Offensive security for the way modern teams build
PocForge is a human-led penetration testing practice. We help organisations find exploitable weaknesses across web, API, mobile, cloud, infrastructure and AI systems — then prove impact and retest fixes.
Who we are
PocForge is a boutique offensive-security practice. Engagements are led by senior practitioners, with specialist collaborators brought in when a scope needs deeper coverage. We keep communication paths short: your team talks to the people testing your systems.
We serve India-market and international organisations remotely. Contact: [email protected].
What we believe
- Human-led offensive testing — manual reasoning plus targeted automation.
- Proof-of-exploit — show what an attacker can actually do within agreed rules.
- Remediation retest — verify fixes instead of leaving closure ambiguous.
- Business-logic focus — authorisation, workflow abuse, tenant isolation and privilege boundaries — not only generic OWASP checklists.
How engagements work
- Scope discussion (assets, environments, roles, timeline, compliance context).
- Statement of work with clear inclusions and exclusions.
- Testing under rules of engagement.
- Report with evidence and remediation guidance.
- Retest of in-scope remediated findings.
Honesty on certifications and empanelment
We do not decorate pages with badges we cannot substantiate. If your procurement requires CERT-In empanelment or a named accreditation, verify it on the issuing body’s official register. For a plain-language decision tree, read Do you need CERT-In empanelled VAPT?
Explore further
Tell us what you need tested
A short brief is enough to start a useful scope conversation.
