VAPT in Kolkata for enterprise IT and product teams
Human-led vulnerability assessment and penetration testing for Kolkata technology and product teams. Validated findings, India-market pricing clarity and a remediation retest — remote-first, with on-site when the work requires it.
Why firms in Kolkata buy VAPT
Kolkata’s technology landscape includes enterprise IT centres, regional BFSI technology, education and publishing platforms, and a growing product/SaaS layer. Buyers searching for VAPT Kolkata want practical testing evidence for customer and internal reviews, without inflated certification claims.
PocForge delivers scope-based, human-led testing aligned to India procurement language and published indicative INR bands.
Industries and product shapes common in Kolkata
Common Kolkata scopes:
- Enterprise and regional IT — portals, vendor platforms and customer digital channels.
- BFSI technology delivery — ops and customer platforms supporting eastern-region programmes.
- Edtech and publishing tech — content platforms and multi-role access models.
- SaaS / product startups — web and API stacks preparing for enterprise questionnaires.
Whatever the vertical, useful VAPT is scope-based: agreed assets, roles under test, environments, exclusions and a retest window — not an overnight scanner dump. See the commercial map on VAPT services in India and the buyer hub at VAPT India.
How we deliver for Kolkata teams
Application and API VAPT for Kolkata teams is typically remote. On-site visits are planned for internal network/AD scopes or workshops when office access is available. Reporting follows IST calendars.
PocForge is based in Delhi (NCR), not in Kolkata. We serve Kolkata remotely as part of nationwide delivery, and we plan on-site in Kolkata when a scope needs it — for example internal network or Active Directory work, or a stakeholder kick-off. That is written into the statement of work. This page is local context for Kolkata buyers; it is not a claim that PocForge is a Kolkata company.
Surfaces we commonly test
City-based buyers usually combine more than one surface. Pick what matches your risk:
- Web application penetration testing in India
- API security testing in India
- Mobile app security testing in India
- Cloud security assessment in India
- External infrastructure pentesting in India
- Desktop / Electron pentesting in India
- Network & Active Directory pentesting in India
- AI / LLM security testing in India
Typical Kolkata engagement scenarios
Enterprise questionnaire pack. Fresh web+API report for a customer security review.
Regional platform hardening. Authorisation testing before a multi-state rollout.
Hybrid app + perimeter. Application scope plus external infrastructure checks.
Local context for buyers in Kolkata
Use national guides for cost and RFQ hygiene — city pages add local context, not a different methodology. Start at VAPT services in India and cost guide 2026.
Indicative pricing (India)
We publish indicative INR bands that sit slightly under many broad market package openers for comparable manual work. Examples (exclusive of GST; final quote after scope):
- Web application: ₹30,000 – ₹65,000
- Web + API: ₹55,000 – ₹1,10,000
- API security: ₹25,000 – ₹60,000
- Mobile (per platform): ₹35,000 – ₹80,000
- External network / infrastructure: ₹25,000 – ₹65,000
- Desktop / thick client (Electron): ₹40,000 – ₹95,000
- Cloud security review: ₹35,000 – ₹90,000
- Internal / Active Directory: ₹55,000 – ₹1,35,000
- AI / LLM security testing: ₹45,000 – ₹1,10,000
- Application bundle (app + mobile): ₹90,000 – ₹1,75,000
Full bands and cost drivers: penetration testing cost in India 2026. For a clean vendor brief, use how to write a VAPT RFQ in India.
CERT-In empanelment — be precise
Some regulated programmes require a CERT-In empanelled auditor. That is a procurement attribute, not a synonym for testing quality. PocForge does not claim empanelment we do not have. If your contract needs it, verify the official CERT-In PDF and match the legal entity name. Read Do you need CERT-In empanelled VAPT? before you shortlist anyone in Kolkata or elsewhere.
Frequently asked questions
Do you offer VAPT on-site in Kolkata?
PocForge is based in Delhi (NCR). We serve Kolkata remotely and deliver nationwide. On-site in Kolkata is arranged when the scope requires it — typically LAN, Active Directory or an in-person workshop — and is stated in the statement of work.
Are you only available in Kolkata?
No. PocForge is based in Delhi (NCR). We serve Kolkata remotely and deliver nationwide, with on-site in Kolkata when the work requires it. This page targets local search; PocForge is not based in Kolkata.
Do you publish Kolkata-specific prices?
We publish India-wide indicative bands; final quotes are scope-based, not city surcharges.
Are you CERT-In empanelled?
We do not claim empanelment we do not have. Verify the official CERT-In PDF when your contract requires it.
What surfaces can Kolkata teams include?
Web, API, mobile, cloud, external infra, desktop/Electron, network/AD and AI/LLM — per agreed scope.
How do we request a quote?
Use the contact page with assets, environments and timeline for a free scope review.
Related guides
Ready to scope VAPT for a Kolkata product or programme?
Tell us the surfaces, environments and timeline. We will return a clear scope outline — remote-first, with on-site planned only when the work needs it.
Talk to a pentester →