New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now live See changelog →
Security testing

Security and VAPT for IT teams

Continuous exposure management: automated scans, scoped engagements, HTTP Lab, imports, analyst workbench, and audit-ready reports—tenant-isolated.

Infronest VAPT executive dashboard — scans, vulnerability distribution and risk trend across engagements
Product proof

Already live in the product

Backed by app modules

Running in production today: the web VAPT dashboard, engagements, HTTP Lab, analyst workbench, mobile VAPT, integrations, benchmarking, and realtime views.

Protected app route: /vapt-dashboard
How it works

Built around real workflows

Highlights below describe capabilities already present in the protected app behind this page.

Automated web scans (full, quick, nuclei, API)
Engagements with allowed_hosts
HTTP Lab and manual findings
Burp / SARIF / JSON import
Analyst workbench triage
HTML + PDF engagement reports
Viewer vs analyst RBAC
CI integrations and severity gates
Workflow

What teams can do here

Step 1
Scope engagement and allowed_hosts
Step 2
Run automated scans
Step 3
Manual test in HTTP Lab or import tools
Step 4
Triage on workbench
Step 5
Deliver HTML/PDF report
How it works

How it works

01
Scope an engagement
Create a per-client or per-app engagement with a mandatory allowed_hosts list so testing stays inside agreed scope. Map the engagement to the frameworks that matter for your audit (OWASP Top 10, PCI-DSS, ISO 27001).
02
Run automated scans
Launch full, quick, header, SSL, API-oriented or Nuclei-template profiles against in-scope targets. Findings are severity-ranked and carry CVSS 3.1 vectors; dependency findings are enriched with CVE, EPSS and CISA KEV data.
03
Verify manually
Use the scoped HTTP Lab to replay and confirm requests by hand, raise manual findings, or import Burp XML, SARIF or JSON so automated and human results sit in one engagement.
04
Triage and report
Analysts work the findings by severity, status and source; false positives require a documented reason. Export one HTML or PDF report covering automated, manual and imported findings.
05
Add certified validation (optional)
For audits that need a human sign-off, add the L4 consulting engagement: certified manual validation, retest after fixes and an optional attestation letter.
Example

A worked example

Say a 200-person lender is preparing for a partner security review with a customer portal, an Android app and 40 cloud servers in scope. They split the work into three engagements: a web scan of the portal whose reflected-XSS finding is confirmed by hand in the HTTP Lab, a static review of the APK, and an nmap-based sweep of the external range. All findings land on one workbench ranked by CVSS, and each engagement exports its own PDF. When the fixes ship, a re-scan plus an optional certified re-test closes the loop — one platform, with the engagement type chosen per asset.

In depth

Six engagement types, one workbench

VAPT is not one test — the right depth depends on the asset. Infronest splits the practice into six engagement types that share the same scoping, triage and reporting workflow, so a programme that starts with one web app can grow to cover APIs, mobile builds, networks and cloud accounts without changing tools or re-learning a report format.

Every type feeds the same remediation and re-test loop: findings get owners, fixes are re-verified by the verification engine, and a delta report shows exactly what closed. Whichever combination you scope, the output is one evidence trail per engagement.

  • Web application VAPT — crawl and scan browser-facing apps for OWASP Top 10 classes, with high-impact findings verified by hand.
  • API security testing — REST and GraphQL checks plus role-matrix replay to catch BOLA and broken function-level authorisation.
  • Mobile application VAPT — static analysis of APK, AAB and IPA builds mapped to OWASP MASVS.
  • Network penetration testing — consulting-led external and internal testing with human exploitation under signed rules of engagement.
  • Cloud security review — read-only IAM, storage and network-rule audit against CIS Benchmarks with human attack-path analysis.
  • Continuous / CI security — webhook-triggered scans that gate builds on severity thresholds.
FAQ

Frequently asked questions

Which type of VAPT do I need — web, API, mobile, network or cloud?
Match the engagement to the asset. A browser-facing product needs web application VAPT; services and integrations need API security testing; a shipped APK/AAB/IPA needs the mobile assessment; infrastructure and Active Directory need network penetration testing; AWS, Azure or GCP accounts need the cloud review. If you ship weekly, add continuous scanning between point-in-time engagements.
Can I combine several engagement types into one assessment?
Yes — most audit-driven scopes pair web + API, and perimeter reviews pair network + cloud. Each engagement keeps its own allowed_hosts list and report so evidence stays per-asset, while everything is triaged on the same workbench. The easiest way to scope a combination is a short demo call.
How much does VAPT cost in India?
Across the Indian market, a focused web application penetration test typically costs ₹1.5–4 lakh (USD 2,000–5,000), and combined network + web VAPT for a mid-size environment runs ₹5–15 lakh (USD 6,000–18,000). Infronest’s productised engagements start at ₹36,750 per application, with certified manual validation available as a consulting add-on — see the VAPT hub.
How long does a VAPT engagement take?
Typical industry ranges: a scoped web application test runs one to three weeks end to end, including manual verification and reporting. Multi-surface scopes (web + API + network) trend longer, while re-tests are faster because they only re-check previously reported findings.
Is Infronest VAPT automated scanning or a human penetration test?
Both, in layers. The platform runs automated scanners and gives you a scoped HTTP Lab plus import and triage tools (this is the L3 subscription). Certified manual penetration testing and attestation are delivered on top as an L4 consulting engagement — software alone is not a CREST- or OSCP-level pentest, and we say so.
Do I get one report covering automated, manual and imported findings?
Yes. Automated scan output, findings you raise by hand in the HTTP Lab, and results you import from Burp XML, SARIF or JSON all live in the same engagement and export together as a single HTML or PDF report.
Has the Infronest platform itself been independently penetration tested?
We are transparent about our own posture rather than overstating it: Internal security assessment, May 2026 — no third-party penetration test. On frameworks we describe ourselves as ISO 27001 aligned — certification in progress. Your VAPT report is evidence you can hand to an auditor; it is not a certification we issue.
Is my data isolated from other tenants during a scan?
Yes. Each organisation’s engagements, findings and reports are tenant-isolated, and every engagement enforces an allowed_hosts list so scans cannot reach hosts you have not authorised.

See also: VAPT product hub · What is VAPT? (blog) · Types of penetration testing (blog) · Remediation & re-test · Book a demo

Related

Explore connected offerings

Which VAPT engagement does your audit actually need?

Scope it in one conversation — web, API, mobile, network or cloud — and get severity-ranked findings with an audit-ready report, starting at ₹36,750 per application.