SECURITY GLOSSARY

VAPT (Vulnerability Assessment and Penetration Testing)

VAPT pairs a vulnerability assessment (finding and listing known weaknesses, often with scanners) with a penetration test (a tester trying to exploit weaknesses to show real impact). In India the combined term is the common procurement label.

What it is

VAPT pairs a vulnerability assessment (finding and listing known weaknesses, often with scanners) with a penetration test (a tester trying to exploit weaknesses to show real impact). In India the combined term is the common procurement label.

Why it matters

Customers, auditors and regulators ask for VAPT evidence before trusting a product or vendor. A report that only lists scanner output rarely answers the real question: what could an attacker actually do?

How we test it

We scope assets, roles and environments in writing, use automation for coverage, then manually test authorisation, business logic and attack paths. Each confirmed finding gets evidence, impact and a fix, and fixed findings are retested.

Common mistakes

  • Buying a scan and calling it a pentest
  • No written scope, so nobody knows what was tested
  • No retest, so closure is never proven

An example

A SaaS team preparing for an enterprise security review gets a VAPT covering its web app and API: the scan flags outdated headers; the manual test finds a user can read another tenant’s invoices.

Not to be confused with

Vulnerability scan, which is automated discovery only. See Penetration test vs vulnerability scan.

Related at PoCForge

Sources

Need this tested on your systems?

Share your scope and we will propose a human-led plan with proof and a retest.

Request a free scope review →