Partners who bring VAPT and penetration testing work
PoCForge (Cyber Security) — Security Tested. Businesses Empowered. We work with people who already have the client relationship: consultants, MSPs, software firms, advisors and resellers. You introduce a real project. We deliver human-led vulnerability assessment and penetration testing, a clear report and a remediation retest. This is a referral and channel partnership, not a badge or a certification.
Who should partner
The fit is simple: you meet organisations that need an independent penetration test, and you would rather not staff that work yourself. We stay the delivery practice. You stay the relationship.
Consultants and advisors
Security, IT, growth or risk advisors whose clients keep asking for a VAPT before a release, an audit or a customer questionnaire.
MSPs and IT service firms
Managed providers and system integrators who want offensive testing in the portfolio without hiring a red team.
Software firms and ISVs
Agencies, product studios and vendors who need a web, API or cloud test before handover or an enterprise deal.
Compliance advisors and law firms
GRC consultants, chartered accountants and counsel who need a technical test beside a policy or regulatory programme. We do not replace the advisor.
Channel and reseller teams
Firms that already quote technology or services and want to attach a scoped penetration test, with margin agreed before the proposal goes out.
India and global introducers
Partners based in India, or anywhere else, introducing work for clients in India or abroad. Engagements are remote-first unless a scope says otherwise.
What you get
We do not publish a partner portal, market-development fund or a certified-partner logo. What we do offer is delivery your client can read, and a commercial arrangement written down before work starts.
Delivery quality
Senior, human-led testing. Findings are evidenced, including proof of exploit where it is safe and in scope. We do not pad reports with scanner noise.
Reporting your client can use
An executive summary plus technical detail engineers can reproduce. Severity is tied to impact, not to a tool score.
Remediation retest
In-scope fixes are retested so the engagement closes on evidence, not on a promise. Retest scope is confirmed with the original test, not invented later.
Co-sell when it helps
We can join a scoping call with you and the client, or stay in the background while you run the conversation. Say which you want up front.
Co-branded or white-label reports
Available only when agreed in writing before kickoff. The default report is PoCForge-branded. We will not hide our name, or add yours, unless that model is confirmed.
A written commercial
Referral fee or reseller margin is agreed before the engagement, for work that actually closes. We do not pay a fee for an introduction that does not become paid testing.
We do not advertise auditor-panel membership, CREST, or any other badge on this page. If a procurement needs a specific accreditation, say so in the enquiry and we will tell you plainly whether we can meet it.
How it works
Introduce the need
Use the partner enquiry form on this page, or email [email protected]. Tell us the client type, the likely surface and how you want to be involved.
Scope together
We confirm assets, rules of engagement and whether the report is PoCForge-branded, co-branded or white-label. Nothing starts without a written scope.
We test and report
Practitioners test the agreed surface, write the report and share it through the path we agreed — you, the client, or both.
Retest and close
In-scope fixes are retested. Your referral fee or margin is paid on the terms already agreed, after the client engagement is real.
Partner types
Pick the model closest to how you sell. We can mix them on a single project if the paperwork says so. These are working arrangements, not tiers with invented status.
Referral — introduce and earn
You introduce an organisation that needs VAPT or penetration testing. We scope and deliver. You do not run the test and you do not employ the testers.
- Best for consultants, advisors, law firms and anyone who should not deliver the technical test themselves.
- A referral fee is agreed in writing before work starts. We do not publish a blanket percentage.
- The fee applies when the introduced opportunity becomes a paid engagement, not merely because an email was sent.
- We confirm by email that the introduction is yours, so a later direct enquiry from that client is not quietly reclassified.
Channel / reseller — you contract, we deliver
You sell the assessment as part of your own proposal. We are the delivery team under a subcontract or reseller note agreed first.
- Best for VARs, IT service firms and MSPs who already quote a bundle.
- Margin is agreed per engagement or in a short partner note. Wholesale rates are not listed on this site.
- Your client can know we do the testing, or not, depending on the white-label terms below.
- We will not undercut you on that account while the introduction is active and the terms say so.
Co-sell — joint conversation, our delivery
You keep the account. We join scoping, or support your proposal with a realistic test plan, then deliver the assessment under the PoCForge name unless branding is agreed otherwise.
- Best for technology partners, integrators and advisors who want the client to meet the testers.
- No market-development fund and no co-branded event programme unless we explicitly agree one.
- Useful when the buyer wants to see who will actually test, not only who sold the project.
White-label — your brand on the report, if agreed
Some partners need the report to carry their name. We can do that, but only as a written exception to the default PoCForge report.
- Agree branding before kickoff: PoCForge, co-branded, or white-label.
- White-label means the client-facing report can omit our name. It does not mean we pretend to hold your certifications.
- We still need a lawful rules-of-engagement path. Hiding the tester from the client does not remove the need for authorisation to test.
- Neutral wording can be used so you can add a cover note. We do not hand over an editable file full of another firm’s marks.
Services you can introduce
Partners usually bring one of these scoped assessments. If the need is broader, start from security assessments and we will narrow it.
Red-team objectives are scoped per engagement. The assumed-breach case study shows the shape of that work; it is not a product catalogue. Mobile application testing is also available when the scope calls for it: mobile application penetration testing.
Partnership questions
Who is the PoCForge partner programme for?
It is for people and firms who can introduce VAPT or penetration testing projects: consultants, MSPs, software agencies, ISVs, resellers, compliance advisors and law firms. It is not a training certificate and not a franchise.
Do you pay a referral commission?
Yes, when we agree a referral fee in writing before the engagement, and the introduction becomes paid work. We do not publish a single percentage. Channel or reseller margin is agreed the same way. An email introduction that never becomes a project is not a payable event.
Can the report be white-label or co-branded?
Yes, if we agree it before kickoff. The default is a PoCForge (Cyber Security) report. White-label is a delivery choice, not a claim that we hold your certifications or that a regulator has approved the partnership.
Do I need a security certification to partner?
No. We do not require OSCP, CREST, CEH or any other personal certification from a referrer. We also do not issue a PoCForge partner badge. What matters is a real client need and a clear commercial note.
Which tests can I refer?
Web and API VAPT, network and Active Directory, cloud, external infrastructure, desktop and Electron, mobile, AI and LLM testing, and scoped red-team objectives. See the service links on this page, or the solutions overview.
Is this only for partners in India?
No. The public site speaks to a global audience. Partnership enquiries are welcome from India and from introducers elsewhere, for clients in India or abroad. Delivery is remote-first unless a scope requires otherwise.
Will you go around me to my client?
No. Once we have accepted an introduction in writing, we will not separately solicit that client for the same project. How visible we are on calls and on the report follows the model you picked: referral, co-sell or white-label.
How do I apply?
Use the partner enquiry form on this page: your name, firm, partner type and how you will introduce work. You can also email [email protected] with subject PARTNERS. There is no portal login. We aim to reply within a few working days.
Bring a project
Tell us who you are and the kind of testing your clients ask for. If it is a fit, we will reply with how we would scope the first introduction — including fee or margin, branding and who speaks to the client.
Use the partner enquiry form below. It is separate from the client contact form and from Careers. If the form is unavailable, email [email protected] with subject PARTNERS.
Company: read About Us for how the practice works, or Careers if you want to join the delivery team rather than introduce projects. Tagline: Security Tested. Businesses Empowered.
Partner enquiry
Dedicated form for referral, MSP, ISV and consultant partners — not the client scope form and not Careers. Submissions go to [email protected] with a PARTNERS subject line.
