backed impact.

Desktop vs web, API and mobile testing

Desktop testing does not replace web, API or mobile assessments when the same product exposes those surfaces. In practice:

  • Web covers browser-facing auth, authorisation and business logic.
  • API covers BOLA, tenancy and workflow abuse on backends the desktop client calls.
  • Mobile covers on-device storage and mobile-originated API paths.
  • Desktop / thick client covers local privilege, IPC and installer/update assumptions the browser never sees.

Many India SaaS RFQs say “VAPT” without naming desktop. If you ship an Electron companion, put it in the RFQ explicitly — see how to write a VAPT RFQ in India and the comparison of penetration test vs vulnerability scan.

Engagement flow

  1. Scope — platforms (Windows / macOS / Linux), build channels, test accounts, update exclusions and out-of-scope native modules.
  2. Rules of engagement — dedicated builds vs shared environments; what may be exploited; data handling.
  3. Surface mapping — windows, webviews, preload APIs, IPC, protocols, storage and native bridges into a privilege map.
  4. Analysis and controlled exploitation — trust-boundary failures with safe, non-destructive proofs where authorised.
  5. Report and retest — severity, evidence, remediation guidance and closure verification for remediated in-scope findings.

Phases align with the spirit of PTES-style engagement structure — pre-engagement, intelligence gathering, analysis, controlled exploitation and reporting — without pretending a checklist stamp replaces judgement.

Indicative India pricing

Published desktop / thick-client range: ₹40,000 – ₹95,000 + GST for typical scopes. Final quotes follow platforms, IPC complexity, feature depth and whether API or web testing is combined. Use the homepage calculator for a quick build-up, then confirm with a scope review. Broader India bands live on the 2026 cost guide.

Who this is for

Good fit: product teams in India shipping Electron-based productivity, fintech, security or SaaS companion apps; companies preparing customer security reviews for desktop installers and auto-update channels; buyers who need validated desktop findings rather than dependency-CVE lists alone.

May need a different procurement path: regulated programmes that contractually require a CERT-In empanelled auditor — verify the official list and read our CERT-In decision guide. PocForge does not claim CERT-In empanelment.

Deliverables

  • Executive summary of desktop risk and notable Electron or thick-client attack paths
  • Technical findings with severity, evidence and practical remediation guidance
  • Privilege-boundary notes for in-scope IPC, preload and privileged surfaces observed
  • Retest confirmation for remediated in-scope issues

Typical India desktop scenarios

SaaS companion desktop app. Enterprise customers ask whether the Electron shell can reach local files or privileged APIs from attacker-controlled renderer input. Testing focuses on isolation, preload exposure and IPC authorisation — often paired with API testing for the same tenants.

Fintech or ops console. Operators run privileged workflows from a desktop client. Scope covers local credential storage, session handling and whether deep links can jump into elevated screens without re-auth.

Security or productivity agent. Background privileges and update channels matter as much as the UI. We agree carefully what update and service surfaces are in scope so reports stay honest.

Legacy thick client plus Electron rewrite. Some products still ship classic clients while migrating. Where both are in scope, we apply the same evidence standard: validated impact, not scanner-only noise.

Buyer checklist for desktop scopes

  • Platforms and OS versions you support in production
  • Build channel you can supply (release, internal, signed) and whether source or asar access is available
  • Test accounts across roles; whether multi-tenant desktop behaviour matters
  • Whether auto-update, code signing and plugin install paths are in or out of scope
  • Whether the same APIs are already covered under a web+API engagement
  • Whether CERT-In empanelment is a contractual requirement (verify officially if yes)

What we intentionally avoid claiming

We do not promise “zero vulnerabilities”, unlimited retests, or coverage of every native dependency on earth. Unbounded malware-style reverse engineering of unrelated third-party SDKs, physical theft of devices, and destructive testing of production update infrastructure are out of scope unless explicitly agreed. Honest boundaries make reports more useful than theatre.

We also do not relabel a vulnerability scan as a penetration test. If you only need continuous scanning, say so — see pentest vs vulnerability scan. For assurance programmes that need offensive evidence alongside SOC 2 or ISO narratives, read VAPT for SOC 2 / ISO 27001 — we are not an audit firm and do not issue certificates.

How desktop findings should be prioritised

Prioritise issues that enable privilege escalation from renderer to Node/native capabilities, theft of long-lived credentials from local storage, unsafe update or plugin install paths, or trivial bypass of client-side-only controls that backends fail to enforce. Informational hardening notes still help, but they should not drown the report. Ask vendors how they triage — “count of findings” is a weak quality metric.

Working with desktop and backend teams together

Desktop findings often require coordinated fixes: tighten preload/IPC on the client and enforce authorisation on the API. We structure reports so owners are obvious, and we encourage joint triage when both teams attend. That reduces the failure mode where a client “fix” leaves the backend still wide open.

Why choose a boutique over a checklist factory

Large delivery factories can be the right fit for some procurement programmes. Boutique testing suits product companies that want senior attention on their specific Electron or thick-client architecture, clearer writing, and honest scoping. PocForge is intentionally small: we publish indicative prices, decline work that is a poor fit, and focus on validated impact. If you need a global brand stamp more than depth, say so — we would rather redirect you than oversell. Start at solutions or penetration testing company India.

Frequently asked questions

What is desktop / thick-client penetration testing?

It is security testing of installed desktop applications — including Electron apps and classic thick clients — focused on trust boundaries between the UI, local privileged code, storage, IPC and update mechanisms.

How much does desktop application pentesting cost in India?

PocForge’s indicative range for typical desktop / thick-client scopes is ₹40,000–₹95,000 + GST. Final pricing depends on platforms, IPC complexity and whether API or web testing is combined. See the cost guide.

Why is Electron a special case?

Electron combines a web renderer with powerful Node.js and native capabilities. If isolation or the preload bridge fails, renderer-controlled input can reach filesystem or process impact. See our Electron security deep dive.

Do you need source code?

Source helps but is not always required. Provide a testable build, platform targets and accounts. Source or asar/layout access improves coverage of preload and IPC handlers when available.

Will testing disrupt users?

Testing follows agreed rules of engagement on dedicated builds or controlled environments where possible. Potentially disruptive checks are controlled; proofs are designed to be safe and non-destructive.

Can desktop testing be combined with other VAPT work?

Yes. Desktop assessments often pair with API, web or mobile testing when the same product exposes those surfaces. See VAPT services in India for programme framing.

Do you claim CERT-In empanelment?

No. If your RFQ requires a CERT-In empanelled auditor, verify the official Empanel_org.pdf list and read our CERT-In decision guide. Do not treat marketing pages as the list.

Is a vulnerability scan enough for a desktop Electron app?

Usually not if you need confidence in IPC, preload and local privilege boundaries. Scans help with known dependency issues; they do not replace human-led trust-boundary testing. Compare pentest vs vulnerability scan.

Related PocForge guides

Related India guides

Need a scope-based desktop estimate?

Share platforms, build access and whether Electron or classic thick clients are in scope — PocForge will help define the right assessment.

Request a Quote →